Sub-technique of T1114 Email Collection.View on attack.mitre.org
Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user’s local system, such as Outlook storage or cache files.
Outlook stores data locally in offline data files with an extension of .ost. Outlook 2010 and later supports .ost file sizes up to 50GB, while earlier versions of Outlook support up to 20GB. IMAP accounts in Outlook 2013 (and earlier) and POP accounts use Outlook Data Files (.pst) as opposed to .ost, whereas IMAP accounts in Outlook 2016 (and later) use .ost files. Both types of Outlook data files are typically stored in `C:\Users\<username>\Documents\Outlook Files` or `C:\Users\<username>\AppData\Local\Microsoft\Outlook`.
Rules on DetectionCode tagged with T1114.001.
| Rule | Level | Log source |
|---|---|---|
| Powershell Local Email Collection | medium | windows / ps_script |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Email files written outside of the Outlook directory | Anomaly | NULL | Sysmon EventID 11 |
| Mailsniper Invoke functions | TTP | NULL | Powershell Script Block Logging 4104 |
| O365 Email Password and Payroll Compromise Behavior | TTP | NULL | Office 365 Universal Audit Log, Office 365 Reporting Message Trace |
| O365 Email Receive and Hard Delete Takeover Behavior | Anomaly | NULL | Office 365 Universal Audit Log, Office 365 Reporting Message Trace |
| O365 Email Send and Hard Delete Exfiltration Behavior | Anomaly | NULL | Office 365 Universal Audit Log, Office 365 Reporting Message Trace |
| O365 Email Send and Hard Delete Suspicious Behavior | Anomaly | NULL | Office 365 Universal Audit Log |
| Used by | Procedure example |
|---|---|
| GroupAPT1 | APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files. |
| GroupChimera | Chimera has harvested data from victim's e-mail including through execution of |
| GroupMagic Hound | Magic Hound has collected .PST archives. |
| GroupMirrorFace | MirrorFace has exfiltrated stored emails from compromised hosts. |
| GroupRedCurl | RedCurl has collected emails to use in future phishing campaigns. |
| GroupSea Turtle | Sea Turtle collected email archives from victim environments. |
| GroupWinter Vivern | Winter Vivern delivered malicious JavaScript payloads capable of exfiltrating email messages from exploited email servers. |
| GroupWIRTE | WIRTE has collected documents from victims' email accounts. |
| Used by | Procedure example |
|---|---|
| MalwareCarbanak | Carbanak searches recursively for Outlook personal storage tables (PST) files within user directories and sends them back to the C2 server. |
| MalwareCosmicDuke | CosmicDuke searches for Microsoft Outlook data files with extensions .pst and .ost for collection and exfiltration. |
| MalwareCrimson | Crimson contains a command to collect and exfiltrate emails from Outlook. |
| MalwareEmotet | Emotet has been observed leveraging a module that scrapes email data from Outlook. |
| ToolEmpire | Empire has the ability to collect emails on a target system. |
| MalwareKGH_SPY | KGH_SPY can harvest data from mail clients. |
| MalwareLunarMail | LunarMail can capture the recipients of sent email messages from compromised accounts. |
| ToolOut1 | Out1 can parse e-mails on a target machine. |
| Used by | Procedure example |
|---|---|
| CampaignNight Dragon | During Night Dragon, threat actors used RAT malware to exfiltrate email archives. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.