T1669
About this technique
Adversaries may gain initial access to target systems by connecting to wireless networks.
Read the full ATT&CK description
They may accomplish this by exploiting open Wi-Fi networks used by target devices or by accessing secured Wi-Fi networks — requiring Valid Accounts — belonging to a target organization.(Citation: DOJ GRU Charges 2018)(Citation: Nearest Neighbor Volexity) Establishing a connection to a Wi-Fi access point requires a certain level of proximity to both discover and maintain a stable network connection.
Adversaries may establish a wireless connection through various methods, such as by physically positioning themselves near a Wi-Fi network to conduct close access operations. To bypass the need for physical proximity, adversaries may attempt to remotely compromise nearby third-party systems that have both wired and wireless network connections available (i.e., dual-homed systems).
These third-party compromised devices can then serve as a bridge to connect to a target’s Wi-Fi network.(Citation: Nearest Neighbor Volexity)
Once an initial wireless connection is achieved, adversaries may leverage this access for follow-on activities in the victim network or further targeting of specific devices on the network.
Adversaries may perform Network Sniffing or Adversary-in-the-Middle activities for Credential Access or Discovery.
Curated incident relationships
These associations come from maintained incident records. The recorded confidence is shown when the source record provides it.
Daily items linked through predicted CVEs
A Daily item appears here when it mentions a CVE whose triage artifact predicts this technique. This is not a verified ATT&CK mapping.
Predicted CVE associations
These backfilled or model-produced candidates come from the current triage artifact. They are informational, not official MITRE mappings.