Employee Names

T1589.003

Sub-technique of T1589 Gather Victim Identity Information.View on attack.mitre.org

About this technique

Adversaries may gather employee names that can be used during targeting. Employee names be used to derive email addresses as well as to help guide other reconnaissance efforts and/or craft more-believable lures.

Adversaries may easily gather employee names, since they may be readily available and exposed via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Compromise Accounts), and/or initial access (ex: Phishing or Valid Accounts).

Detection rules0

Rules on DetectionCode tagged with T1589.003.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

Groups3

Used byProcedure example
GroupKimsuky

Kimsuky has collected victim employee name information.

GroupSandworm Team

Sandworm Team's research of potential victim organizations included the identification and collection of employee information.

GroupSilent Librarian

Silent Librarian has collected lists of names for individuals from targeted organizations.

References1

  1. OPM Leak Open source
    Cybersecurity Resource Center. (n.d.). CYBERSECURITY INCIDENTS. Retrieved September 16, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.