• Overview
    • Scam Map
    • Kill Chain
Recents

    Conversations will appear here

Technique

MFA Device Registration

Also known as: MFA Manipulation, Device Registration

PERSISTENCEPERSISTENCEMITRE ATT&CK: T1098.005 Account Manipulation: Device Registration -- Describes adversaries enrolling new devices in MFA systems like Duo or Okta after compromising credentials, to bypass initial MFA requirements and gain persistent access.

After gaining access to a victim's account -- typically via adversary-in-the-middle phishing, session hijacking, or stolen credentials -- attackers register their own authenticator app or security key as an additional MFA method. Because most platforms (including Microsoft 365) do not require MFA re…

Common attack flows

How it fits in a scam

This technique shows up duringPERSISTENCE

Before

  • Account TakeoverEXPLOITATION
  • Cookie HijackingCOMPROMISE

After

  • Email Forwarding PersistencePERSISTENCE
  • Payment Method InjectionPERSISTENCE
  • Fund SiphoningMONETIZATION

Defense

How to defend against this

How to spot it

  • Unfamiliar authenticator apps or security keys listed in your account security settings that you did not add
  • Notification emails from services about new sign-in methods being registered (if the service sends them)
  • Continued unauthorized access to your accounts even after you have changed your password
  • Unexpected MFA prompts appearing on a device you do not recognize (indicating attacker is using your account with their enrolled MFA)
  • Account activity from unfamiliar devices or locations visible in sign-in history after you believed the account was re-secured
  • Being unable to remove an MFA method you do not recognize
  • or finding it re-added after removal

Tools you can use

  • Hardware Security KeysCost medium · Effect high

Further reading

  • Proofpoint

    Cybersecurity Stop of the Month: MFA Manipulation -- Proofpoint details how bad actors introduce their own MFA method into compromised Microsoft 365 cloud accounts, combining MFA manipulation with OAuth application abuse for persistence.

  • Mitiga

    Advisory on persistent MFA circumvention in an advanced BEC campaign on Microsoft 365. Documents attackers registering a second Authenticator app on a compromised executive's account within seconds, achieving full persistence that nullified MFA value.

  • MITRE ATT&CK

    T1098.005 Account Manipulation: Device Registration -- Describes adversaries enrolling new devices in MFA systems like Duo or Okta after compromising credentials, to bypass initial MFA requirements and gain persistent access.

  • Obsidian Security

    Behind The Breach: MFA Everywhere, Yes. MFA For Everyone, No. -- Describes how attackers exploit weak MFA registration policies by registering their own MFA methods once they gain access to an account without MFA, establishing persistent access.

  • Help Net Security

    How attackers use and abuse Microsoft MFA -- Reports on the Mitiga finding that Microsoft does not require MFA re-challenge for accessing and changing user authentication methods, enabling persistent access even from extremely brief compromise windows.

  • Microsoft Security Blog

    Evolved phishing: Device registration trick adds to phishers' toolbox -- Microsoft documents a large-scale phishing campaign where attackers registered unmanaged devices to Azure AD after stealing credentials, enabling lateral phishing from within the organization.

Related techniques

Variants

  • Cloud Account Persistence

Same stage

  • Remote Access Tool
  • Email Forwarding Persistence
  • Payment Method Injection
  • Stalkerware
  • Account Recovery Backdoor
  • +2 more

Similar defense

  • Data Breach Harvesting
  • Man In The Middle
  • Account Takeover
  • SIM Swap
  • MFA Fatigue Attack
  • +2 more