ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1087.003×

9 examples

TechniqueUsed byProcedure example
T1087.003
Email Account
MalwareTrickBot

TrickBot collects email addresses from Outlook.

T1087.003
Email Account
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects address book information from Outlook.

T1087.003
Email Account
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

T1087.003
Email Account
MalwareGrandoreiro

Grandoreiro can parse Outlook .pst files to extract e-mail addresses.

T1087.003
Email Account
MalwareBoomBox

BoomBox can execute an LDAP query to discover e-mail accounts for domain users.

T1087.003
Email Account
MalwareLizar

Lizar can collect email accounts from Microsoft Outlook and Mozilla Thunderbird.

T1087.003
Email Account
ToolRuler

Ruler can be used to enumerate Exchange users and dump the GAL.

T1087.003
Email Account
ToolMailSniper

MailSniper can be used to obtain account names from Exchange and Office 365 using the Get-GlobalAddressList cmdlet.

T1087.003
Email Account
MalwareKali365

Kali365 has leveraged an Exchange Admin module that utilizes Graph to enumerate mailboxes in victim environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.