Mail Protocols

T1071.003

Sub-technique of T1071 Application Layer Protocol.View on attack.mitre.org

About this technique

Adversaries may communicate using application layer protocols associated with electronic mail delivery to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Protocols such as SMTP/S, POP3/S, and IMAP that carry electronic mail may be very common in environments. Packets produced from these protocols may have many fields and headers in which data can be concealed. Data could also be concealed within the email messages themselves. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.

Detection rules3

Rules on DetectionCode tagged with T1071.003.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk3

RuleTypeRiskData source
Windows File Transfer Protocol In Non-Common Process PathAnomalyNULLSysmon EventID 3
Windows Mail Protocol In Non-Common Process PathAnomalyNULLSysmon EventID 3
Windows Multi hop Proxy TOR Website QueryAnomalyNULLSysmon EventID 22

Groups6

Software20

Campaigns0

None recorded.

Procedure examples26

Groups6

Used byProcedure example
GroupAPT28

APT28 has used IMAP, POP3, and SMTP for a communication channel in various implants, including using self-registered Google Mail accounts and later compromised email servers of its victims.

GroupAPT32

APT32 has used email for C2 via an Office macro.

GroupContagious Interview

Contagious Interview has utilized email notifications from malware distribution servers to track victim engagement.

GroupKimsuky

Kimsuky has used e-mail to send exfiltrated data to C2 servers.

GroupSilverTerrier

SilverTerrier uses SMTP for C2 communications.

GroupTurla

Turla has used multiple backdoors which communicate with a C2 server via email attachments.

Software20

Used byProcedure example
MalwareAgent Tesla

Agent Tesla has used SMTP for C2 communications.

MalwareBadPatch

BadPatch uses SMTP for C2.

MalwareCannon

Cannon uses SMTP/S and POP3/S for C2 communications by sending and receiving emails.

MalwareCHOPSTICK

Various implementations of CHOPSTICK communicate with C2 over SMTP and POP3.

MalwareComRAT

ComRAT can use email attachments for command and control.

MalwareCORESHELL

CORESHELL can communicate over SMTP and POP3 for C2.

MalwareGoopy

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

MalwareIMAPLoader

IMAPLoader uses the IMAP email protocol for command and control purposes.

View all 20 software examples

References1

  1. FireEye APT28 Open source
    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.