T1213.005 — Messaging Applications
T1213.005: Messaging Applications
MITRE ATT&CK® Enterprise technique
| Tactics | Collection |
| Platforms | Office Suite, SaaS |
| Permissions required | — |
| Version | 1.0 |
| Parent technique | T1213 |
Description
Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information.
The following is a brief list of example information that may hold potential value to an adversary and may also be found on messaging applications:
- Testing / development credentials (i.e., Chat Messages)
- Source code snippets
- Links to network shares and other internal resources
- Proprietary data(Citation: Guardian Grand Theft Auto Leak 2022)
- Discussions about ongoing incident response efforts(Citation: SC Magazine Ragnar Locker 2021)(Citation: Microsoft DEV-0537)
In addition to exfiltrating data from messaging applications, adversaries may leverage data from chat messages in order to improve their targeting - for example, by learning more about an environment or evading ongoing incident response efforts.(Citation: Sentinel Labs NullBulge 2024)(Citation: Permiso Scattered Spider 2023)
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1213/005
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/