Email Addresses

T1589.002

Sub-technique of T1589 Gather Victim Identity Information.View on attack.mitre.org

About this technique

Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email infrastructure and addresses for employees.

Adversaries may easily gather email addresses, since they may be readily available and exposed via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Email addresses could also be enumerated via more active means (i.e. Active Scanning), such as probing and analyzing responses from authentication services that may reveal valid usernames in a system. For example, adversaries may be able to enumerate email addresses in Office 365 environments by querying a variety of publicly available API endpoints, such as autodiscover and GetCredentialType.

Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Email Accounts), and/or initial access (ex: Phishing or Brute Force via External Remote Services).

Detection rules2

Rules on DetectionCode tagged with T1589.002.

Sigma1

Splunk1

RuleTypeRiskData source
Kerberos User EnumerationAnomalyNULLWindows Event Log Security 4768

Groups14

Software1

Campaigns2

Procedure examples17

Groups14

Used byProcedure example
GroupAPT32

APT32 has collected e-mail addresses for activists and bloggers in order to target them with spyware.

GroupEXOTIC LILY

EXOTIC LILY has gathered targeted individuals' e-mail addresses through open source research and website contact forms.

GroupHAFNIUM

HAFNIUM has collected e-mail addresses for users they intended to target.

GroupHEXANE

HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing.

GroupKimsuky

Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering.

GroupLAPSUS$

LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts.

GroupLazarus Group

Lazarus Group collected email addresses belonging to various departments of a targeted organization which were used in follow-on phishing campaigns.

GroupMagic Hound

Magic Hound has identified high-value email accounts in academia, journalism, NGO's, foreign policy, and national security for targeting.

View all 14 groups examples

Software1

Used byProcedure example
ToolAADInternals

AADInternals can check for the existence of user email addresses using public Microsoft APIs.

Campaigns2

Used byProcedure example
CampaignQuad7 Activity

Quad7 Activity has gathered targeted individual’s e-mail addresses for the password spraying attempts.

CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution utilizes thread spoofing of existing email threads in order to execute spear phishing operations.

References5

  1. Azure Active Directory Reconnaisance Open source
    Dr. Nestori Syynimaa. (2020, June 13). Just looking: Azure Active Directory reconnaissance as an outsider. Retrieved May 27, 2022.
  2. CNET Leaks Open source
    Ng, A. (2019, January 17). Massive breach leaks 773 million email addresses, 21 million passwords. Retrieved October 20, 2020.
  3. GitHub Office 365 User Enumeration Open source
    gremwell. (2020, March 24). Office 365 User Enumeration. Retrieved May 27, 2022.
  4. GrimBlog UsernameEnum Open source
    GrimHacker. (2017, July 24). Office365 ActiveSync Username Enumeration. Retrieved December 9, 2021.
  5. HackersArise Email Open source
    Hackers Arise. (n.d.). Email Scraping and Maltego. Retrieved October 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.