Credential Stuffing

T1110.004

Sub-technique of T1110 Brute Force.View on attack.mitre.org

About this technique

Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap. Occasionally, large numbers of username and password pairs are dumped online when a website or service is compromised and the user account credentials accessed. The information may be useful to an adversary attempting to compromise accounts by taking advantage of the tendency for users to use the same passwords across personal and business accounts.

Credential stuffing is a risky option because it could cause numerous authentication failures and account lockouts, depending on the organization's login failure policies.

Typically, management services over commonly used ports are used when stuffing credentials. Commonly targeted services include the following:

* SSH (22/TCP)
* Telnet (23/TCP)
* FTP (21/TCP)
* NetBIOS / SMB / Samba (139/TCP & 445/TCP)
* LDAP (389/TCP)
* Kerberos (88/TCP)
* RDP / Terminal Services (3389/TCP)
* HTTP/HTTP Management Services (80/TCP & 443/TCP)
* MSSQL (1433/TCP)
* Oracle (1521/TCP)
* MySQL (3306/TCP)
* VNC (5900/TCP)

In addition to management services, adversaries may "target single sign-on (SSO) and cloud-based applications utilizing federated authentication protocols," as well as externally facing email applications, such as Office 365.

Detection rules13

Rules on DetectionCode tagged with T1110.004.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk13

RuleTypeRiskData source
AWS High Number Of Failed Authentications From IpAnomalyNULLAWS CloudTrail ConsoleLogin
AWS Multiple Users Failing To Authenticate From IpAnomalyNULLAWS CloudTrail ConsoleLogin
AWS Unusual Number of Failed Authentications From IpAnomalyNULLAWS CloudTrail ConsoleLogin
Azure AD Multi-Source Failed Authentications SpikeHuntingNULLAzure Active Directory
Azure AD Multiple Users Failing To Authenticate From IpAnomalyNULLAzure Active Directory
Azure AD Unusual Number of Failed Authentications From IpAnomalyNULLAzure Active Directory
CrushFTP Max Simultaneous Users From IPAnomalyNULLCrushFTP
GCP Multiple Users Failing To Authenticate From IpAnomalyNULLGoogle Workspace
GCP Unusual Number of Failed Authentications From IpAnomalyNULLGoogle Workspace
O365 Multi-Source Failed Authentications SpikeHuntingNULLO365 UserLoginFailed
O365 Multiple Users Failing To Authenticate From IpTTPNULLO365 UserLoginFailed
Okta ThreatInsight Login Failure with High Unknown usersTTPNULL
Windows Local Administrator Credential StuffingTTPNULLWindows Event Log Security 4624, Windows Event Log Security 4625

Groups2

Software1

Campaigns0

None recorded.

Procedure examples3

Groups2

Used byProcedure example
GroupChimera

Chimera has used credential stuffing against victim's remote services to obtain valid accounts.

GroupVOID MANTICORE

VOID MANTICORE has utilized credential stuffing attacks to obtain initial access to victim environments.

Software1

Used byProcedure example
MalwareTrickBot

TrickBot uses brute-force attack against RDP with rdpscanDll module.

References1

  1. US-CERT TA18-068A 2018 Open source
    US-CERT. (2018, March 27). TA18-068A Brute Force Attacks Conducted by Cyber Actors. Retrieved October 2, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.