Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1114.001 Local Email Collection |
MalwareSmoke Loader | Smoke Loader searches through Outlook files and directories (e.g., inbox, sent, templates, drafts, archives, etc.). |
| T1114.001 Local Email Collection |
MalwareCosmicDuke | CosmicDuke searches for Microsoft Outlook data files with extensions .pst and .ost for collection and exfiltration. |
| T1114.001 Local Email Collection |
MalwareEmotet | Emotet has been observed leveraging a module that scrapes email data from Outlook. |
| T1114.001 Local Email Collection |
MalwareCrimson | Crimson contains a command to collect and exfiltrate emails from Outlook. |
| T1114.001 Local Email Collection |
MalwareCarbanak | Carbanak searches recursively for Outlook personal storage tables (PST) files within user directories and sends them back to the C2 server. |
| T1114.001 Local Email Collection |
MalwareKGH_SPY | KGH_SPY can harvest data from mail clients. |
| T1114.001 Local Email Collection |
MalwareLunarMail | LunarMail can capture the recipients of sent email messages from compromised accounts. |
| T1114.001 Local Email Collection |
MalwareQakBot | QakBot can target and steal locally stored emails to support thread hijacking phishing campaigns. |
| T1114.001 Local Email Collection |
ToolEmpire | Empire has the ability to collect emails on a target system. |
| T1114.001 Local Email Collection |
ToolOut1 | Out1 can parse e-mails on a target machine. |
| T1114.001 Local Email Collection |
ToolPupy | Pupy can interact with a victim’s Outlook session and look through folders and emails. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.