T1098.001Additional Cloud Credentials
T1098.001 — Additional Cloud Credentials is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 5 detection use cases covering it and 74 threat-intel articles citing it.
PersistencePrivilege Escalation
5Use cases
74Articles
0Sub-techniques
2Tactics
↑ Parent technique: T1098 · Account Manipulation
Use cases covering this technique (5)
OAuth consent / suspicious app grant [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Azure AD Service Principal New Client Credentials O365 Service Principal New Client CredentialsArticles citing this technique (74)
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97
high Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization art-114
crit Begun, the Patch Wars have art-150
crit When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website art-246
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-380
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-423
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-471
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-475
high Snyk Apps now GA: An easy, standardized, and secure framework for building custom integrations art-1488
crit API Security Guide art-1751