Adversaries may target two-factor authentication mechanisms, such as smart cards, to gain access to credentials that can be used to access systems, services, and network resources. Use of two or multi-factor authentication (2FA or MFA) is recommended and provides a higher level of security than user names and passwords alone, but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms.
If a smart card is used for two-factor authentication, then a keylogger will need to be used to obtain the password associated with a smart card during normal use. With both an inserted card and access to the smart card password, an adversary can connect to a network resource using the infected system to proxy the authentication with the inserted hardware token. (Citation: Mandiant M Trends 2011)
Adversaries may also employ a keylogger to similarly target other hardware tokens, such as RSA SecurID. Capturing token input (including a user's personal identification code) may provide temporary access (i.e. replay the one-time passcode until the next value rollover) as well as possibly enabling adversaries to reliably predict future authentication values (given access to both the algorithm and any seed values used to generate appended temporary codes). (Citation: GCN RSA June 2011)
Other methods of 2FA may be intercepted and used by an adversary to authenticate. It is common for one-time codes to be sent via out-of-band communications (email, SMS). If the device and/or service is not secured, then it may be vulnerable to interception. Although primarily focused on by cyber criminals, these authentication mechanisms have been targeted by advanced actors. (Citation: Operation Emmental)
View in MITRE ATT&CK®Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name |
---|---|---|---|---|
CA-7 | Continuous Monitoring | Protects | T1111 | Two-Factor Authentication Interception |
CM-2 | Baseline Configuration | Protects | T1111 | Two-Factor Authentication Interception |
CM-6 | Configuration Settings | Protects | T1111 | Two-Factor Authentication Interception |
IA-2 | Identification and Authentication (organizational Users) | Protects | T1111 | Two-Factor Authentication Interception |
IA-5 | Authenticator Management | Protects | T1111 | Two-Factor Authentication Interception |
SI-3 | Malicious Code Protection | Protects | T1111 | Two-Factor Authentication Interception |
SI-4 | System Monitoring | Protects | T1111 | Two-Factor Authentication Interception |
action.hacking.variety.Unknown | Unknown | related-to | T1111 | Two-Factor Authentication Interception |