T1078.003 Local Accounts
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.
| Item | Value |
|---|---|
| ID | T1078.003 |
| Sub-techniques | T1078.001, T1078.002, T1078.003, T1078.004 |
| Tactics | TA0005, TA0003, TA0004, TA0001 |
| Platforms | Containers, ESXi, Linux, Network Devices, Windows, macOS |
| Version | 1.5 |
| Created | 13 March 2020 |
| Last Modified | 24 October 2025 |
Procedure Examples
| ID | Name | Description |
|---|---|---|
| G0016 | APT29 | APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence.22 |
| G0050 | APT32 | APT32 has used legitimate local admin account credentials.16 |
| S0154 | Cobalt Strike | Cobalt Strike can use known credentials to run commands and spawn processes as a local user account.67 |
| S0367 | Emotet | Emotet can brute force a local admin password, then use it to facilitate lateral movement.5 |
| G0051 | FIN10 | FIN10 has moved laterally using the Local Administrator account.14 |
| G0046 | FIN7 | FIN7 has used compromised credentials for access as SYSTEM on Exchange servers.20 |
| G0125 | HAFNIUM | HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers.19 |
| G0094 | Kimsuky | Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP.12 |
| C0049 | Leviathan Australian Intrusions | Leviathan used captured local account information, such as service accounts, for actions during Leviathan Australian Intrusions.25 |
| S1202 | LockBit 3.0 | LockBit 3.0 can use a compromised local account for lateral movement.10 |
| S0368 | NotPetya | NotPetya can use valid credentials with PsExec or wmic to spread itself to remote systems.89 |
| C0014 | Operation Wocao | During Operation Wocao, threat actors used local account credentials found during the intrusion for lateral movement and privilege escalation.26 |
| G1040 | Play | Play has used valid local accounts to gain initial access.15 |
| G0056 | PROMETHIUM | PROMETHIUM has created admin accounts on a compromised host.13 |
| G1041 | Sea Turtle | Sea Turtle compromised cPanel accounts in victim environments.17 |
| C0024 | SolarWinds Compromise | During the SolarWinds Compromise, APT29 used compromised local accounts to access victims’ networks.24 |
| G0081 | Tropic Trooper | Tropic Trooper has used known administrator account credentials to execute the backdoor directly.18 |
| G0010 | Turla | Turla has abused local accounts that have the same password across the victim’s network.23 |
| S0221 | Umbreon | Umbreon creates valid local users to provide access to the system.11 |
| G1047 | Velvet Ant | Velvet Ant accessed vulnerable Cisco switch devices using accounts with administrator privileges.21 |
Mitigations
| ID | Mitigation | Description |
|---|---|---|
| M1032 | Multi-factor Authentication | Enable multi-factor authentication (MFA) for local accounts to add an extra layer of protection against credential theft and misuse. MFA can be implemented using methods like mobile-based authenticators or hardware tokens, even in environments that do not rely on domain controllers or cloud services. This additional security measure can help reduce the risk of adversaries gaining unauthorized access to local systems and resources. |
| M1027 | Password Policies | Ensure that local administrator accounts have complex, unique passwords across all systems on the network. |
| M1026 | Privileged Account Management | Audit local accounts permission levels routinely to look for situations that could allow an adversary to gain wide access by obtaining credentials of a privileged account. 3 4 Limit the usage of local administrator accounts to be used for day-to-day operations that may expose them to potential adversaries. |
| M1018 | User Account Management | Enforce user account management practices for local accounts to limit access and remove inactive or unused accounts. By doing so, you reduce the attack surface available to adversaries and prevent unauthorized access to local systems. |
References
-
Kubernetes. (2022, February 26). Configure Service Accounts for Pods. Retrieved April 1, 2022. ↩
-
Margosis, A.. (2018, December 10). Remote Use of Local Accounts: LAPS Changes Everything. Retrieved March 13, 2020. ↩
-
Microsoft. (2016, April 15). Attractive Accounts for Credential Theft. Retrieved June 3, 2016. ↩
-
Microsoft. (2016, April 16). Implementing Least-Privilege Administrative Models. Retrieved June 3, 2016. ↩
-
Smith, A.. (2017, December 22). Protect your network from Emotet Trojan with Malwarebytes Endpoint Security. Retrieved January 17, 2019. ↩
-
Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017. ↩
-
Mudge, R. (2017, May 23). Cobalt Strike 3.8 – Who’s Your Daddy?. Retrieved June 4, 2019. ↩
-
Chiu, A. (2016, June 27). New Ransomware Variant “Nyetya” Compromises Systems Worldwide. Retrieved March 26, 2019. ↩
-
US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019. ↩
-
FBI et al. (2023, March 16). #StopRansomware: LockBit 3.0. Retrieved February 5, 2025. ↩
-
Fernando Mercês. (2016, September 5). Pokémon-themed Umbreon Linux Rootkit Hits x86, ARM Systems. Retrieved March 5, 2018. ↩
-
ASERT team. (2018, December 5). STOLEN PENCIL Campaign Targets Academia. Retrieved February 5, 2019. ↩
-
Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020. ↩
-
FireEye iSIGHT Intelligence. (2017, June 16). FIN10: Anatomy of a Cyber Extortion Operation. Retrieved November 17, 2024. ↩
-
Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024. ↩
-
Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017. ↩
-
Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024. ↩
-
Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020. ↩
-
Bromiley, M. et al. (2021, March 4). Detection and Response to Exploitation of Microsoft Exchange Zero-Day Vulnerabilities. Retrieved March 9, 2021. ↩
-
Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023. ↩
-
Sygnia Team. (2024, July 1). China-Nexus Threat Group ‘Velvet Ant’ Exploits Cisco Zero-Day (CVE-2024-20399) to Compromise Nexus Switch Devices – Advisory for Mitigation and Response. Retrieved March 14, 2025. ↩
-
UK National Cyber Security Center et al. (2024, February). SVR cyber actors adapt tactics for initial cloud access. Retrieved March 1, 2024. ↩
-
Faou, M. (2020, December 2). Turla Crutch: Keeping the “back door” open. Retrieved December 4, 2020. ↩
-
CrowdStrike. (2022, January 27). Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign. Retrieved February 7, 2022. ↩
-
CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025. ↩
-
Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020. ↩