Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.
Adversaries in possession of credentials to Valid Accounts may be unable to complete the login process if they lack access to the 2FA or MFA mechanisms required as an additional credential and security control. To circumvent this, adversaries may abuse the automatic generation of push notifications to MFA services such as Duo Push, Microsoft Authenticator, Okta, or similar services to have the user grant access to their account. If adversaries lack credentials to victim accounts, they may also abuse automatic push notification generation when this option is configured for self-service password reset (SSPR).(Citation: Obsidian SSPR Abuse 2023)
In some cases, adversaries may continuously repeat login attempts in order to bombard users with MFA push notifications, SMS messages, and phone calls, potentially resulting in the user finally accepting the authentication request in response to “MFA fatigue.”(Citation: Russian 2FA Push Annoyance - Cimpanu)(Citation: MFA Fatigue Attacks - PortSwigger)(Citation: Suspected Russian Activity Targeting Government and Business Entities Around the Globe)
View in MITRE ATT&CK®Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
---|---|---|---|---|---|
CM-05 | Access Restrictions for Change | mitigates | T1621 | Multi-Factor Authentication Request Generation | |
IA-05 | Authenticator Management | mitigates | T1621 | Multi-Factor Authentication Request Generation | |
IA-13 | Identity Providers and Authorization Servers | mitigates | T1621 | Multi-Factor Authentication Request Generation | |
IA-03 | Device Identification and Authentication | mitigates | T1621 | Multi-Factor Authentication Request Generation | |
IA-02 | Identification and Authentication (Organizational Users) | mitigates | T1621 | Multi-Factor Authentication Request Generation | |
AC-02 | Account Management | mitigates | T1621 | Multi-Factor Authentication Request Generation | |
AC-06 | Least Privilege | mitigates | T1621 | Multi-Factor Authentication Request Generation |
Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
---|---|---|---|---|---|
cloud_identity | Cloud Identity | technique_scores | T1621 | Multi-Factor Authentication Request Generation |
Comments
The Identity Platform can establish limits and quotas for MFA.
References
|
Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
---|---|---|---|---|---|
aws_identity_and_access_management | AWS Identity and Access Management | technique_scores | T1621 | Multi-Factor Authentication Request Generation |
Comments
AWS Identity and Access Management can be configured to lock at user out after repeated Multi-Factor Authentication requests.
References
|