Token Impersonation/Theft

T1134.001

Sub-technique of T1134 Access Token Manipulation.View on attack.mitre.org

About this technique

Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread.

An adversary may perform Token Impersonation/Theft when they have a specific, existing process they want to assign the duplicated token to. For example, this may be useful for when the target user has a non-network logon session on the system.

When an adversary would instead use a duplicated token to create a new process rather than attaching to an existing process, they can additionally Create Process with Token using `CreateProcessWithTokenW` or `CreateProcessAsUserW`. Token Impersonation/Theft is also distinct from Make and Impersonate Token in that it refers to duplicating an existing token, rather than creating a new one.

Detection rules14

Rules on DetectionCode tagged with T1134.001.

Sigma9

RuleLevelLog source
HackTool - Koh Default Named Pipecriticalwindows / pipe_created
HackTool - NoFilter Executionhighwindows / NULL
HackTool - SharpDPAPI Executionhighwindows / process_creation
HackTool - SharpImpersonation Executionhighwindows / process_creation
Meterpreter or Cobalt Strike Getsystem Service Installation - Securityhighwindows / NULL
Meterpreter or Cobalt Strike Getsystem Service Installation - Systemhighwindows / NULL
Potential Meterpreter/CobaltStrike Activityhighwindows / process_creation
HackTool - Impersonate Executionmediumwindows / process_creation
Potential Access Token Abusemediumwindows / NULL

Splunk5

RuleTypeRiskData source
Runas Execution in CommandLineHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Access Token Manipulation Winlogon Duplicate Token HandleHuntingNULLSysmon EventID 10
Windows Access Token Winlogon Duplicate Handle In Uncommon PathAnomalyNULLSysmon EventID 10
Windows Handle Duplication in Known UAC-Bypass BinariesAnomalyNULLSysmon EventID 10
Windows Wermgr Spawning System Integrity ProcessTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups2

Software17

Campaigns1

Procedure examples20

Groups2

Used byProcedure example
GroupAPT28

APT28 has used CVE-2015-1701 to access the SYSTEM token and copy it into the current process as part of privilege escalation.

GroupFIN8

FIN8 has used a malicious framework designed to impersonate the lsass.exe/vmtoolsd.exe token.

Software17

Used byProcedure example
MalwareAria-body

Aria-body has the ability to duplicate a token from ntprint.exe.

MalwareBADHATCH

BADHATCH can impersonate a `lsass.exe` or `vmtoolsd.exe` token.

MalwareBitPaymer

BitPaymer can use the tokens of users to create processes on infected systems.

MalwareCobalt Strike

Cobalt Strike can steal access tokens from exiting processes.

MalwareEmotet

Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed.

MalwareFinFisher

FinFisher uses token manipulation with NtFilterToken as part of UAC bypass.

MalwareFooder

Fooder has used the `DuplicateTokenEx` API to duplicate the token of a specified process, and `CreateProcessAsUserA` to execute its payload.

MalwareHavoc

Havoc has a module capable of token impersonation.

View all 17 software examples

Campaigns1

Used byProcedure example
CampaignHomeLand Justice

During HomeLand Justice, threat actors used custom tooling to acquire tokens using `ImpersonateLoggedOnUser/SetThreadToken`.

References1

  1. DuplicateToken function Open source
    Microsoft. (2021, October 12). DuplicateToken function (securitybaseapi.h). Retrieved January 8, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.