Local Email Collection

T1114.001

Sub-technique of T1114 Email Collection.View on attack.mitre.org

About this technique

Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user’s local system, such as Outlook storage or cache files.

Outlook stores data locally in offline data files with an extension of .ost. Outlook 2010 and later supports .ost file sizes up to 50GB, while earlier versions of Outlook support up to 20GB. IMAP accounts in Outlook 2013 (and earlier) and POP accounts use Outlook Data Files (.pst) as opposed to .ost, whereas IMAP accounts in Outlook 2016 (and later) use .ost files. Both types of Outlook data files are typically stored in `C:\Users\<username>\Documents\Outlook Files` or `C:\Users\<username>\AppData\Local\Microsoft\Outlook`.

Detection rules7

Rules on DetectionCode tagged with T1114.001.

Sigma1

RuleLevelLog source
Powershell Local Email Collectionmediumwindows / ps_script

Splunk6

RuleTypeRiskData source
Email files written outside of the Outlook directoryAnomalyNULLSysmon EventID 11
Mailsniper Invoke functionsTTPNULLPowershell Script Block Logging 4104
O365 Email Password and Payroll Compromise BehaviorTTPNULLOffice 365 Universal Audit Log, Office 365 Reporting Message Trace
O365 Email Receive and Hard Delete Takeover BehaviorAnomalyNULLOffice 365 Universal Audit Log, Office 365 Reporting Message Trace
O365 Email Send and Hard Delete Exfiltration BehaviorAnomalyNULLOffice 365 Universal Audit Log, Office 365 Reporting Message Trace
O365 Email Send and Hard Delete Suspicious BehaviorAnomalyNULLOffice 365 Universal Audit Log

Groups8

Software11

Campaigns1

Procedure examples20

Groups8

Used byProcedure example
GroupAPT1

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files.

GroupChimera

Chimera has harvested data from victim's e-mail including through execution of wmic /node:<ip> process call create "cmd /c copy c:\Users\<username>\<path>\backup.pst c:\windows\temp\backup.pst" copy "i:\<path>\<username>\My Documents\<filename>.pst"
copy
.

GroupMagic Hound

Magic Hound has collected .PST archives.

GroupMirrorFace

MirrorFace has exfiltrated stored emails from compromised hosts.

GroupRedCurl

RedCurl has collected emails to use in future phishing campaigns.

GroupSea Turtle

Sea Turtle collected email archives from victim environments.

GroupWinter Vivern

Winter Vivern delivered malicious JavaScript payloads capable of exfiltrating email messages from exploited email servers.

GroupWIRTE

WIRTE has collected documents from victims' email accounts.

Software11

Used byProcedure example
MalwareCarbanak

Carbanak searches recursively for Outlook personal storage tables (PST) files within user directories and sends them back to the C2 server.

MalwareCosmicDuke

CosmicDuke searches for Microsoft Outlook data files with extensions .pst and .ost for collection and exfiltration.

MalwareCrimson

Crimson contains a command to collect and exfiltrate emails from Outlook.

MalwareEmotet

Emotet has been observed leveraging a module that scrapes email data from Outlook.

ToolEmpire

Empire has the ability to collect emails on a target system.

MalwareKGH_SPY

KGH_SPY can harvest data from mail clients.

MalwareLunarMail

LunarMail can capture the recipients of sent email messages from compromised accounts.

ToolOut1

Out1 can parse e-mails on a target machine.

View all 11 software examples

Campaigns1

Used byProcedure example
CampaignNight Dragon

During Night Dragon, threat actors used RAT malware to exfiltrate email archives.

References2

  1. Microsoft Outlook Files Open source
    Microsoft. (n.d.). Introduction to Outlook Data Files (.pst and .ost). Retrieved February 19, 2020.
  2. Outlook File Sizes Open source
    N. O'Bryan. (2018, May 30). Managing Outlook Cached Mode and OST File Sizes. Retrieved February 19, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.