Meta tags:
Headings (most frequently used words):
multi, factor, authentication, interception, procedure, examples, mitigations, detection, strategy, references,
Text of the page (most frequently used words):
and (18), authentication (16), the (15), retrieved (13), att (10), all (10), for (10), may (10), used (10), smart (9), techniques (8), 2024 (8), access (8), mfa (8), #factor (8), enterprise (7), tokens (7), user (7), card (7), input (6), can (6), has (6), use (5), ics (5), mobile (5), none (5), detection (5), january (5), one (5), october (5), apt42 (5), via (5), interception (5), intercept (5), token (5), multi (5), mitre (4), resources (4), data (4), operation (4), phishing (4), during (4), passwords (4), time (4), codes (4), sms (4), version (4), with (4), 2026 (3), groups (3), cti (3), mitigations (3), defenses (3), sub (3), sykipot (3), cards (3), 2021 (3), pulse (3), bypass (3), february (3), wocao (3), security (3), 2022 (3), target (3), 2fa (3), services (3), mandiant (3), 2011 (3), using (3), keylogger (3), capture (3), not (3), description (3), that (3), network (3), hardware (3), compromised (3), two (3), values (3), leviathan (3), sent (3), adversary (3), service (3), adversaries (3), corporation (2), are (2), registered (2), domains (2), reference (2), campaigns (2), software (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), windows (2), 2016 (2), actors (2), secure (2), 2019 (2), china (2), july (2), march (2), dev (2), targeting (2), organizations (2), resource (2), next (2), rsa (2), polling (2), interaction (2), behavior (2), non (2), strategy (2), analytic (2), name (2), proxy (2), credentials (2), procedure (2), slowpulse (2), threat (2), australian (2), intrusions (2), approval (2), will (2), lapsus (2), kimsuky (2), evilginx2 (2), users (2), chimera (2), intercepted (2), t1111 (2), other (2), then (2), also (2), temporary (2), both (2), password (2), inserted (2), mechanisms (2), ckcon (2), person (2), tickets (2), faq (2), 2015, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, blasco, 2012, variant, hijacks, dod, perez, april, check, your, suspected, apt, leverage, zero, day, dantzig, schamper, december, shining, light, hidden, hacking, 2020, cisa, people, republic, prc, ministry, state, apt40, tradecraft, action, 2025, mstic, dart, m365, defender, 0537, criminal, actor, exfiltration, destruction, kisa, reconnaissance, attack, analysis, muzabi, gretzky, 2018, evilginx, generation, jansen, abusing, cloud, fly, under, radar, september, rozmann, uncharmed, untangling, iran, operations, crooked, charms, cons, compromises, okta, august, detecting, scatter, swine, insights, into, relentless, campaign, 2023, jackson, william, june, confirms, its, lockheed, hack, november, trends, references, processes, accessing, tcc, protected, apis, hid, without, dynamically, loaded, keylogging, frameworks, accessibility, privileges, an0689, unauthorized, through, loading, kernel, modules, insmod, devices, from, shells, an0688, chain, involving, unexpected, api, calls, keyboard, driver, loads, keyloggers, remote, logon, sessions, initiated, local, an0687, proxying, det0246, remove, when, training, m1017, mitigation, known, contain, functionality, enables, technologies, connections, restricted, detected, s0018, log, vpns, ace, dsauth, aceauthserver, checkusernamepassword, s1104, custom, collection, method, soft, c0014, abused, appliance, collect, multifactor, c0049, replayed, stolen, session, trigger, simple, prompts, hope, legitimate, grant, necessary, g1004, proprietary, tool, required, g0094, enable, resistant, forms, s9003, alternate, phone, numbers, g0114, based, set, additionally, cloned, fake, websites, g1044, examples, live, permalink, last, modified, 2017, created, john, lambert, microsoft, intelligence, center, contributors, linux, macos, platforms, credential, tactic, methods, authenticate, common, out, band, communications, email, device, secured, vulnerable, providers, targeted, example, compromise, messaging, order, steal, phones, employ, similarly, such, securid, capturing, including, personal, identification, code, provide, replay, passcode, until, value, rollover, well, possibly, enabling, reliably, predict, future, given, algorithm, any, seed, generate, appended, need, obtain, associated, normal, connect, infected, system, generators, etc, gain, systems, recommended, provides, higher, level, than, usernames, alone, but, should, aware, could, these, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, about, get, started, detections, technique,
Text of the page (random words):
