ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1114.001×

11 examples

TechniqueUsed byProcedure example
T1114.001
Local Email Collection
MalwareSmoke Loader

Smoke Loader searches through Outlook files and directories (e.g., inbox, sent, templates, drafts, archives, etc.).

T1114.001
Local Email Collection
MalwareCosmicDuke

CosmicDuke searches for Microsoft Outlook data files with extensions .pst and .ost for collection and exfiltration.

T1114.001
Local Email Collection
MalwareEmotet

Emotet has been observed leveraging a module that scrapes email data from Outlook.

T1114.001
Local Email Collection
MalwareCrimson

Crimson contains a command to collect and exfiltrate emails from Outlook.

T1114.001
Local Email Collection
MalwareCarbanak

Carbanak searches recursively for Outlook personal storage tables (PST) files within user directories and sends them back to the C2 server.

T1114.001
Local Email Collection
MalwareKGH_SPY

KGH_SPY can harvest data from mail clients.

T1114.001
Local Email Collection
MalwareLunarMail

LunarMail can capture the recipients of sent email messages from compromised accounts.

T1114.001
Local Email Collection
MalwareQakBot

QakBot can target and steal locally stored emails to support thread hijacking phishing campaigns.

T1114.001
Local Email Collection
ToolEmpire

Empire has the ability to collect emails on a target system.

T1114.001
Local Email Collection
ToolOut1

Out1 can parse e-mails on a target machine.

T1114.001
Local Email Collection
ToolPupy

Pupy can interact with a victim’s Outlook session and look through folders and emails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.