Sub-technique of T1114 Email Collection.View on attack.mitre.org
Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.
Rules on DetectionCode tagged with T1114.002.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Email servers sending high volume traffic to hosts | Anomaly | NULL | |
| Hosts receiving high volume of network traffic from email server | Anomaly | NULL | |
| O365 Compliance Content Search Exported | TTP | NULL | |
| O365 Compliance Content Search Started | TTP | NULL | |
| O365 Email Access By Security Administrator | TTP | NULL | Office 365 Universal Audit Log |
| O365 Email Suspicious Search Behavior | Anomaly | NULL | Office 365 Universal Audit Log |
| O365 Mailbox Inbox Folder Shared with All Users | TTP | NULL | O365 ModifyFolderPermissions |
| O365 Mailbox Read Access Granted to Application | TTP | NULL | O365 Update application. |
| O365 Multiple Mailboxes Accessed via API | TTP | NULL | O365 MailItemsAccessed |
| O365 OAuth App Mailbox Access via EWS | TTP | NULL | O365 MailItemsAccessed |
| O365 OAuth App Mailbox Access via Graph API | TTP | NULL | O365 MailItemsAccessed |
| O365 Suspicious Rights Delegation | TTP | NULL |
| Used by | Procedure example |
|---|---|
| GroupAPT1 | APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived. |
| GroupAPT28 | APT28 has collected emails from victim Microsoft Exchange servers. |
| GroupAPT29 | APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests. |
| GroupChimera | Chimera has harvested data from remote mailboxes including through execution of |
| GroupDragonfly | Dragonfly has accessed email accounts using Outlook Web Access. |
| GroupFIN4 | FIN4 has accessed and hijacked online email communications using stolen credentials. |
| GroupHAFNIUM | HAFNIUM has used web shells and MSGraph to export mailbox data. |
| GroupKe3chang | Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes. |
| Used by | Procedure example |
|---|---|
| MalwareLightNeuron | LightNeuron collects Exchange emails matching rules specified in its configuration. |
| ToolMailSniper | MailSniper can be used for searching through email in Exchange and Office 365 environments. |
| MalwareSeaDuke | Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials. |
| MalwareValak | Valak can collect sensitive mailing information from Exchange servers, including credentials and the domain certificate of an enterprise. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to gather data and email messages from Exchange services related to OT topics and technical work carried out within organizations. |
| CampaignHomeLand Justice | During HomeLand Justice, threat actors made multiple HTTP POST requests to the Exchange servers of the victim organization to transfer data. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 collected emails from specific individuals, such as executives and IT staff, using `New-MailboxExportRequest` followed by `Get-MailboxExportRequest`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.