TACTIC: DEFENSE EVASION
Valid Accounts (T1078): real cases
MITRE Definition ↗ Adversaries obtain and misuse legitimate credentials of existing user accounts to maintain persistence and bypass controls.
Key Facts
Technique ID
T1078
Defense Evasion
Mapped Cases
28
Primary sources
Related Laws
4
Criminal statutes
- ATT&CK Technique Identifier: T1078.
- Tactical Phase: Defense Evasion.
- Substantiated in 28 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Khoroshev et al. (LockBit Ransomware Operation)
charged 2024-05-07
Primary Source Evidence Excerpt: Complaint ¶ 22
"Conspirators purchased compromised administrative account logins on Genesis Market to authenticate through victim VPN portals."
U.S. District Court for the District of New Jersey
View full case dossier →
Volt Typhoon Critical Infrastructure Pre-Positioning
alleged 2023-05-24
Primary Source Evidence Excerpt: CISA Advisory AA24-038A ¶ 3
"Volt Typhoon actors exclusively use legitimate credentials and built-in system administration tools (living off the land) to evade security detections."
Federal Law Enforcement Action / FISA Court Authorized Operations
View full case dossier →
ALPHV / BlackCat Ransomware Attack on Change Healthcare
alleged 2024-02-21
Primary Source Evidence Excerpt: Senate Finance Committee Testimony ¶ 4
"The threat actor gained entry to a Change Healthcare Citrix portal using compromised credentials for an account that lacked multifactor authentication."
U.S. District Court for the District of Minnesota
View full case dossier →
Colonial Pipeline DarkSide Ransomware Attack
pleaded 2021-05-07
Primary Source Evidence Excerpt: Senate Homeland Security Committee Testimony
"The initial entry vector was a legacy Virtual Private Network account that was active without multifactor authentication using a password discovered in a dark web leak."
U.S. District Court for the Northern District of California
View full case dossier →
SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)
alleged 2020-12-13
Primary Source Evidence Excerpt: CISA Emergency Directive 21-01
"Adversaries abused stolen SAML signing keys to forge authentication tokens and bypass multifactor authentication in victim Microsoft 365 environments."
U.S. District Court for the Southern District of New York
View full case dossier →
U.S. v. Vachon-Desjardins (Netwalker Ransomware)
sentenced 2020-12-16
Primary Source Evidence Excerpt: Plea Agreement ¶ 4, Page 13
"Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials."
U.S. District Court for the Middle District of Florida
View full case dossier →
U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)
sentenced 2017-02-28
Primary Source Evidence Excerpt: Indictment ¶ 31, Page 18
"Adversaries created forged cryptographic authentication cookies to access Yahoo webmail accounts of targeted individuals without passwords."
U.S. District Court for the Northern District of California
View full case dossier →
U.S. v. Joshua Schulte (CIA Vault 7 Leak)
sentenced 2017-08-24
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 8
"Schulte abused his administrative credentials as a CIA Center for Cyber Intelligence software engineer to grant himself backdoor access to secure development servers."
U.S. District Court for the Southern District of New York
View full case dossier →
U.S. v. Paige Thompson (Capital One Cloud Breach)
convicted 2019-07-29
Primary Source Evidence Excerpt: Trial Transcript Day 3, Page 54
"Obtained temporary security credentials from the AWS EC2 instance metadata service to access private S3 storage buckets."
U.S. District Court for the Western District of Washington
View full case dossier →
Operation Cookie Monster (Genesis Market Takedown)
alleged 2023-04-04
Primary Source Evidence Excerpt: DOJ Seizure Affidavit ¶ 16
"Purchasers loaded stolen fingerprints into custom browser plugins to perfectly impersonate victim machines and bypass fraud detection."
U.S. District Court for the Eastern District of Wisconsin
View full case dossier →
U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)
sentenced 2020-08-25
Primary Source Evidence Excerpt: Criminal Complaint ¶ 12, Page 6
"Defendant recruited an insider with legitimate administrator privileges to connect an infected USB drive and execute custom malware within the company's intranet."
U.S. District Court for the District of Nevada
View full case dossier →
U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)
sentenced 2016-10-05
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes."
U.S. District Court for the Northern District of California
View full case dossier →
U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)
fugitive 2024-09-24
Primary Source Evidence Excerpt: CISA Advisory AA23-335A ¶ 4
"Defendants gained access to internet-connected Unitronics Vision PLCs because the industrial devices remained configured with the default manufacturer password '1111'."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
U.S. v. Kirill Victorovich Firsov (Deer.io Dark Web Shop)
sentenced 2020-03-04
Primary Source Evidence Excerpt: Indictment ¶ 8, Page 4
"Deer.io functioned as an automated turn-key storefront allowing hackers to upload and sell stolen user account databases in bulk."
U.S. District Court for the Southern District of California
View full case dossier →
U.S. v. Sergey Medvedev et al. (Infraud Organization)
sentenced 2018-01-26
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"Infraud operated escrow systems enabling cybercriminals to buy and sell verified high-balance administrative account credentials."
U.S. District Court for the District of Nevada
View full case dossier →
U.S. v. Denis Gennadievich Kulkov (Try2Check Card Checking Service)
fugitive 2023-04-18
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"Try2Check executed automated test transactions against merchant payment gateway APIs using stolen account logins."
