Remote Email Collection

T1114.002

Sub-technique of T1114 Email Collection.View on attack.mitre.org

About this technique

Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.

Detection rules12

Rules on DetectionCode tagged with T1114.002.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk12

Groups13

Software4

Campaigns3

Procedure examples20

Groups13

Used byProcedure example
GroupAPT1

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived.

GroupAPT28

APT28 has collected emails from victim Microsoft Exchange servers.

GroupAPT29

APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests.

GroupChimera

Chimera has harvested data from remote mailboxes including through execution of \\<hostname>\c$\Users\<username>\AppData\Local\Microsoft\Outlook*.ost.

GroupDragonfly

Dragonfly has accessed email accounts using Outlook Web Access.

GroupFIN4

FIN4 has accessed and hijacked online email communications using stolen credentials.

GroupHAFNIUM

HAFNIUM has used web shells and MSGraph to export mailbox data.

GroupKe3chang

Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes.

View all 13 groups examples

Software4

Used byProcedure example
MalwareLightNeuron

LightNeuron collects Exchange emails matching rules specified in its configuration.

ToolMailSniper

MailSniper can be used for searching through email in Exchange and Office 365 environments.

MalwareSeaDuke

Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials.

MalwareValak

Valak can collect sensitive mailing information from Exchange servers, including credentials and the domain certificate of an enterprise.

Campaigns3

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to gather data and email messages from Exchange services related to OT topics and technical work carried out within organizations.

CampaignHomeLand Justice

During HomeLand Justice, threat actors made multiple HTTP POST requests to the Exchange servers of the victim organization to transfer data.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 collected emails from specific individuals, such as executives and IT staff, using `New-MailboxExportRequest` followed by `Get-MailboxExportRequest`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.