logo

MITRE ATT&CK T1078 Valid Accounts Explained

ID: b9a67696-d6fc-53c7-bec8-c65bb54586b0

STIX ID: report--b9a67696-d6fc-53c7-bec8-c65bb54586b0

Feed Name: Resources-2

Threat Score
80/100

Date Published: 2026-02-03

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren Hacıoğlu)

...
...

This report analyzes MITRE ATT&CK T1078 (Valid Accounts) and its four sub-techniques (default, domain, local, cloud), documents real-world abuse by multiple ransomware groups and APTs (e.g., DragonForce, Scattered Spider, Silk Typhoon, WARP PANDA), and highlights that credential-based access is highly effective and difficult to detect (citing a 98% success rate in tests). It emphasizes identity and cloud accounts as primary attack surfaces, details common adversary behaviors (credential theft, MFA abuse, service principal/OAuth misuse), and recommends validating identity-abuse paths rather than relying solely on vulnerability severity scoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.