Technique with 4 sub-techniques.View on attack.mitre.org
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
For example, adversaries may manipulate victim DNS settings to enable other malicious activities such as preventing/redirecting users from accessing legitimate sites and/or pushing additional malware. Adversaries may also manipulate DNS and leverage their position in order to intercept user credentials, including access tokens (Steal Application Access Token) and session cookies (Steal Web Session Cookie). Downgrade Attacks can also be used to establish an AiTM position, such as by negotiating a less secure, deprecated, or weaker version of communication protocol (SSL/TLS) or encryption algorithm.
Adversaries may also leverage the AiTM position to attempt to monitor and/or modify traffic, such as in Transmitted Data Manipulation. Adversaries can setup a position similar to AiTM to prevent traffic from flowing to the appropriate destination, potentially to impair defenses and/or in support of a Network Denial of Service.
Rules on DetectionCode tagged with T1557 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Cisco ASA - Packet Capture Activity | Anomaly | NULL | Cisco ASA Logs | T1557 |
| Detect ARP Poisoning | TTP | NULL | Cisco IOS Logs | T1557.002 |
| Detect IPv6 Network Infrastructure Threats | TTP | NULL | Cisco IOS Logs | T1557.002 |
| Detect Port Security Violation | TTP | NULL | Cisco IOS Logs | T1557.002 |
| Detect Rogue DHCP Server | TTP | NULL | Cisco IOS Logs | T1557 |
| DNS Kerberos Coercion | TTP | NULL | Suricata, Sysmon EventID 22 | T1557.001 |
| Windows Credential Target Information Structure in Commandline | TTP | NULL | Sysmon EventID 1 | T1557.001 |
| Windows Kerberos Coercion via DNS | TTP | NULL | Windows Event Log Security 4662, Windows Event Log Security 5136, Windows Event Log Security 5137 | T1557.001 |
| Windows Short Lived DNS Record | TTP | NULL | Windows Event Log Security 5136, Windows Event Log Security 5137 | T1557.001 |
| Windows Theme File Creation in Unusual Location | Anomaly | NULL | Sysmon EventID 11 | T1557.001 |
| Used by | Procedure example |
|---|---|
| GroupKimsuky | Kimsuky has used modified versions of PHProxy to examine web traffic between the victim and the accessed website. |
| GroupMustang Panda | Mustang Panda leveraged a captive portal hijack that redirected the victim to a webpage that prompted the victim to download a malicious payload. |
| GroupSea Turtle | Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture. |
| Used by | Procedure example |
|---|---|
| MalwareDok | Dok proxies web traffic to potentially monitor and alter victim HTTP(S) traffic. |
| Toolevilginx2 | evilginx2 has the ability to act as an adversary-in-the-middle (AiTM) relay between a legitimate website and a phished user to capture all transmitted data including usernames, passwords, authentication tokens, and session cookies and tokens. |
| MalwareKali365 | Kali365 has created obfuscated phishing landing pages that act as an adversary in the middle infrastructure that intercepts communications between the victim host and legitimate services to steal credentials and user sessions. |
| MalwareLine Runner | Line Runner intercepts HTTP requests to the victim Cisco ASA, looking for a request with a 32-character, victim dependent parameter. If that parameter matches a value in the malware, a contained payload is then written to a Lua script and executed. |
| ToolNPPSPY | NPPSPY opens a new network listener for the |
| Used by | Procedure example |
|---|---|
| CampaignArcaneDoor | ArcaneDoor included interception of HTTP traffic to victim devices to identify and parse command and control information sent to the device. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.