Code Repositories

T1213.003

Sub-technique of T1213 Data from Information Repositories.View on attack.mitre.org

About this technique

Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.

Once adversaries gain access to a victim network or a private code repository, they may collect sensitive information such as proprietary source code or Unsecured Credentials contained within software's source code. Having access to software's source code may allow adversaries to develop Exploits, while credentials may provide access to additional resources using Valid Accounts.

**Note:** This is distinct from Code Repositories, which focuses on conducting Reconnaissance via public code repositories.

Detection rules5

Rules on DetectionCode tagged with T1213.003.

Sigma5

Splunk0

No Splunk rules are mapped to this technique yet.

Groups4

Software5

Campaigns1

Procedure examples10

Groups4

Used byProcedure example
GroupAPT41

APT41 cloned victim user Git repositories during intrusions.

GroupLAPSUS$

LAPSUS$ has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials.

GroupScattered Spider

Scattered Spider enumerates data stored within victim code repositories, such as internal GitHub repositories.

GroupShinyHunters

ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code.

Software5

Used byProcedure example
MalwareGlassWorm

GlassWorm has gathered code repository authentication materials for NPM and GitHub. GlassWorm has collected details pertaining to the npm configuration data for `_authToken`.

MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered and downloaded data stored on both compromised and publicly accessible code repositories.

MalwareShai-Hulud

Shai-Hulud has downloaded existing packages from code repositories and extracted data stored within them.

MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can target sensitive file paths in Git repos to extract credentials.

ToolTruffleHog

TruffleHog has gathered data and credentials from code repositories.

Campaigns1

Used byProcedure example
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 downloaded source code from code repositories.

References2

  1. Krebs Adobe Open source
    Brian Krebs. (2013, October 3). Adobe To Announce Source Code, Customer Data Breach. Retrieved May 17, 2021.
  2. Wired Uber Breach Open source
    Andy Greenberg. (2017, January 21). Hack Brief: Uber Paid Off Hackers to Hide a 57-Million User Data Breach. Retrieved May 14, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.