Code Repositories

T1593.003

Sub-technique of T1593 Search Open Websites/Domains.View on attack.mitre.org

About this technique

Adversaries may search public code repositories for information about victims that can be used during targeting. Victims may store code in repositories on various third-party websites such as GitHub, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.

Adversaries may search various public code repositories for various information about a victim. Public code repositories can often be a source of various general information about victims, such as commonly used programming languages and libraries as well as the names of employees. Adversaries may also identify more sensitive data, including accidentally leaked credentials or API keys. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information), establishing operational resources (ex: Compromise Accounts or Compromise Infrastructure), and/or initial access (ex: Valid Accounts or Phishing).

**Note:** This is distinct from Code Repositories, which focuses on Collection from private and internally hosted code repositories.

Detection rules2

Rules on DetectionCode tagged with T1593.003.

Sigma2

RuleLevelLog source
Suspicious Git Clonemediumwindows / process_creation
Suspicious Git Clone - Linuxmediumlinux / process_creation

Splunk0

No Splunk rules are mapped to this technique yet.

Groups4

Software1

Campaigns0

None recorded.

Procedure examples5

Groups4

Used byProcedure example
GroupContagious Interview

Contagious Interview had identified and solicited victims through code repositories such as GitHub.

GroupHAFNIUM

HAFNIUM has discovered leaked corporate credentials on public repositories including GitHub.

GroupLAPSUS$

LAPSUS$ has searched public code repositories for exposed credentials.

GroupShinyHunters

ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys.

Software1

Used byProcedure example
MalwareShai-Hulud

Shai-Hulud has the ability to search open sites and code repositories for compromised credentials. Shai-Hulud has discovered packages associated with compromised accounts. Shai-Hulud has also searched code repositories for other compromised repositories that include predefined parameters or markers to include “Second Coming” combined with an 18-character alphanumeric string.

References1

  1. GitHub Cloud Service Credentials Open source
    Runa A. Sandvik. (2014, January 14). Attackers Scrape GitHub For Cloud Service Credentials, Hijack Account To Mine Virtual Currency. Retrieved August 9, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.