FORENSIA

ATT&CK · T1056.003 · sub-technique

Web Portal Capture

Tactics: collection, credential-access

About

Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login page may log provided user credentials before logging the user in to the service. This variation on input capture may be conducted post-compromise using legitimate administrative access as a backup measure to maintain network access through External Remote Services and Valid Accounts or as part of the initial compromise by exploitation of the externally facing web service.

Platforms: Linux, macOS, WindowsParent: T1056 Input CaptureMITRE ATT&CK ↗

Used by actors

2 known groups

Software

2 malware/tools implement this

IceAppleWARPWIRE

Corpus indicators tagged with this technique

261 indicators in the corpus carry T1056.003.