Databases

T1213.006

Sub-technique of T1213 Data from Information Repositories.View on attack.mitre.org

About this technique

Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments).

Examples of databases from which information may be collected include MySQL, PostgreSQL, MongoDB, Amazon Relational Database Service, Azure SQL Database, Google Firebase, and Snowflake. Databases may include a variety of information of interest to adversaries, such as usernames, hashed passwords, personally identifiable information, and financial data. Data collected from databases may be used for Lateral Movement, Command and Control, or Exfiltration. Data exfiltrated from databases may also be used to extort victims or may be sold for profit.

Detection rules0

Rules on DetectionCode tagged with T1213.006.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups5

Software4

Campaigns3

Procedure examples12

Groups5

Used byProcedure example
GroupFIN6

FIN6 has collected schemas and user accounts from systems running SQL Server.

GroupSandworm Team

Sandworm Team exfiltrates data of interest from enterprise databases using Adminer.

GroupSea Turtle

Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines.

GroupShinyHunters

ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors.

GroupTurla

Turla has used a custom .NET tool to collect documents from an organization's internal central database.

Software4

Used byProcedure example
MalwareGlassWorm

GlassWorm has collected data from macOS devices through the gathering of Apple Notes related files by targeting `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite`, `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-wal`, and `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-shm`.

MalwareMgBot

MgBot includes a module capable of stealing content from the Tencent QQ database storing user QQ message history on infected devices.

MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to list and extract data from SQL databases.

MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can extract credentials from multiple database configuration files including ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, and /etc/mysql/my.cnf.

Campaigns3

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to query internal databases and systems to extract proprietary information, system configurations, and sensitive operational data.

CampaignAPT41 DUST

APT41 DUST collected data from victim Oracle databases using SQLULDR2.

CampaignLeviathan Australian Intrusions

Leviathan gathered information from SQL servers and Building Management System (BMS) servers during Leviathan Australian Intrusions.

References1

  1. Google Cloud Threat Intelligence UNC5537 Snowflake 2024 Open source
    Mandiant. (2024, June 10). UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion. Retrieved May 22, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.