ATT&CK Technique · Stealth / Persistence / Privilege Escalation / Initial Access
T1078 Valid AccountsMapped by 5 reports, 7 detection rules and 6 tracked actors on The Hunters Ledger. Technique page on attack.mitre.org.
← All techniques and the coverage heatmap
Reports
Each report maps this technique in its own ATT&CK table, at the confidence the report states. The link opens that table.
Report
AdvancedRouterScanner
Detection rules
Rules whose ATT&CK coverage line names this technique, by detection page. The link opens the page's coverage table.
Detection rules
Enough to Be Dangerous: The Mechanics of an LLM-Assisted Intrusion CampaignNewly Registered Account Probing Administrative Routes Within Minutes (Correlation) (SIGMA, Detection)
Detection rules
Russian Gemini CLI Credential Mill (213.165.51.115)Stolen LLM API Key Validator (YARA, Detection)
Detection rules
Turkish ARPA AI-Augmented Observability Compromise (209.38.205.158)Rule 4: Multi-Source Observability Polling Python Script (YARA, Detection); Sigma Rule 6: Long-Lived Instana JWT Detected in Audit Logs (Governance Baseline) (SIGMA, Detection); Sigma Rule 2: Outbound HTTPS to the Victim Organization Instana Tenant (SIGMA, Hunting); Sigma Rule 7: Observability Platform Authentication Event (Cross-Source Burst Indicator) (SIGMA, Hunting); DNS Query Egress to the Victim Organization Instana Tenant (SURICATA, Hunting)
Tracked actors
Designations whose reports map this technique.
- UTA-2026-011: Financially motivated operator weaponising a cPanel authentication bypass with a custom harvesting toolkit
- UTA-2026-012: AI-augmented credential-mill operator using an LLM for per-target password mutation
- UTA-2026-013: Espionage-flavoured operator harvesting a state-affiliated insurer's observability stack through an AI agent platform
- UTA-2026-018: Hands-on-keyboard operator exploiting four Southeast Asian governments with a bespoke edge-device toolkit
- UTA-2026-019: Grey-market personal-data harvester running scores of LLM-assisted attack scripts against Chinese consumer platforms
- UTA-2026-023: Telecom-focused operator reaching a carrier's credential plane through a customer's managed router
ATT&CK v19.2. MITRE ATT&CK® is a registered trademark of The MITRE Corporation; technique names are MITRE's and link to MITRE's own pages. The mapping on each linked page is this publication's reading of its own evidence.