Multi-Factor Authentication Request Generation

T1621

Technique.View on attack.mitre.org

About this technique

Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.

Adversaries in possession of credentials to Valid Accounts may be unable to complete the login process if they lack access to the 2FA or MFA mechanisms required as an additional credential and security control. To circumvent this, adversaries may abuse the automatic generation of push notifications to MFA services such as Duo Push, Microsoft Authenticator, Okta, or similar services to have the user grant access to their account. If adversaries lack credentials to victim accounts, they may also abuse automatic push notification generation when this option is configured for self-service password reset (SSPR).

In some cases, adversaries may continuously repeat login attempts in order to bombard users with MFA push notifications, SMS messages, and phone calls, potentially resulting in the user finally accepting the authentication request in response to “MFA fatigue.”

Detection rules20

Rules on DetectionCode tagged with T1621.

Sigma2

RuleLevelLog source
Multifactor Authentication Deniedmediumazure / NULL
Multifactor Authentication Interruptedmediumazure / NULL

Splunk18

Groups3

Software0

None recorded.

Campaigns1

Procedure examples4

Groups3

Used byProcedure example
GroupAPT29

APT29 has used repeated MFA requests to gain access to victim accounts.

GroupLAPSUS$

LAPSUS$ has spammed target users with MFA prompts in the hope that the legitimate user will grant necessary approval.

GroupScattered Spider

Scattered Spider has used multifactor authentication (MFA) fatigue by sending repeated MFA authentication requests to targets.

Campaigns1

Used byProcedure example
CampaignC0027

During C0027, Scattered Spider attempted to gain access by continuously sending MFA messages to the victim until they accept the MFA push challenge.

References4

  1. MFA Fatigue Attacks - PortSwigger Open source
    Jessica Haworth. (2022, February 16). MFA fatigue attacks: Users tricked into allowing device access due to overload of push notifications. Retrieved March 31, 2022.
  2. Obsidian SSPR Abuse 2023 Open source
    Noah Corradin and Shuyang Wang. (2023, August 1). Behind The Breach: Self-Service Password Reset (SSPR) Abuse in Azure AD. Retrieved March 28, 2024.
  3. Russian 2FA Push Annoyance - Cimpanu Open source
    Catalin Cimpanu. (2021, December 9). Russian hackers bypass 2FA by annoying victims with repeated push notifications. Retrieved March 31, 2022.
  4. Suspected Russian Activity Targeting Government and Business Entities Around the Globe Open source
    Luke Jenkins, Sarah Hawley, Parnian Najafi, Doug Bienstock. (2021, December 6). Suspected Russian Activity Targeting Government and Business Entities Around the Globe. Retrieved April 15, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.