TACTIC: DEFENSE EVASION
Valid Accounts (T1078): real cases
MITRE Definition ↗ Adversaries obtain and misuse legitimate credentials of existing user accounts to maintain persistence and bypass controls.
Key Facts
Technique ID
T1078
Defense Evasion
Mapped Cases
19
Primary sources
Related Laws
4
Criminal statutes
- ATT&CK Technique Identifier: T1078.
- Tactical Phase: Defense Evasion.
- Substantiated in 19 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Khoroshev et al. (LockBit Ransomware Operation)
charged 2024-05-07
Primary Source Evidence Excerpt: Complaint ¶ 22
"Conspirators purchased compromised administrative account logins on Genesis Market to authenticate through victim VPN portals."
U.S. District Court for the District of New Jersey
View full case dossier →
Volt Typhoon Critical Infrastructure Pre-Positioning
alleged 2023-05-24
Primary Source Evidence Excerpt: CISA Advisory AA24-038A ¶ 3
"Volt Typhoon actors exclusively use legitimate credentials and built-in system administration tools (living off the land) to evade security detections."
Federal Law Enforcement Action / FISA Court Authorized Operations
View full case dossier →
ALPHV / BlackCat Ransomware Attack on Change Healthcare
alleged 2024-02-21
Primary Source Evidence Excerpt: Senate Finance Committee Testimony ¶ 4
"The threat actor gained entry to a Change Healthcare Citrix portal using compromised credentials for an account that lacked multifactor authentication."
U.S. District Court for the District of Minnesota
View full case dossier →
Colonial Pipeline DarkSide Ransomware Attack
pleaded 2021-05-07
Primary Source Evidence Excerpt: Senate Homeland Security Committee Testimony
"The initial entry vector was a legacy Virtual Private Network account that was active without multifactor authentication using a password discovered in a dark web leak."
U.S. District Court for the Northern District of California
View full case dossier →
SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)
alleged 2020-12-13
Primary Source Evidence Excerpt: CISA Emergency Directive 21-01
"Adversaries abused stolen SAML signing keys to forge authentication tokens and bypass multifactor authentication in victim Microsoft 365 environments."
U.S. District Court for the Southern District of New York
View full case dossier →
U.S. v. Vachon-Desjardins (Netwalker Ransomware)
sentenced 2020-12-16
Primary Source Evidence Excerpt: Plea Agreement ¶ 4, Page 13
"Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials."
U.S. District Court for the Middle District of Florida
View full case dossier →
U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)
sentenced 2017-02-28
Primary Source Evidence Excerpt: Indictment ¶ 31, Page 18
"Adversaries created forged cryptographic authentication cookies to access Yahoo webmail accounts of targeted individuals without passwords."
U.S. District Court for the Northern District of California
View full case dossier →
U.S. v. Joshua Schulte (CIA Vault 7 Leak)
sentenced 2017-08-24
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 8
"Schulte abused his administrative credentials as a CIA Center for Cyber Intelligence software engineer to grant himself backdoor access to secure development servers."
U.S. District Court for the Southern District of New York
View full case dossier →
U.S. v. Paige Thompson (Capital One Cloud Breach)
convicted 2019-07-29
Primary Source Evidence Excerpt: Trial Transcript Day 3, Page 54
"Obtained temporary security credentials from the AWS EC2 instance metadata service to access private S3 storage buckets."
U.S. District Court for the Western District of Washington
View full case dossier →
Operation Cookie Monster (Genesis Market Takedown)
alleged 2023-04-04
Primary Source Evidence Excerpt: DOJ Seizure Affidavit ¶ 16
"Purchasers loaded stolen fingerprints into custom browser plugins to perfectly impersonate victim machines and bypass fraud detection."
U.S. District Court for the Eastern District of Wisconsin
View full case dossier →
U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)
sentenced 2020-08-25
Primary Source Evidence Excerpt: Criminal Complaint ¶ 12, Page 6
"Defendant recruited an insider with legitimate administrator privileges to connect an infected USB drive and execute custom malware within the company's intranet."
U.S. District Court for the District of Nevada
View full case dossier →
U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)
sentenced 2016-10-05
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes."
U.S. District Court for the Northern District of California
View full case dossier →
U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)
fugitive 2024-09-24
Primary Source Evidence Excerpt: CISA Advisory AA23-335A ¶ 4
"Defendants gained access to internet-connected Unitronics Vision PLCs because the industrial devices remained configured with the default manufacturer password '1111'."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
U.S. v. Kirill Victorovich Firsov (Deer.io Dark Web Shop)
sentenced 2020-03-04
Primary Source Evidence Excerpt: Indictment ¶ 8, Page 4
"Deer.io functioned as an automated turn-key storefront allowing hackers to upload and sell stolen user account databases in bulk."
U.S. District Court for the Southern District of California
View full case dossier →
U.S. v. Sergey Medvedev et al. (Infraud Organization)
sentenced 2018-01-26
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"Infraud operated escrow systems enabling cybercriminals to buy and sell verified high-balance administrative account credentials."
U.S. District Court for the District of Nevada
View full case dossier →
U.S. v. Denis Gennadievich Kulkov (Try2Check Card Checking Service)
fugitive 2023-04-18
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"Try2Check executed automated test transactions against merchant payment gateway APIs using stolen account logins."
U.S. District Court for the Eastern District of New York
View full case dossier →
U.S. v. Daniel Rhyne (Industrial Insider Extortion)
charged 2024-04-16
Primary Source Evidence Excerpt: Criminal Complaint ¶ 9, Page 4
"Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier."
U.S. District Court for the Western District of Missouri
View full case dossier →
Snowflake Customer Multi-Tenant Credential Stuffing Campaign
alleged 2024-05-31
Primary Source Evidence Excerpt: Mandiant Joint Advisory ¶ 2
"Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier."
U.S. District Court for the Northern District of California
View full case dossier →
U.S. v. Ilya Lichtenstein & Heather Morgan (Bitfinex Hack & Laundering)
sentenced 2022-02-07
Primary Source Evidence Excerpt: Statement of Offense ¶ 6, Page 3
"Lichtenstein gained access to Bitfinex's internal systems and authorized over 2,000 fraudulent cryptocurrency withdrawal transactions to private wallets."
U.S. District Court for the District of Columbia
View full case dossier →
Commonly Charged Criminal Statutes
18 U.S.C. § 1030(a)(2)
Unauthorized Access to Obtain Protected Information
Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.
18 U.S.C. § 1030(a)(5)(A)
Intentional Damage to a Protected Computer
Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.
18 U.S.C. § 1030(a)(7)
Extortion in Connection with Computers
Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.
18 U.S.C. § 1030(b)
Conspiracy to Commit Computer Fraud
Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.