Sub-technique of T1586 Compromise Accounts.View on attack.mitre.org
Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Compromised email accounts can also be used in the acquisition of infrastructure (ex: Domains).
A variety of methods exist for compromising email accounts, such as gathering credentials via Phishing for Information, purchasing credentials from third-party sites, brute forcing credentials (ex: password reuse from breach credential dumps), or paying employees, suppliers or business partners for access to credentials. Prior to compromising email accounts, adversaries may conduct Reconnaissance to inform decisions about which accounts to compromise to further their operation. Adversaries may target compromising well-known email accounts or domains from which malicious spam or Phishing emails may evade reputation-based email filtering rules.
Adversaries can use a compromised email account to hijack existing email threads with targets of interest.
Rules on DetectionCode tagged with T1586.002.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has regularly used compromised email accounts in spearphishing campaigns. |
| GroupAPT28 | APT28 has used compromised email accounts to send credential phishing emails. |
| GroupAPT29 | APT29 has compromised email accounts to further enable phishing campaigns and taken control of dormant accounts. |
| GroupHEXANE | HEXANE has used compromised accounts to send spearphishing emails. |
| GroupIndigoZebra | IndigoZebra has compromised legitimate email accounts to use in their spearphishing operations. |
| GroupKimsuky | Kimsuky has compromised email accounts to send spearphishing e-mails. |
| GroupLAPSUS$ | LAPSUS$ has payed employees, suppliers, and business partners of target organizations for credentials. |
| GroupLeviathan | Leviathan has compromised email accounts to conduct social engineering attacks. |
| Used by | Procedure example |
|---|---|
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used compromised accounts to send spearphishing emails. |
| CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used compromised emails to create Salesforce trial accounts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.