Suspicious AWS Virtual MFA Device Creation

PremiumReviewedSigma · Medium · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-09-16
Updated
2026-09-16

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the CreateVirtualMFADevice API call in AWS CloudTrail, used by the DPRK cryptocurrency-heist actors to register attacker-controlled MFA devices for persistent access to compromised identities. Unexpected MFA device creation may indicate account takeover and persistence via multi-factor manipulation and should be correlated with the acting principal.

Related detections4 linkedT1098.005 — drag to rearrange
Suspicious Device Registration Following OAuth Token Theft
Suspicious Workday Payment Election Change via Compromised Account (via workday)
Possible Rogue Device Registration in Entra ID After Device Code Phishing
Suspicious Exchange Online Mail Flow Rule or Connector Creation via Compromised Account
Suspicious AWS Virtual MFA Device Creation
Pivot detection · T1098.005 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.