Sub-technique of T1589 Gather Victim Identity Information.View on attack.mitre.org
Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email infrastructure and addresses for employees.
Adversaries may easily gather email addresses, since they may be readily available and exposed via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Email addresses could also be enumerated via more active means (i.e. Active Scanning), such as probing and analyzing responses from authentication services that may reveal valid usernames in a system. For example, adversaries may be able to enumerate email addresses in Office 365 environments by querying a variety of publicly available API endpoints, such as autodiscover and GetCredentialType.
Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Email Accounts), and/or initial access (ex: Phishing or Brute Force via External Remote Services).
Rules on DetectionCode tagged with T1589.002.
| Rule | Level | Log source |
|---|---|---|
| Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock | medium | windows / ps_script |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Kerberos User Enumeration | Anomaly | NULL | Windows Event Log Security 4768 |
| Used by | Procedure example |
|---|---|
| GroupAPT32 | APT32 has collected e-mail addresses for activists and bloggers in order to target them with spyware. |
| GroupEXOTIC LILY | EXOTIC LILY has gathered targeted individuals' e-mail addresses through open source research and website contact forms. |
| GroupHAFNIUM | HAFNIUM has collected e-mail addresses for users they intended to target. |
| GroupHEXANE | HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing. |
| GroupKimsuky | Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering. |
| GroupLAPSUS$ | LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts. |
| GroupLazarus Group | Lazarus Group collected email addresses belonging to various departments of a targeted organization which were used in follow-on phishing campaigns. |
| GroupMagic Hound | Magic Hound has identified high-value email accounts in academia, journalism, NGO's, foreign policy, and national security for targeting. |
| Used by | Procedure example |
|---|---|
| ToolAADInternals | AADInternals can check for the existence of user email addresses using public Microsoft APIs. |
| Used by | Procedure example |
|---|---|
| CampaignQuad7 Activity | Quad7 Activity has gathered targeted individual’s e-mail addresses for the password spraying attempts. |
| CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution utilizes thread spoofing of existing email threads in order to execute spear phishing operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.