U.S. District Court for the Eastern District of New York
View full case dossier →
U.S. v. Daniel Rhyne (Industrial Insider Extortion)
charged 2024-04-16
Primary Source Evidence Excerpt: Criminal Complaint ¶ 9, Page 4
"Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier."
U.S. District Court for the Western District of Missouri
View full case dossier →
Snowflake Customer Multi-Tenant Credential Stuffing Campaign
alleged 2024-05-31
Primary Source Evidence Excerpt: Mandiant Joint Advisory ¶ 2
"Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier."
U.S. District Court for the Northern District of California
View full case dossier →
U.S. v. Ilya Lichtenstein & Heather Morgan (Bitfinex Hack & Laundering)
sentenced 2022-02-07
Primary Source Evidence Excerpt: Statement of Offense ¶ 6, Page 3
"Lichtenstein gained access to Bitfinex's internal systems and authorized over 2,000 fraudulent cryptocurrency withdrawal transactions to private wallets."
U.S. District Court for the District of Columbia
View full case dossier →
Target Corporation Point-of-Sale Data Breach (Fazio Mechanical Ingress)
settled 2014-04-02
Primary Source Evidence Excerpt: Senate Commerce Committee Forensic Report, Page 12
"Attackers gained initial network entry using legitimate credentials stolen via a spearphishing email directed at Fazio Mechanical Services, an external HVAC contractor."
U.S. District Court for the District of Minnesota
View full case dossier →
MGM Resorts Cyberattack (Scattered Spider / ALPHV Vishing Ingress)
alleged 2023-10-05
Primary Source Evidence Excerpt: CISA Advisory AA23-320A, Page 4
"After securing initial access, attackers elevated their privileges into Okta Identity Cloud and Microsoft Azure tenants, establishing super administrator roles to persist across the enterprise."
U.S. District Court for the District of Nevada
View full case dossier →
U.S. v. Paige Thompson (Capital One AWS Cloud SSRF Breach)
sentenced 2019-08-28
Primary Source Evidence Excerpt: Trial Exhibit 14, Criminal Complaint ¶ 12
"The metadata response yielded temporary security credentials for an IAM role named *PRIV_WA_SCAN*, which possessed excessive permissions to enumerate and download files from Capital One Amazon S3 buckets."
U.S. District Court for the Western District of Pennsylvania and Western District of Washington
View full case dossier →
State of Florida v. Graham Ivan Clark (Twitter VIP Bitcoin Hijack)
sentenced 2020-07-31
Primary Source Evidence Excerpt: Twitter Technical Post-Mortem Investigation
"Using stolen employee credentials, Clark logged into Twitter internal customer service management portal ('God Mode'), which allowed direct account recovery email changes and instant password overrides."
Hillsborough County 13th Judicial Circuit Court
View full case dossier →
Change Healthcare Ransomware Outage (ALPHV / BlackCat)
convicted 2024-02-21
Primary Source Evidence Excerpt: Congressional Hearing Testimony of UnitedHealth Group CEO Andrew Witty, May 1, 2024
"Attackers logged into a production Citrix remote access portal using compromised employee credentials that were not protected by multi-factor authentication."
U.S. House Energy and Commerce Committee Oversight & HHS OCR
View full case dossier →
Snowflake Enterprise Credential Stuffing & Customer Cloud Thefts
alleged 2024-05-23
Primary Source Evidence Excerpt: Mandiant Threat Intelligence Special Report: UNC5537 Snowflake Campaign
"UNC5537 authenticated directly to enterprise customer Snowflake tenants using single-factor credentials previously captured by RedLine, Vidar, and Lumma infostealer Trojans on employee personal devices."
U.S. Securities and Exchange Commission & FBI Cyber Division
View full case dossier →
CDK Global BlackSuit Ransomware Incident
alleged 2024-06-19
Primary Source Evidence Excerpt: Class Action Complaint: 1:24-cv-05231 (N.D. Ill.)
"Attackers gained access to CDK enterprise networks using compromised administrator credentials, bypassing secondary verification checks."
U.S. District Court for the Northern District of Illinois
View full case dossier →
AT&T Cloud Telecom Call and Text Metadata Exfiltration
investigation 2024-07-12
Primary Source Evidence Excerpt: AT&T Form 8-K Current Report to SEC
"Attackers logged into AT&T customer Snowflake cloud workspace using compromised access tokens without hardware multi-factor verification."
U.S. Securities and Exchange Commission & DOJ National Security Division
View full case dossier →
Microsoft Corporate Executive Email Intrusion (Midnight Blizzard / SVR)
investigation 2024-01-19
Primary Source Evidence Excerpt: CISA Emergency Directive 24-02: Mitigating SVR Compromise
"After authenticating to the legacy test tenant, Midnight Blizzard created new OAuth credentials with high-privilege application permissions (full_access_as_app) to query Exchange Web Services."
U.S. Securities and Exchange Commission & CISA Emergency Directive 24-02
View full case dossier →
Commonly Charged Criminal Statutes
18 U.S.C. § 1030(a)(2)
Unauthorized Access to Obtain Protected Information
Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.
18 U.S.C. § 1030(a)(5)(A)
Intentional Damage to a Protected Computer
Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.
18 U.S.C. § 1030(a)(7)
Extortion in Connection with Computers
Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.
18 U.S.C. § 1030(b)
Conspiracy to Commit Computer Fraud
Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.