ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1589.002×

14 examples

TechniqueUsed byProcedure example
T1589.002
Email Addresses
GroupKimsuky

Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering.

T1589.002
Email Addresses
GroupEXOTIC LILY

EXOTIC LILY has gathered targeted individuals' e-mail addresses through open source research and website contact forms.

T1589.002
Email Addresses
GroupVolt Typhoon

Volt Typhoon has targeted the personal emails of key network and IT staff at victim organizations.

T1589.002
Email Addresses
GroupAPT32

APT32 has collected e-mail addresses for activists and bloggers in order to target them with spyware.

T1589.002
Email Addresses
GroupHAFNIUM

HAFNIUM has collected e-mail addresses for users they intended to target.

T1589.002
Email Addresses
GroupSandworm Team

Sandworm Team has obtained valid emails addresses while conducting research against target organizations that were subsequently used in spearphishing campaigns.

T1589.002
Email Addresses
GroupSaint Bear

Saint Bear gathered victim email information in advance of phishing operations for targeted attacks.

T1589.002
Email Addresses
GroupSilent Librarian

Silent Librarian has collected e-mail addresses from targeted organizations from open Internet searches.

T1589.002
Email Addresses
GroupTA551

TA551 has used spoofed company emails that were acquired from email clients on previously infected hosts to target other individuals.

T1589.002
Email Addresses
GroupLazarus Group

Lazarus Group collected email addresses belonging to various departments of a targeted organization which were used in follow-on phishing campaigns.

T1589.002
Email Addresses
GroupLAPSUS$

LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts.

T1589.002
Email Addresses
GroupMoonstone Sleet

Moonstone Sleet gathered victim email address information for follow-on phishing activity.

T1589.002
Email Addresses
GroupHEXANE

HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing.

T1589.002
Email Addresses
GroupMagic Hound

Magic Hound has identified high-value email accounts in academia, journalism, NGO's, foreign policy, and national security for targeting.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.