Gather Victim Org Information

T1591

Technique with 4 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may gather information about the victim's organization that can be used during targeting. Information about an organization may include a variety of details, including the names of divisions/departments, specifics of business operations, as well as the roles and responsibilities of key employees.

Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. Information about an organization may also be exposed to adversaries via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information or Search Open Websites/Domains), establishing operational resources (ex: Establish Accounts or Compromise Accounts), and/or initial access (ex: Phishing or Trusted Relationship).

Detection rules2

Rules on DetectionCode tagged with T1591 or one of its sub-techniques.

Sigma2

RuleLevelLog sourceTechnique
Bitbucket User Details Export Attempt Detectedmediumbitbucket / NULLT1591.004
Bitbucket User Permissions Export Attemptmediumbitbucket / NULLT1591.004

Splunk0

No Splunk rules are mapped to this technique yet.

Sub-techniques4

IDNameExamples
T1591.001Determine Physical Locations1
T1591.002Business Relationships3
T1591.003Identify Business Tempo0
T1591.004Identify Roles5

Groups7

Software0

None recorded.

Campaigns2

Procedure examples9

Groups7

Used byProcedure example
GroupAPT28

APT28 has used large language models (LLMs) to gather information about satellite capabilities.

GroupFIN7

FIN7 has compiled a list of victims by filtering companies by revenue using Zoominfo, which is a service that provides business information.

GroupKimsuky

Kimsuky has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others. Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest.

GroupLazarus Group

Lazarus Group has studied publicly available information about a targeted organization to tailor spearphishing efforts against specific departments and/or individuals.

GroupMirrorFace

MirrorFace has placed specific content in phishing emails to target members of particular political parties.

GroupMoonstone Sleet

Moonstone Sleet has gathered information on victim organizations through email and social media interaction.

GroupVolt Typhoon

Volt Typhoon has conducted extensive reconnaissance pre-compromise to gain information about the targeted organization.

Campaigns2

Used byProcedure example
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors concealed malicious activity by using terms that aligned with the technological context of the targeted organization.

CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group gathered victim organization information to identify specific targets.

References2

  1. SEC EDGAR Search Open source
    U.S. SEC. (n.d.). EDGAR - Search and Access. Retrieved November 17, 2024.
  2. ThreatPost Broadvoice Leak Open source
    Seals, T. (2020, October 15). Broadvoice Leak Exposes 350M Records, Personal Voicemail Transcripts. Retrieved October 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.