Clear Mailbox Data

T1070.008

Sub-technique of T1070 Indicator Removal.View on attack.mitre.org

About this technique

Adversaries may modify mail and mail application data to remove evidence of their activity. Email applications allow users and other programs to export and delete mailbox data via command line tools or use of APIs. Mail application data can be emails, email metadata, or logs generated by the application or operating system, such as export requests.

Adversaries may manipulate emails and mailbox data to remove logs, artifacts, and metadata, such as evidence of Phishing/Internal Spearphishing, Email Collection, Mail Protocols for command and control, or email-based exfiltration such as Exfiltration Over Alternative Protocol. For example, to remove evidence on Exchange servers adversaries have used the ExchangePowerShell PowerShell module, including Remove-MailboxExportRequest to remove evidence of mailbox exports. On Linux and macOS, adversaries may also delete emails through a command line utility called mail or use AppleScript to interact with APIs on macOS.

Adversaries may also remove emails and metadata/headers indicative of spam or suspicious activity (for example, through the use of organization-wide transport rules) to reduce the likelihood of malicious emails being detected by security products.

Detection rules7

Rules on DetectionCode tagged with T1070.008.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk7

RuleTypeRiskData source
Cisco ASA - User Account Deleted From Local DatabaseAnomalyNULLCisco ASA Logs
O365 Email Hard Delete Excessive VolumeAnomalyNULLOffice 365 Universal Audit Log
O365 Email Password and Payroll Compromise BehaviorTTPNULLOffice 365 Universal Audit Log, Office 365 Reporting Message Trace
O365 Email Receive and Hard Delete Takeover BehaviorAnomalyNULLOffice 365 Universal Audit Log, Office 365 Reporting Message Trace
O365 Email Send and Hard Delete Exfiltration BehaviorAnomalyNULLOffice 365 Universal Audit Log, Office 365 Reporting Message Trace
O365 Email Send and Hard Delete Suspicious BehaviorAnomalyNULLOffice 365 Universal Audit Log
O365 Email Send Attachments Excessive VolumeAnomalyNULLOffice 365 Universal Audit Log

Groups2

Software2

Campaigns1

Procedure examples5

Groups2

Used byProcedure example
GroupAPT42

APT42 has deleted login notification emails and has cleared the Sent folder to cover their tracks.

GroupScattered Spider

Scattered Spider has manually deleted emails notifying users of suspicious account activity.

Software2

Used byProcedure example
MalwareGoopy

Goopy has the ability to delete emails used for C2 once the content has been copied.

MalwareLunarMail

LunarMail can set the `PR_DELETE_AFTER_SUBMIT` flag to delete messages sent for data exfiltration.

Campaigns1

Used byProcedure example
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 removed evidence of email export requests using `Remove-MailboxExportRequest`.

References5

  1. Cybereason Cobalt Kitty 2017 Open source
    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.
  2. ExchangePowerShell Module Open source
    Microsoft. (2017, September 25). ExchangePowerShell. Retrieved June 10, 2022.
  3. Microsoft OAuth Spam 2022 Open source
    Microsoft. (2023, September 22). Malicious OAuth applications abuse cloud email services to spread spam. Retrieved March 13, 2023.
  4. Volexity SolarWinds Open source
    Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020.
  5. mailx man page Open source
    Michael Kerrisk. (2021, August 27). mailx(1p) — Linux manual page. Retrieved June 10, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.