TACTIC: DEFENSE EVASION

Valid Accounts (T1078): real cases

MITRE Definition ↗
Adversaries obtain and misuse legitimate credentials of existing user accounts to maintain persistence and bypass controls.

Key Facts

Technique ID
T1078
Defense Evasion
Mapped Cases
19
Primary sources
Related Laws
4
Criminal statutes
  • ATT&CK Technique Identifier: T1078.
  • Tactical Phase: Defense Evasion.
  • Substantiated in 19 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Complaint ¶ 22
"Conspirators purchased compromised administrative account logins on Genesis Market to authenticate through victim VPN portals."
U.S. District Court for the District of New Jersey View full case dossier →
Primary Source Evidence Excerpt: CISA Advisory AA24-038A ¶ 3
"Volt Typhoon actors exclusively use legitimate credentials and built-in system administration tools (living off the land) to evade security detections."
Federal Law Enforcement Action / FISA Court Authorized Operations View full case dossier →
Primary Source Evidence Excerpt: Senate Finance Committee Testimony ¶ 4
"The threat actor gained entry to a Change Healthcare Citrix portal using compromised credentials for an account that lacked multifactor authentication."
U.S. District Court for the District of Minnesota View full case dossier →
Primary Source Evidence Excerpt: Senate Homeland Security Committee Testimony
"The initial entry vector was a legacy Virtual Private Network account that was active without multifactor authentication using a password discovered in a dark web leak."
U.S. District Court for the Northern District of California View full case dossier →
Primary Source Evidence Excerpt: CISA Emergency Directive 21-01
"Adversaries abused stolen SAML signing keys to forge authentication tokens and bypass multifactor authentication in victim Microsoft 365 environments."
U.S. District Court for the Southern District of New York View full case dossier →
Primary Source Evidence Excerpt: Plea Agreement ¶ 4, Page 13
"Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials."
U.S. District Court for the Middle District of Florida View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 31, Page 18
"Adversaries created forged cryptographic authentication cookies to access Yahoo webmail accounts of targeted individuals without passwords."
U.S. District Court for the Northern District of California View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 8
"Schulte abused his administrative credentials as a CIA Center for Cyber Intelligence software engineer to grant himself backdoor access to secure development servers."
U.S. District Court for the Southern District of New York View full case dossier →
Primary Source Evidence Excerpt: Trial Transcript Day 3, Page 54
"Obtained temporary security credentials from the AWS EC2 instance metadata service to access private S3 storage buckets."
U.S. District Court for the Western District of Washington View full case dossier →
Primary Source Evidence Excerpt: DOJ Seizure Affidavit ¶ 16
"Purchasers loaded stolen fingerprints into custom browser plugins to perfectly impersonate victim machines and bypass fraud detection."
U.S. District Court for the Eastern District of Wisconsin View full case dossier →
Primary Source Evidence Excerpt: Criminal Complaint ¶ 12, Page 6
"Defendant recruited an insider with legitimate administrator privileges to connect an infected USB drive and execute custom malware within the company's intranet."
U.S. District Court for the District of Nevada View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes."
U.S. District Court for the Northern District of California View full case dossier →
Primary Source Evidence Excerpt: CISA Advisory AA23-335A ¶ 4
"Defendants gained access to internet-connected Unitronics Vision PLCs because the industrial devices remained configured with the default manufacturer password '1111'."
U.S. District Court for the Western District of Pennsylvania View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 8, Page 4
"Deer.io functioned as an automated turn-key storefront allowing hackers to upload and sell stolen user account databases in bulk."
U.S. District Court for the Southern District of California View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"Infraud operated escrow systems enabling cybercriminals to buy and sell verified high-balance administrative account credentials."
U.S. District Court for the District of Nevada View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"Try2Check executed automated test transactions against merchant payment gateway APIs using stolen account logins."
U.S. District Court for the Eastern District of New York View full case dossier →
Primary Source Evidence Excerpt: Criminal Complaint ¶ 9, Page 4
"Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier."
U.S. District Court for the Western District of Missouri View full case dossier →
Primary Source Evidence Excerpt: Mandiant Joint Advisory ¶ 2
"Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier."
U.S. District Court for the Northern District of California View full case dossier →
Primary Source Evidence Excerpt: Statement of Offense ¶ 6, Page 3
"Lichtenstein gained access to Bitfinex's internal systems and authorized over 2,000 fraudulent cryptocurrency withdrawal transactions to private wallets."
U.S. District Court for the District of Columbia View full case dossier →

Commonly Charged Criminal Statutes

18 U.S.C. § 1030(a)(2)

Unauthorized Access to Obtain Protected Information

Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.

18 U.S.C. § 1030(a)(5)(A)

Intentional Damage to a Protected Computer

Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.

18 U.S.C. § 1030(a)(7)

Extortion in Connection with Computers

Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.

18 U.S.C. § 1030(b)

Conspiracy to Commit Computer Fraud

Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.