Internal Spearphishing

T1534

Technique.View on attack.mitre.org

About this technique

After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization. Internal spearphishing is multi-staged campaign where a legitimate account is initially compromised either by controlling the user's device or by compromising the account credentials of the user. Adversaries may then attempt to take advantage of the trusted internal account to increase the likelihood of tricking more victims into falling for phish attempts, often incorporating Impersonation.

For example, adversaries may leverage Spearphishing Attachment or Spearphishing Link as part of internal spearphishing to deliver a payload or redirect to an external site to capture credentials through Input Capture on sites that mimic login interfaces.

Adversaries may also leverage internal chat apps, such as Microsoft Teams, to spread malicious content or engage users in attempts to capture sensitive information and/or credentials.

Detection rules0

Rules on DetectionCode tagged with T1534.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups6

Software1

Campaigns1

Procedure examples8

Groups6

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used a compromised account to send a phishing email to an address likely used and monitored by the IT team within the same targeted organization.

GroupGamaredon Group

Gamaredon Group has used an Outlook VBA module on infected systems to send phishing emails with malicious attachments to other employees within the organization.

GroupHEXANE

HEXANE has conducted internal spearphishing attacks against executives, HR, and IT personnel to gain information and access.

GroupKimsuky

Kimsuky has sent internal spearphishing emails for lateral movement after stealing victim information.

GroupLeviathan

Leviathan has conducted internal spearphishing within the victim's environment for lateral movement.

GroupMuddyWater

MuddyWater has used compromised mailboxes within target organizations to send spearphishing emails.

Software1

Used byProcedure example
MalwareSameCoin

SameCoin can send its Setup.exe file as an attachment to other addresses in the same compromised organization.

Campaigns1

Used byProcedure example
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group conducted internal spearphishing from within a compromised organization.

References2

  1. Int SP - chat apps Open source
    Microsoft Threat Intelligence. (2023, August 2). Midnight Blizzard conducts targeted social engineering over Microsoft Teams. Retrieved February 16, 2024.
  2. Trend Micro - Int SP Open source
    Trend Micro. (n.d.). Retrieved February 16, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.