Spearphishing via Service

T1566.003

Sub-technique of T1566 Phishing.View on attack.mitre.org

About this technique

Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.

All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries send messages through various social media services, personal webmail, and other non-enterprise controlled services. These services are more likely to have a less-strict security policy than an enterprise. As with most kinds of spearphishing, the goal is to generate rapport with the target or get the target's interest in some way. Adversaries will create fake social media accounts and message employees for potential job opportunities. Doing so allows a plausible reason for asking about services, policies, and software that's running in an environment. The adversary can then send malicious links or attachments through these services.

A common example is to build rapport with a target via social media, then send content to a personal webmail service that the target uses on their work computer. This allows an adversary to bypass some email restrictions on the work account, and the target is more likely to open the file since it's something they were expecting. If the payload doesn't work as expected, the adversary can continue normal communications and troubleshoot with the target on how to get it working.

Detection rules1

Rules on DetectionCode tagged with T1566.003.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

Groups14

Software1

Campaigns1

Procedure examples16

Groups14

Used byProcedure example
GroupAjax Security Team

Ajax Security Team has used various social media channels to spearphish victims.

GroupAPT29

APT29 has used the legitimate mailing service Constant Contact to send phishing e-mails.

GroupContagious Interview

Contagious Interview has used fake job advertisements and messages sent via social media to spearphish targets. Contagious Interview has also leveraged hiring websites to solicit victims.

GroupCURIUM

CURIUM has used social media to deliver malicious files to victims.

GroupDark Caracal

Dark Caracal spearphished victims via Facebook and Whatsapp.

GroupEXOTIC LILY

EXOTIC LILY has used the e-mail notification features of legitimate file sharing services for spearphishing.

GroupFIN6

FIN6 has used fake job advertisements sent via LinkedIn to spearphish targets.

GroupLazarus Group

Lazarus Group has used social media platforms, including LinkedIn and Twitter, to send spearphishing messages.

View all 14 groups examples

Software1

Used byProcedure example
MalwareNinja

Ninja has been distributed to victims via the messaging app Telegram.

Campaigns1

Used byProcedure example
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent victims spearphishing messages via LinkedIn concerning fictitious jobs.

References1

  1. Lookout Dark Caracal Jan 2018 Open source
    Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.