Email Accounts

T1586.002

Sub-technique of T1586 Compromise Accounts.View on attack.mitre.org

About this technique

Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Compromised email accounts can also be used in the acquisition of infrastructure (ex: Domains).

A variety of methods exist for compromising email accounts, such as gathering credentials via Phishing for Information, purchasing credentials from third-party sites, brute forcing credentials (ex: password reuse from breach credential dumps), or paying employees, suppliers or business partners for access to credentials. Prior to compromising email accounts, adversaries may conduct Reconnaissance to inform decisions about which accounts to compromise to further their operation. Adversaries may target compromising well-known email accounts or domains from which malicious spam or Phishing emails may evade reputation-based email filtering rules.

Adversaries can use a compromised email account to hijack existing email threads with targets of interest.

Detection rules0

Rules on DetectionCode tagged with T1586.002.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups14

Software0

None recorded.

Campaigns2

Procedure examples16

Groups14

Used byProcedure example
GroupAPT-C-36

APT-C-36 has regularly used compromised email accounts in spearphishing campaigns.

GroupAPT28

APT28 has used compromised email accounts to send credential phishing emails.

GroupAPT29

APT29 has compromised email accounts to further enable phishing campaigns and taken control of dormant accounts.

GroupHEXANE

HEXANE has used compromised accounts to send spearphishing emails.

GroupIndigoZebra

IndigoZebra has compromised legitimate email accounts to use in their spearphishing operations.

GroupKimsuky

Kimsuky has compromised email accounts to send spearphishing e-mails.

GroupLAPSUS$

LAPSUS$ has payed employees, suppliers, and business partners of target organizations for credentials.

GroupLeviathan

Leviathan has compromised email accounts to conduct social engineering attacks.

View all 14 groups examples

Campaigns2

Used byProcedure example
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used compromised accounts to send spearphishing emails.

CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used compromised emails to create Salesforce trial accounts.

References2

  1. AnonHBGary Open source
    Bright, P. (2011, February 15). Anonymous speaks: the inside story of the HBGary hack. Retrieved March 9, 2017.
  2. Microsoft DEV-0537 Open source
    Microsoft. (2022, March 22). DEV-0537 criminal actor targeting organizations for data exfiltration and destruction. Retrieved March 23, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.