Email Collection: Remote Email Collection, Sub-technique T1114.002 - Enterprise (original) (raw)

C0063

2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to gather data and email messages from Exchange services related to OT topics and technical work carried out within organizations.[1]

G0006

APT1

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived.[2]

G0007

APT28

APT28 has collected emails from victim Microsoft Exchange servers.[3][4]

G0016

APT29

APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests.[5][6]

G0114

Chimera

Chimera has harvested data from remote mailboxes including through execution of \\c$\Users\\AppData\Local\Microsoft\Outlook*.ost.[7]

G0035

Dragonfly

Dragonfly has accessed email accounts using Outlook Web Access.[8]

G0085

FIN4

FIN4 has accessed and hijacked online email communications using stolen credentials.[9][10]

G0125

HAFNIUM

HAFNIUM has used web shells and MSGraph to export mailbox data.[11][12][13]

C0038

HomeLand Justice

During HomeLand Justice, threat actors made multiple HTTP POST requests to the Exchange servers of the victim organization to transfer data.[14]

G0004

Ke3chang

Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes.[15][16]

G0094

Kimsuky

Kimsuky has used tools such as the MailFetch mail crawler to collect victim emails (excluding spam) from online services via IMAP.[17]

G0077

Leafminer

Leafminer used a tool called MailSniper to search through the Exchange server mailboxes for keywords.[18]

S0395

LightNeuron

LightNeuron collects Exchange emails matching rules specified in its configuration.[19]

G0059

Magic Hound

Magic Hound has exported emails from compromised Exchange servers including through use of the cmdlet New-MailboxExportRequest.[20][21]

S0413

MailSniper

MailSniper can be used for searching through email in Exchange and Office 365 environments.[22]

S0053

SeaDuke

Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials.[23]

C0024

SolarWinds Compromise

During the SolarWinds Compromise, APT29 collected emails from specific individuals, such as executives and IT staff, using New-MailboxExportRequest followed by Get-MailboxExportRequest.[24][25]

G1033

Star Blizzard

Star Blizzard has remotely accessed victims' email accounts to steal messages and attachments.[26]

S0476

Valak

Valak can collect sensitive mailing information from Exchange servers, including credentials and the domain certificate of an enterprise.[27]

G1055

VOID MANTICORE

VOID MANTICORE has gathered victim email-content from victim servers.[28]