Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1114.002 Remote Email Collection |
GroupKimsuky | Kimsuky has used tools such as the MailFetch mail crawler to collect victim emails (excluding spam) from online services via IMAP. |
| T1114.002 Remote Email Collection |
GroupDragonfly | Dragonfly has accessed email accounts using Outlook Web Access. |
| T1114.002 Remote Email Collection |
GroupHAFNIUM | HAFNIUM has used web shells and MSGraph to export mailbox data. |
| T1114.002 Remote Email Collection |
GroupLeafminer | Leafminer used a tool called MailSniper to search through the Exchange server mailboxes for keywords. |
| T1114.002 Remote Email Collection |
GroupKe3chang | Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes. |
| T1114.002 Remote Email Collection |
GroupAPT1 | APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived. |
| T1114.002 Remote Email Collection |
GroupAPT29 | APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests. |
| T1114.002 Remote Email Collection |
GroupChimera | Chimera has harvested data from remote mailboxes including through execution of |
| T1114.002 Remote Email Collection |
GroupStar Blizzard | Star Blizzard has remotely accessed victims' email accounts to steal messages and attachments. |
| T1114.002 Remote Email Collection |
GroupAPT28 | APT28 has collected emails from victim Microsoft Exchange servers. |
| T1114.002 Remote Email Collection |
GroupFIN4 | FIN4 has accessed and hijacked online email communications using stolen credentials. |
| T1114.002 Remote Email Collection |
GroupVOID MANTICORE | VOID MANTICORE has gathered victim email-content from victim servers. |
| T1114.002 Remote Email Collection |
GroupMagic Hound | Magic Hound has exported emails from compromised Exchange servers including through use of the cmdlet `New-MailboxExportRequest.` |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.