TACTIC: CREDENTIAL ACCESS
OS Credential Dumping (T1003): real cases
MITRE Definition ↗ Adversaries dump plaintext passwords and hashes from operating system memory structures such as LSASS.
Key Facts
Technique ID
T1003
Credential Access
Mapped Cases
3
Primary sources
Related Laws
4
Criminal statutes
- ATT&CK Technique Identifier: T1003.
- Tactical Phase: Credential Access.
- Substantiated in 3 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)
fugitive 2020-10-15
Primary Source Evidence Excerpt: Indictment ¶ 46, Page 23
"The malware harvested passwords from computer memory using a bundled Mimikatz variant to impersonate network administrators."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)
sentenced 2017-02-28
Primary Source Evidence Excerpt: Indictment ¶ 27, Page 15
"Adversaries stole Yahoo's proprietary user database containing names, email addresses, cryptographic salts, and hashed passwords."
U.S. District Court for the Northern District of California
View full case dossier →
U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)
sentenced 2021-02-18
Primary Source Evidence Excerpt: Indictment ¶ 19, Page 11
"Injected modular credential harvesters that pulled domain credentials from Windows memory to pave the way for ransomware."
U.S. District Court for the Northern District of Ohio
View full case dossier →
Commonly Charged Criminal Statutes
18 U.S.C. § 1030(a)(2)
Unauthorized Access to Obtain Protected Information
Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.
18 U.S.C. § 1030(a)(5)(A)
Intentional Damage to a Protected Computer
Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.
18 U.S.C. § 1030(a)(7)
Extortion in Connection with Computers
Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.
18 U.S.C. § 1030(b)
Conspiracy to Commit Computer Fraud
Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.