Private Keys

T1552.004

Sub-technique of T1552 Unsecured Credentials.View on attack.mitre.org

About this technique

Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.

Adversaries may also look in common key directories, such as ~/.ssh for SSH keys on * nix-based systems or C:\Users\(username)\.ssh\ on Windows. Adversary tools may also search compromised systems for file extensions relating to cryptographic keys and certificates.

When a device is registered to Entra ID, a device key and a transport key are generated and used to verify the device’s identity. An adversary with access to the device may be able to export the keys in order to impersonate the device.

On network devices, private keys may be exported via Network Device CLI commands such as `crypto pki export`.

Some private keys require a password or passphrase for operation, so an adversary may also use Input Capture for keylogging or attempt to Brute Force the passphrase off-line. These private keys can be used to authenticate to Remote Services like SSH or for use in decrypting other collected files such as email.

Detection rules14

Rules on DetectionCode tagged with T1552.004.

Sigma7

RuleLevelLog source
Cisco Crypto Commandshighcisco / NULL
DPAPI Backup Keys And Certificate Export Activity IOChighwindows / file_event
PowerShell Get-Process LSASShighwindows / process_creation
Certificate Exported Via PowerShellmediumwindows / process_creation
Certificate Exported Via PowerShell - ScriptBlockmediumwindows / ps_script
Private Keys Reconnaissance Via CommandLine Toolsmediumwindows / process_creation
Suspicious PFX File Creationmediumwindows / file_event

Splunk7

RuleTypeRiskData source
Linux Auditd Find Private KeysTTPNULLLinux Auditd Execve
Linux Auditd Find Ssh Private KeysAnomalyNULLLinux Auditd Execve
Linux Auditd Private Keys and Certificate EnumerationAnomalyNULLLinux Auditd Execve
Windows Export CertificateAnomalyNULLWindows Event Log CertificateServicesClient 1007
Windows PowerShell Export CertificateAnomalyNULLPowershell Script Block Logging 4104
Windows PowerShell Export PfxCertificateAnomalyNULLPowershell Script Block Logging 4104
Windows Private Keys DiscoveryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups7

Software14

Campaigns2

Procedure examples23

Groups7

Used byProcedure example
GroupKimsuky

Kimsuky has accessed a Local State files associated with Chromium-based browsers that contain the AES key used to encrypt passwords stored in the browser to include `app_bound_encrypted_key`.

GroupRocke

Rocke has used SSH private keys on the infected machine to spread its coinminer throughout a network.

GroupScattered Spider

Scattered Spider enumerate and exfiltrate code-signing certificates from a compromised host.

GroupStorm-0501

Storm-0501 has leveraged the Azure Owner role to access and steal the Storage Account Access keys using the `Microsoft.Storage/storageAccounts/listkeys/action` operation.

GroupTeamPCP

TeamPCP has used malware to extract SSH and GPG keys from victim environments.

GroupTeamTNT

TeamTNT has searched for unsecured SSH keys.

GroupVolt Typhoon

Volt Typhoon has accessed a Local State file that contains the AES key used to encrypt passwords stored in the Chrome browser.

Software14

Used byProcedure example
ToolAADInternals

AADInternals can gather encryption keys from Azure AD services such as ADSync and Active Directory Federated Services servers.

MalwareCanisterWorm

CanisterWorm has gathered SSH private keys from the .ssh file.

MalwareEbury

Ebury has intercepted unencrypted private keys as well as private key pass-phrases.

ToolEmpire

Empire can use modules like Invoke-SessionGopher to extract private key and session information.

MalwareFoggyWeb

FoggyWeb can retrieve token signing certificates and token decryption certificates from a compromised AD FS server.

MalwareHildegard

Hildegard has searched for private keys in .ssh.

MalwarejRAT

jRAT can steal keys for VPNs and cryptocurrency wallets.

MalwareKinsing

Kinsing has searched for private keys.

View all 14 software examples

Campaigns2

Used byProcedure example
CampaignOperation Wocao

During Operation Wocao, threat actors used Mimikatz to dump certificates and private keys from the Windows certificate store.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained PKI keys, certificate files, and the private encryption key from an Active Directory Federation Services (AD FS) container to decrypt corresponding SAML signing certificates.

References6

  1. AADInternals Azure AD Device Identities Open source
    Dr. Nestori Syynimaa. (2022, February 15). Stealing and faking Azure AD device identities. Retrieved February 21, 2023.
  2. Kaspersky Careto Open source
    Kaspersky Labs. (2014, February 11). Unveiling “Careto” - The Masked APT. Retrieved July 5, 2017.
  3. Microsoft Primary Refresh Token Open source
    Microsoft. (2022, September 9). What is a Primary Refresh Token?. Retrieved February 21, 2023.
  4. Palo Alto Prince of Persia Open source
    Bar, T., Conant, S., Efraim, L. (2016, June 28). Prince of Persia – Game Over. Retrieved July 5, 2017.
  5. Wikipedia Public Key Crypto Open source
    Wikipedia. (2017, June 29). Public-key cryptography. Retrieved July 5, 2017.
  6. cisco_deploy_rsa_keys Open source
    Cisco. (2023, February 17). Chapter: Deploying RSA Keys Within a PKI . Retrieved March 27, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.