ATT&CKReferencesCIS Emotet Dec 2018

CIS Emotet Dec 2018

CIS. (2018, December 12). MS-ISAC Security Primer- Emotet. Retrieved March 25, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1087.003
Email Account
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

T1110.001
Password Guessing
MalwareEmotet

Emotet has been observed using a hard coded list of passwords to brute force user accounts.

T1114
Email Collection
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

T1114.001
Local Email Collection
MalwareEmotet

Emotet has been observed leveraging a module that scrapes email data from Outlook.

T1552.001
Credentials In Files
MalwareEmotet

Emotet has been observed leveraging a module that retrieves passwords stored on a system for the current logged-on user.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.