Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1087.003 Email Account |
MalwareTrickBot | TrickBot collects email addresses from Outlook. |
| T1087.003 Email Account |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects address book information from Outlook. |
| T1087.003 Email Account |
MalwareEmotet | Emotet has been observed leveraging a module that can scrape email addresses from Outlook. |
| T1087.003 Email Account |
MalwareGrandoreiro | Grandoreiro can parse Outlook .pst files to extract e-mail addresses. |
| T1087.003 Email Account |
MalwareBoomBox | BoomBox can execute an LDAP query to discover e-mail accounts for domain users. |
| T1087.003 Email Account |
MalwareLizar | Lizar can collect email accounts from Microsoft Outlook and Mozilla Thunderbird. |
| T1087.003 Email Account |
ToolRuler | Ruler can be used to enumerate Exchange users and dump the GAL. |
| T1087.003 Email Account |
ToolMailSniper | MailSniper can be used to obtain account names from Exchange and Office 365 using the |
| T1087.003 Email Account |
MalwareKali365 | Kali365 has leveraged an Exchange Admin module that utilizes Graph to enumerate mailboxes in victim environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.