Phishing for Information

T1598

Technique with 4 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Phishing for information is different from Phishing in that the objective is gathering data from the victim rather than executing malicious code.

All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass credential harvesting campaigns.

Adversaries may also try to obtain information directly through the exchange of emails, instant messages, or other electronic conversation means. Victims may also receive phishing messages that direct them to call a phone number where the adversary attempts to collect confidential information.

Phishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Establish Accounts or Compromise Accounts) and/or sending multiple, seemingly urgent messages. Another way to accomplish this is by Email Spoofing the identity of the sender, which can be used to fool both the human recipient as well as automated security tools.

Phishing for information may also involve evasive techniques, such as removing or manipulating emails or metadata/headers from compromised accounts being abused to send messages (e.g., Email Hiding Rules).

Detection rules2

Rules on DetectionCode tagged with T1598 or one of its sub-techniques.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk2

RuleTypeRiskData sourceTechnique
Cisco Secure Firewall - Rare Snort Rule TriggeredHuntingNULLCisco Secure Firewall Threat Defense Intrusion EventT1598
Windows RDP File ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1598.002

Sub-techniques4

IDNameExamples
T1598.001Spearphishing Service1
T1598.002Spearphishing Attachment4
T1598.003Spearphishing Link19
T1598.004Spearphishing Voice4

Groups6

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

Groups6

Used byProcedure example
GroupAPT28

APT28 has used spearphishing to compromise credentials.

GroupKimsuky

Kimsuky has used tailored spearphishing emails to gather victim information including contat lists to identify additional targets.

GroupMoonstone Sleet

Moonstone Sleet has interacted with victims to gather information via email.

GroupScattered Spider

Scattered Spider has used a combination of credential phishing and social engineering to capture one-time-password (OTP) codes.

GroupShinyHunters

ShinyHunters has sent phishing emails to Microsoft Office 365 corporate users in order to steal credentials.

GroupZIRCONIUM

ZIRCONIUM targeted presidential campaign staffers with credential phishing e-mails.

References10

  1. Avertium callback phishing Open source
    Avertium. (n.d.). EVERYTHING YOU NEED TO KNOW ABOUT CALLBACK PHISHING. Retrieved February 2, 2023.
  2. GitHub Phishery Open source
    Ryan Hanson. (2016, September 24). phishery. Retrieved October 23, 2020.
  3. Microsoft OAuth Spam 2022 Open source
    Microsoft. (2023, September 22). Malicious OAuth applications abuse cloud email services to spread spam. Retrieved March 13, 2023.
  4. PCMag FakeLogin Open source
    Kan, M. (2019, October 24). Hackers Try to Phish United Nations Staffers With Fake Login Pages. Retrieved October 20, 2020.
  5. Palo Alto Unit 42 VBA Infostealer 2014 Open source
    Vicky Ray and Rob Downs. (2014, October 29). Examining a VBA-Initiated Infostealer Campaign. Retrieved March 13, 2023.
  6. Proofpoint-spoof Open source
    Proofpoint. (n.d.). What Is Email Spoofing?. Retrieved February 24, 2023.
  7. Sophos Attachment Open source
    Ducklin, P. (2020, October 2). Serious Security: Phishing without links – when phishers bring along their own web pages. Retrieved October 20, 2020.
  8. ThreatPost Social Media Phishing Open source
    O'Donnell, L. (2020, October 20). Facebook: A Top Launching Pad For Phishing Attacks. Retrieved October 20, 2020.
  9. TrendMictro Phishing Open source
    Babon, P. (2020, September 3). Tricky 'Forms' of Phishing. Retrieved October 20, 2020.
  10. cyberproof-double-bounce Open source
    Itkin, Liora. (2022, September 1). Double-bounced attacks with email spoofing . Retrieved February 24, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.