Messaging Applications

T1213.005

Sub-technique of T1213 Data from Information Repositories.View on attack.mitre.org

About this technique

Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information.

The following is a brief list of example information that may hold potential value to an adversary and may also be found on messaging applications:

* Testing / development credentials (i.e., Chat Messages)
* Source code snippets
* Links to network shares and other internal resources
* Proprietary data
* Discussions about ongoing incident response efforts

In addition to exfiltrating data from messaging applications, adversaries may leverage data from chat messages in order to improve their targeting - for example, by learning more about an environment or evading ongoing incident response efforts.

Detection rules0

Rules on DetectionCode tagged with T1213.005.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software1

Campaigns0

None recorded.

Procedure examples4

Groups3

Used byProcedure example
GroupFox Kitten

Fox Kitten has accessed victim security and IT environments and Microsoft Teams to mine valuable information.

GroupLAPSUS$

LAPSUS$ has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials.

GroupScattered Spider

Scattered Spider threat actors search the victim’s Slack and Microsoft Teams for conversations about the intrusion and incident response.

Software1

Used byProcedure example
ToolTruffleHog

TruffleHog has obtained data and credentials associated with messaging applications to include Slack.

References5

  1. Guardian Grand Theft Auto Leak 2022 Open source
    Keza MacDonald, Keith Stuart and Alex Hern. (2022, September 19). Grand Theft Auto 6 leak: who hacked Rockstar and what was stolen?. Retrieved August 30, 2024.
  2. Microsoft DEV-0537 Open source
    Microsoft. (2022, March 22). DEV-0537 criminal actor targeting organizations for data exfiltration and destruction. Retrieved March 23, 2022.
  3. Permiso Scattered Spider 2023 Open source
    Ian Ahl. (2023, September 20). LUCR-3: SCATTERED SPIDER GETTING SAAS-Y IN THE CLOUD. Retrieved September 25, 2023.
  4. SC Magazine Ragnar Locker 2021 Open source
    Joe Uchill. (2021, December 3). Ragnar Locker reminds breach victims it can read the on-network incident response chat rooms. Retrieved August 30, 2024.
  5. Sentinel Labs NullBulge 2024 Open source
    Jim Walter. (2024, July 16). NullBulge | Threat Actor Masquerades as Hacktivist Group Rebelling Against AI. Retrieved August 30, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.