Real-world descriptions of how a group, tool or campaign used a technique.
14 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1589.002 Email Addresses |
GroupKimsuky | Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering. |
| T1589.002 Email Addresses |
GroupEXOTIC LILY | EXOTIC LILY has gathered targeted individuals' e-mail addresses through open source research and website contact forms. |
| T1589.002 Email Addresses |
GroupVolt Typhoon | Volt Typhoon has targeted the personal emails of key network and IT staff at victim organizations. |
| T1589.002 Email Addresses |
GroupAPT32 | APT32 has collected e-mail addresses for activists and bloggers in order to target them with spyware. |
| T1589.002 Email Addresses |
GroupHAFNIUM | HAFNIUM has collected e-mail addresses for users they intended to target. |
| T1589.002 Email Addresses |
GroupSandworm Team | Sandworm Team has obtained valid emails addresses while conducting research against target organizations that were subsequently used in spearphishing campaigns. |
| T1589.002 Email Addresses |
GroupSaint Bear | Saint Bear gathered victim email information in advance of phishing operations for targeted attacks. |
| T1589.002 Email Addresses |
GroupSilent Librarian | Silent Librarian has collected e-mail addresses from targeted organizations from open Internet searches. |
| T1589.002 Email Addresses |
GroupTA551 | TA551 has used spoofed company emails that were acquired from email clients on previously infected hosts to target other individuals. |
| T1589.002 Email Addresses |
GroupLazarus Group | Lazarus Group collected email addresses belonging to various departments of a targeted organization which were used in follow-on phishing campaigns. |
| T1589.002 Email Addresses |
GroupLAPSUS$ | LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts. |
| T1589.002 Email Addresses |
GroupMoonstone Sleet | Moonstone Sleet gathered victim email address information for follow-on phishing activity. |
| T1589.002 Email Addresses |
GroupHEXANE | HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing. |
| T1589.002 Email Addresses |
GroupMagic Hound | Magic Hound has identified high-value email accounts in academia, journalism, NGO's, foreign policy, and national security for targeting. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.