Umbra Wiki technique technique/T1213.005
Back to wiki

T1213.005 — Messaging Applications

provenance: imported · ATT&CK: T1213.005

T1213.005: Messaging Applications

MITRE ATT&CK® Enterprise technique

Tactics Collection
Platforms Office Suite, SaaS
Permissions required
Version 1.0
Parent technique T1213

Description

Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information.

The following is a brief list of example information that may hold potential value to an adversary and may also be found on messaging applications:

  • Testing / development credentials (i.e., Chat Messages)
  • Source code snippets
  • Links to network shares and other internal resources
  • Proprietary data(Citation: Guardian Grand Theft Auto Leak 2022)
  • Discussions about ongoing incident response efforts(Citation: SC Magazine Ragnar Locker 2021)(Citation: Microsoft DEV-0537)

In addition to exfiltrating data from messaging applications, adversaries may leverage data from chat messages in order to improve their targeting - for example, by learning more about an environment or evading ongoing incident response efforts.(Citation: Sentinel Labs NullBulge 2024)(Citation: Permiso Scattered Spider 2023)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1213/005
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/