47
Groups Using This
4
Tactics
10
Platforms
15
Prevalence Rank
Description

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence. In some cases, adversaries may abuse inactive accounts: for example, those belonging to individuals who are no longer part of an organization. Using these accounts may allow the adversary to evade detection, as the original account user will not be present to identify any anomalous activity taking place on their account. The overlap of permissions for local, domain, and cloud accounts across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access (i.e., domain or enterprise administrator) to bypass access controls set within the enterprise.

View MITRE record โ†—

Platforms
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
Groups Using T1078 (47)
G0032
Lazarus Group
๐Ÿ‡ฐ๐Ÿ‡ต North Korea93 techniques26 software
G0007
APT28
๐Ÿ‡ท๐Ÿ‡บ Russia93 techniques29 software
G0096
APT41
๐Ÿ‡จ๐Ÿ‡ณ China82 techniques32 software
G1017
Volt Typhoon
๐Ÿ‡จ๐Ÿ‡ณ China81 techniques17 software
G0034
Sandworm Team
๐Ÿ‡ท๐Ÿ‡บ Russia79 techniques27 software
G0049
OilRig
๐Ÿ‡ฎ๐Ÿ‡ท Iran76 techniques30 software
G0046
FIN7
67 techniques19 software
G0016
APT29
๐Ÿ‡ท๐Ÿ‡บ Russia66 techniques49 software
G1015
Scattered Spider
64 techniques9 software
G0102
Wizard Spider
๐Ÿ‡ท๐Ÿ‡บ Russia64 techniques22 software
G1055
VOID MANTICORE
๐Ÿ‡ฎ๐Ÿ‡ท Iran63 techniques0 software
G0114
Chimera
๐Ÿ‡จ๐Ÿ‡ณ China59 techniques6 software
G0027
Threat Group-3390
๐Ÿ‡จ๐Ÿ‡ณ China57 techniques24 software
G1051
Medusa Group
57 techniques5 software
G0035
Dragonfly
๐Ÿ‡ท๐Ÿ‡บ Russia56 techniques10 software
G0087
APT39
๐Ÿ‡ฎ๐Ÿ‡ท Iran53 techniques11 software
G0065
Leviathan
๐Ÿ‡จ๐Ÿ‡ณ China50 techniques17 software
G1048
UNC3886
๐Ÿ‡จ๐Ÿ‡ณ China49 techniques8 software
G1043
BlackByte
48 techniques8 software
G1057
ShinyHunters
46 techniques1 software
G0045
menuPass
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques25 software
G0004
Ke3chang
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques11 software
G1004
LAPSUS$
43 techniques1 software
G0117
Fox Kitten
๐Ÿ‡ฎ๐Ÿ‡ท Iran41 techniques5 software
G0037
FIN6
40 techniques12 software
G0061
FIN8
36 techniques11 software
G1056
TeamPCP
36 techniques3 software
G0119
Indrik Spider
๐Ÿ‡ท๐Ÿ‡บ Russia33 techniques8 software
G0064
APT33
๐Ÿ‡ฎ๐Ÿ‡ท Iran31 techniques16 software
G0093
GALLIUM
๐Ÿ‡ท๐Ÿ‡บ Russia31 techniques16 software
G0091
Silence
๐Ÿ‡ท๐Ÿ‡บ Russia28 techniques3 software
G1041
Sea Turtle
27 techniques1 software
G1040
Play
26 techniques9 software
G1032
INC Ransom
25 techniques8 software
G1033
Star Blizzard
๐Ÿ‡ท๐Ÿ‡บ Russia20 techniques1 software
G1021
Cinnamon Tempest
๐Ÿ‡จ๐Ÿ‡ณ China19 techniques8 software
G1024
Akira
17 techniques8 software
G0001
Axiom
๐Ÿ‡จ๐Ÿ‡ณ China16 techniques8 software
G0122
Silent Librarian
๐Ÿ‡ฎ๐Ÿ‡ท Iran13 techniques0 software
G0026
APT18
12 techniques5 software
G0085
FIN4
12 techniques0 software
G0051
FIN10
11 techniques1 software
G0053
FIN5
๐Ÿ‡ท๐Ÿ‡บ Russia11 techniques6 software
G0008
Carbanak
9 techniques4 software
G1005
POLONIUM
๐Ÿ‡ฎ๐Ÿ‡ท Iran7 techniques2 software
G0039
Suckfly
๐Ÿ‡จ๐Ÿ‡ณ China5 techniques1 software
G0011
PittyTiger
๐Ÿ‡จ๐Ÿ‡ณ China2 techniques5 software
โ†‘