Sub-technique of T1213 Data from Information Repositories.View on attack.mitre.org
Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments).
Examples of databases from which information may be collected include MySQL, PostgreSQL, MongoDB, Amazon Relational Database Service, Azure SQL Database, Google Firebase, and Snowflake. Databases may include a variety of information of interest to adversaries, such as usernames, hashed passwords, personally identifiable information, and financial data. Data collected from databases may be used for Lateral Movement, Command and Control, or Exfiltration. Data exfiltrated from databases may also be used to extort victims or may be sold for profit.
Rules on DetectionCode tagged with T1213.006.
| Used by | Procedure example |
|---|---|
| GroupFIN6 | FIN6 has collected schemas and user accounts from systems running SQL Server. |
| GroupSandworm Team | Sandworm Team exfiltrates data of interest from enterprise databases using Adminer. |
| GroupSea Turtle | Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines. |
| GroupShinyHunters | ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors. |
| GroupTurla | Turla has used a custom .NET tool to collect documents from an organization's internal central database. |
| Used by | Procedure example |
|---|---|
| MalwareGlassWorm | GlassWorm has collected data from macOS devices through the gathering of Apple Notes related files by targeting `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite`, `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-wal`, and `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-shm`. |
| MalwareMgBot | MgBot includes a module capable of stealing content from the Tencent QQ database storing user QQ message history on infected devices. |
| MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to list and extract data from SQL databases. |
| MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can extract credentials from multiple database configuration files including ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, and /etc/mysql/my.cnf. |
| Used by | Procedure example |
|---|---|
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to query internal databases and systems to extract proprietary information, system configurations, and sensitive operational data. |
| CampaignAPT41 DUST | APT41 DUST collected data from victim Oracle databases using SQLULDR2. |
| CampaignLeviathan Australian Intrusions | Leviathan gathered information from SQL servers and Building Management System (BMS) servers during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.