multi factor authentication interception technique t1111 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise multi factor authentication interception multi factor authentication interception adversaries may target multi factor authentication mfa mechanisms i e smart cards token generators etc to gain access to credentials that can be used to access systems services and network resources use of mfa is recommended and provides a higher level of security than usernames and passwords alone but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms if a smart card is used for multi factor authentication then a keylogger will need to be used to obtain the password associated with a smart card during normal use with both an inserted card and access to the smart card password an adversary can connect to a network resource using the infected system to proxy the authentication with the inserted hardware token 1 adversaries may also employ a keylogger to similarly target other hardware tokens such as rsa securid capturing token input including a user s personal identification code may provide temporary access i e replay the one time passcode until the next value rollover as well as possibly enabling adversaries to reliably predict future authentication values given access to both the algorithm and any seed values used to generate appended temporary codes 2 other methods of mfa may be intercepted and used by an adversary to authenticate it is common for one time codes to be sent via out of band communications email sms if the device and or service is not secured then it may be vulnerable to interception service providers can also be targeted for example an adversary may compromise an sms messaging service in order to steal mfa codes sent to users phones 3 id t1111 sub techniques no sub techniques ⓘ tactic credential access ⓘ platforms linux windows macos contributors john lambert microsoft threat intelligence center version 2 1 created 31 may 2017 last modified 12 may 2026 version permalink live version procedure examples id name description g1044 apt42 apt42 has intercepted sms based one time passwords and has set up two factor authentication 4 additionally apt42 has used cloned or fake websites to capture mfa tokens 5 g0114 chimera chimera has registered alternate phone numbers for compromised users to intercept 2fa codes sent via sms 6 s9003 evilginx2 evilginx2 can intercept authentication tokens to enable bypass of non phishing resistant forms of mfa 7 g0094 kimsuky kimsuky has used a proprietary tool to intercept one time passwords required for two factor authentication 8 g1004 lapsus lapsus has replayed stolen session token and passwords to trigger simple approval mfa prompts in hope of the legitimate user will grant necessary approval 9 c0049 leviathan australian intrusions leviathan abused compromised appliance access to collect multifactor authentication token values during leviathan australian intrusions 10 c0014 operation wocao during operation wocao threat actors used a custom collection method to intercept two factor authentication soft tokens 11 s1104 slowpulse slowpulse can log credentials on compromised pulse secure vpns during the dsauth aceauthserver checkusernamepassword ace 2fa authentication procedure 12 s0018 sykipot sykipot is known to contain functionality that enables targeting of smart card technologies to proxy authentication for connections to restricted network resources using detected hardware tokens 13 mitigations id mitigation description m1017 user training remove smart cards when not in use detection strategy id name analytic id analytic description det0246 detection strategy for mfa interception via input capture and smart card proxying an0687 behavior chain involving unexpected api calls to capture keyboard input driver loads for keyloggers or remote use of smart card authentication via logon sessions not initiated by local user interaction an0688 detection of unauthorized keylogger behavior through access to dev input loading kernel modules e g via insmod or polling user input devices from non user shells an0689 processes accessing tcc protected input apis or polling hid services without user interaction or dynamically loaded keylogging frameworks using accessibility privileges references mandiant 2011 january 27 mandiant m trends 2011 retrieved january 10 2016 jackson william 2011 june 7 rsa confirms its tokens used in lockheed hack retrieved november 17 2024 okta 2022 august 25 detecting scatter swine insights into a relentless phishing campaign retrieved february 24 2023 mandiant n d apt42 crooked charms cons and compromises retrieved october 9 2024 rozmann o et al 2024 may 1 uncharmed untangling iran s apt42 operations retrieved october 9 2024 jansen w 2021 january 12 abusing cloud services to fly under the radar retrieved september 12 2024 gretzky k 2018 july 26 evilginx 2 next generation of phishing 2fa tokens retrieved october 14 2019 kisa 2021 phishing target reconnaissance and attack resource analysis operation muzabi retrieved march 8 2024 mstic dart m365 defender 2022 march 24 dev 0537 criminal actor targeting organizations for data exfiltration and destruction retrieved may 17 2022 cisa et al 2024 july 8 people s republic of china prc ministry of state security apt40 tradecraft in action retrieved february 3 2025 dantzig m v schamper e 2019 december 19 operation wocao shining a light on one of china s hidden hacking groups retrieved october 8 2020 perez d et al 2021 april 20 check your pulse suspected apt actors leverage authentication bypass techniques and pulse secure zero day retrieved february 5 2024 blasco j 2012 january 12 sykipot variant hijacks dod and windows smart cards retrieved january 10 2016 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|