FORENSIA

ATT&CK · T1557

Adversary-in-the-Middle

Tactics: credential-access, collection

About

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions. For example, adversaries may manipulate victim DNS settings to enable other malicious activities such as preventing/redirecting users from accessing legitimate sites and/or pushing additional malware. Adversaries may also manipulate DNS and leverage their position in order to intercept user credentials, including access tokens (Steal Application Access Token) and session cookies (Steal Web Session Cookie). Downgrade Attacks can also be used to establish an AiTM position, such as by negotiating a less secure, deprecated, or weaker version of communication protocol (SSL/TLS) or encryption algorithm. Adversaries may also leverage the AiTM position to attempt to monitor and/or modify traffic, such as in Transmitted Data Manipulation. Adversaries can setup a position similar to AiTM to prevent traffic from flowing to the appropriate destination, potentially to impair defenses and/or in support of a Network Denial of Service.

Platforms: Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗

Used by actors

3 known groups

Software

4 malware/tools implement this

DokNPPSPYLine Runnerevilginx2

Corpus indicators tagged with this technique

91 indicators in the corpus carry T1557.

IndicatorTypeFamilySevSrc
dce9ad6317ce147f1f3f74bc93d9252ahashransomware801
ea721240c14e3d14f8d88e0020880448c6c602f1180a1e5dbe40871cfeedcc22hashransomware801
70331fdf528f4f5b75b5e30427e379bc88aa05b4hashransomware801
c984787ccd787629542da68302ed4ceb48fc7e458eab1c15bf45c3070883d26ahash802
d65120291dee76c694f8bea54841f7f68329b499b28f4aee5ea5c9369a7432cbhashransomware801
d26bfb0147f60dc6500a9298d521ee67b49daaf4b8f8be54e7cc8fd86a597570hashransomware801
dc9938f51150d13a69fc25f3f19052eacb1bf0a086fd5cf39762501fb3ddd7dahashransomware801
1898d056463284d849801cbdea6a3dec6c9f568f01569912c3868a5eea9a5449hashransomware801
acce811c4fc2a6e3fddd4231e386f1648ca44f039d2d275316bc0a0fc96e0af4hashransomware801
765508aa2ec6a1b73a76a23f4fa559d32355622748c91a46ed7b315eae2ee60ahashransomware801
60aeb9f7bccf377ff02ed64783e66a62c0f976878d9729b067bc7e5b0b9da9d6hashransomware801
265a8e89464e32b22553ef16edbab703da7176a7hashransomware801
589d9480fbfec2d8e61638eb0b537183d0f9977411fd1d2c0f8eb611feebe880hashransomware801
524c953e23ff8b768206cf33a529c11ac5510e47cbf6246db79ee671d1231716hash802
f8cbe44fde6914bc8d06426c03c92ed536c891470292e567a586b54af29c2442hash802
6cd349eda0fa6c8b274a0920852c68f8b727afea1fdbc69ad183cef05d9cf141hashransomware801
bf8c45e5aa9551a17eefbd1d179422c32b4309c47ee9a3f315bb80ed6d4f7efchashransomware801
97aebda5482899fef84a24e456bff055acaa47e5ab4029f768d9e0c62a660ce2hashransomware801
16bad42a397db2e075e09b5b9dd53aaa67b495a4hashransomware801
03dd0efa84d145d7d4ed8e240267e5c5hashransomware801
31800380c359143ae82c4f9011eee653dd22443d03d6a499148203bbfc275502hashransomware801
f6a01d0246ce31faf6938ea488086d4358505405a4ef5c5faa482e79e92cb347hashransomware801
1d10d8f5a420d0e4683b4cb40bcf0c984d1e7ea1f3b4442a00a525584632ac11hashransomware801
24f6c0ca39b2a5593086ff56d818ddfbde121f8e44d54faa762e510397dc9db7hashransomware801
5cc212f84d2bf3fbab165aaf09b16e00fcf2f1ccd880d24b14404c53dcdbf241hashransomware801
6bf155b269d452f3c3b62832b27bbebe4da436e228dbf521155b1d5989e3743fhashransomware801
7f37351979c249417cb180b4ede0ed17e5fe2a1f08add4d72606b589f8fdb245hashransomware801
8d1a22c430252f29611766b8e4a82af0fba60d609246463466b384d6d4793df4hashransomware801
90e46e89fec2108a1cb4850bb33e3563e92a14d04e1e613ac8c9311f152d294chashransomware801
eb37c4fcfc00d3813ab94f4d59378b47hashransomware801

Showing the top 30 by severity of 91.