Skip to content
← RegistryDossier · 5 steps · 4 edges

Insider admin panel coercion → mass account takeover (Twitter 2020)

Identify employees with access to an internal admin panel. SE / coerce one to use the panel to change target accounts' email + 2FA, then take them over.

Filed by AD Knowledge Base
§ Kill-chainDrag · zoom · scroll

§ Context

Assumed environment: target operates a consumer platform with an internal admin panel that bypasses normal auth on user accounts. Helpdesk / customer-support employees have access broadly.

§ Steps

  1. 01
    Post scam content / drain walletsExfiltration
    T1041Exfiltration Over C2 Channel
  2. 02
    Attacker resets password, logs inInitial Access
    T1078Valid Accounts
  3. 03
    Identify employees with panel accessReconnaissance
    W-RECON-GITHUB-DORKGitHub / GitLab Dorking
  4. 04
    Employee changes victim email + 2FACredential Access
    T1556Modify Authentication Process
  5. 05
    Social engineer / bribe employeeInitial Access
    APT-INSIDER-PANELInsider Admin-Panel Coercion (Twitter 2020)

§ References

§ Frequently asked

What is the "Insider admin panel coercion → mass account takeover (Twitter 2020)" attack path?
Identify employees with access to an internal admin panel. SE / coerce one to use the panel to change target accounts' email + 2FA, then take them over. It chains 5 steps drawn from real-world offensive-security techniques.
What starting position does this attack require?
The first step is Post scam content / drain wallets (T1041) — a exfiltration primitive. Assumed environment: target operates a consumer platform with an internal admin panel that bypasses normal auth on user accounts.
What is the final impact of this kill-chain?
The final step lands on Social engineer / bribe employee (APT-INSIDER-PANEL), which falls under Initial Access. From here, an operator typically pivots into post-exploitation or maintains persistence.
How can defenders detect or prevent this attack?
Detection and prevention vary per step. Refer to each linked MITRE ATT&CK entry under "References" — every technique on that page lists defensive controls, detection telemetry, and known threat-actor usage.

§ Related dossiers