ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1114.002×

13 examples

TechniqueUsed byProcedure example
T1114.002
Remote Email Collection
GroupKimsuky

Kimsuky has used tools such as the MailFetch mail crawler to collect victim emails (excluding spam) from online services via IMAP.

T1114.002
Remote Email Collection
GroupDragonfly

Dragonfly has accessed email accounts using Outlook Web Access.

T1114.002
Remote Email Collection
GroupHAFNIUM

HAFNIUM has used web shells and MSGraph to export mailbox data.

T1114.002
Remote Email Collection
GroupLeafminer

Leafminer used a tool called MailSniper to search through the Exchange server mailboxes for keywords.

T1114.002
Remote Email Collection
GroupKe3chang

Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes.

T1114.002
Remote Email Collection
GroupAPT1

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived.

T1114.002
Remote Email Collection
GroupAPT29

APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests.

T1114.002
Remote Email Collection
GroupChimera

Chimera has harvested data from remote mailboxes including through execution of \\<hostname>\c$\Users\<username>\AppData\Local\Microsoft\Outlook*.ost.

T1114.002
Remote Email Collection
GroupStar Blizzard

Star Blizzard has remotely accessed victims' email accounts to steal messages and attachments.

T1114.002
Remote Email Collection
GroupAPT28

APT28 has collected emails from victim Microsoft Exchange servers.

T1114.002
Remote Email Collection
GroupFIN4

FIN4 has accessed and hijacked online email communications using stolen credentials.

T1114.002
Remote Email Collection
GroupVOID MANTICORE

VOID MANTICORE has gathered victim email-content from victim servers.

T1114.002
Remote Email Collection
GroupMagic Hound

Magic Hound has exported emails from compromised Exchange servers including through use of the cmdlet `New-MailboxExportRequest.`

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.