Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1114.001 Local Email Collection |
ToolPupy | Pupy can interact with a victim’s Outlook session and look through folders and emails. |
| T1114.002 Remote Email Collection |
CampaignHomeLand Justice | During HomeLand Justice, threat actors made multiple HTTP POST requests to the Exchange servers of the victim organization to transfer data. |
| T1114.002 Remote Email Collection |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 collected emails from specific individuals, such as executives and IT staff, using `New-MailboxExportRequest` followed by `Get-MailboxExportRequest`. |
| T1114.002 Remote Email Collection |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to gather data and email messages from Exchange services related to OT topics and technical work carried out within organizations. |
| T1114.002 Remote Email Collection |
GroupKimsuky | Kimsuky has used tools such as the MailFetch mail crawler to collect victim emails (excluding spam) from online services via IMAP. |
| T1114.002 Remote Email Collection |
GroupDragonfly | Dragonfly has accessed email accounts using Outlook Web Access. |
| T1114.002 Remote Email Collection |
GroupHAFNIUM | HAFNIUM has used web shells and MSGraph to export mailbox data. |
| T1114.002 Remote Email Collection |
GroupLeafminer | Leafminer used a tool called MailSniper to search through the Exchange server mailboxes for keywords. |
| T1114.002 Remote Email Collection |
GroupKe3chang | Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes. |
| T1114.002 Remote Email Collection |
GroupAPT1 | APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived. |
| T1114.002 Remote Email Collection |
GroupAPT29 | APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests. |
| T1114.002 Remote Email Collection |
GroupChimera | Chimera has harvested data from remote mailboxes including through execution of |
| T1114.002 Remote Email Collection |
GroupStar Blizzard | Star Blizzard has remotely accessed victims' email accounts to steal messages and attachments. |
| T1114.002 Remote Email Collection |
GroupAPT28 | APT28 has collected emails from victim Microsoft Exchange servers. |
| T1114.002 Remote Email Collection |
GroupFIN4 | FIN4 has accessed and hijacked online email communications using stolen credentials. |
| T1114.002 Remote Email Collection |
GroupVOID MANTICORE | VOID MANTICORE has gathered victim email-content from victim servers. |
| T1114.002 Remote Email Collection |
GroupMagic Hound | Magic Hound has exported emails from compromised Exchange servers including through use of the cmdlet `New-MailboxExportRequest.` |
| T1114.002 Remote Email Collection |
MalwareSeaDuke | Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials. |
| T1114.002 Remote Email Collection |
MalwareLightNeuron | LightNeuron collects Exchange emails matching rules specified in its configuration. |
| T1114.002 Remote Email Collection |
MalwareValak | Valak can collect sensitive mailing information from Exchange servers, including credentials and the domain certificate of an enterprise. |
| T1114.002 Remote Email Collection |
ToolMailSniper | MailSniper can be used for searching through email in Exchange and Office 365 environments. |
| T1114.003 Email Forwarding Rule |
GroupKimsuky | Kimsuky has set auto-forward rules on victim's e-mail accounts. |
| T1114.003 Email Forwarding Rule |
GroupScattered Spider | Scattered Spider has redirected emails notifying users of suspicious account activity. |
| T1114.003 Email Forwarding Rule |
GroupSilent Librarian | Silent Librarian has set up auto forwarding rules on compromised e-mail accounts. |
| T1114.003 Email Forwarding Rule |
GroupStar Blizzard | Star Blizzard has abused email forwarding rules to monitor the activities of a victim, steal information, and maintain persistent access after compromised credentials are reset. |
| T1114.003 Email Forwarding Rule |
GroupLAPSUS$ | LAPSUS$ has set an Office 365 tenant level mail transport rule to send all mail in and out of the targeted organization to the newly created account. |
| T1115 Clipboard Data |
CampaignOperation Wocao | During Operation Wocao, threat actors collected clipboard data in plaintext. |
| T1115 Clipboard Data |
GroupAPT38 | APT38 used a Trojan called KEYLIME to collect data from the clipboard. |
| T1115 Clipboard Data |
GroupKimsuky | Kimsuky has the ability to steal data from the clipboard. |
| T1115 Clipboard Data |
GroupAPT39 | APT39 has used tools capable of stealing contents of the clipboard. |
| T1115 Clipboard Data |
GroupOilRig | OilRig has used infostealer tools to copy clipboard data. |
| T1115 Clipboard Data |
MalwarePAKLOG | PAKLOG has monitored and extracted clipboard contents. |
| T1115 Clipboard Data |
MalwareZeus Panda | Zeus Panda can hook GetClipboardData function to watch for clipboard pastes to collect. |
| T1115 Clipboard Data |
MalwareInvisibleFerret | InvisibleFerret has stolen data from the clipboard using the Python project “pyperclip”. InvisibleFerret has also captured clipboard contents during copy and paste operations. |
| T1115 Clipboard Data |
MalwareBOOKWORM | BOOKWORM has used its KBLogger.dll module to steal data saved to the clipboard. |
| T1115 Clipboard Data |
MalwareCosmicDuke | CosmicDuke copies and exfiltrates the clipboard contents every 30 seconds. |
| T1115 Clipboard Data |
MalwareMachete | Machete hijacks the clipboard data by creating an overlapped window that listens to keyboard events. |
| T1115 Clipboard Data |
MalwareFlawedAmmyy | FlawedAmmyy can collect clipboard data. |
| T1115 Clipboard Data |
MalwareMispadu | Mispadu has the ability to capture and replace Bitcoin wallet data in the clipboard on a compromised host. |
| T1115 Clipboard Data |
MalwareVERMIN | VERMIN collects data stored in the clipboard. |
| T1115 Clipboard Data |
MalwareMarkiRAT | MarkiRAT can capture clipboard content. |
| T1115 Clipboard Data |
MalwareDarkComet | DarkComet can steal data from the clipboard. |
| T1115 Clipboard Data |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can capture content from the clipboard. |
| T1115 Clipboard Data |
MalwareDarkTortilla | DarkTortilla can download a clipboard information stealer module. |
| T1115 Clipboard Data |
MalwareROKRAT | ROKRAT can extract clipboard data from a compromised host. |
| T1115 Clipboard Data |
MalwareRunningRAT | RunningRAT contains code to open and copy data from the clipboard. |
| T1115 Clipboard Data |
MalwareExplosive | Explosive has a function to use the OpenClipboard wrapper. |
| T1115 Clipboard Data |
MalwareClambling | Clambling has the ability to capture and store clipboard data. |
| T1115 Clipboard Data |
MalwareDarkGate | DarkGate starts a thread on execution that captures clipboard data and logs it to a predefined log file. |
| T1115 Clipboard Data |
MalwareMetamorfo | Metamorfo has a function to hijack data from the clipboard by monitoring the contents of the clipboard and replacing the cryptocurrency wallet with the attacker's. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.