Sub-technique of T1213 Data from Information Repositories.View on attack.mitre.org
Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information.
The following is a brief list of example information that may hold potential value to an adversary and may also be found on messaging applications:
* Testing / development credentials (i.e., Chat Messages)
* Source code snippets
* Links to network shares and other internal resources
* Proprietary data
* Discussions about ongoing incident response efforts
In addition to exfiltrating data from messaging applications, adversaries may leverage data from chat messages in order to improve their targeting - for example, by learning more about an environment or evading ongoing incident response efforts.
Rules on DetectionCode tagged with T1213.005.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupFox Kitten | Fox Kitten has accessed victim security and IT environments and Microsoft Teams to mine valuable information. |
| GroupLAPSUS$ | LAPSUS$ has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials. |
| GroupScattered Spider | Scattered Spider threat actors search the victim’s Slack and Microsoft Teams for conversations about the intrusion and incident response. |
| Used by | Procedure example |
|---|---|
| ToolTruffleHog | TruffleHog has obtained data and credentials associated with messaging applications to include Slack. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.