FORENSIA

ATT&CK · T1589.003 · sub-technique

Employee Names

Tactics: reconnaissance

About

Adversaries may gather employee names that can be used during targeting. Employee names be used to derive email addresses as well as to help guide other reconnaissance efforts and/or craft more-believable lures. Adversaries may easily gather employee names, since they may be readily available and exposed via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Compromise Accounts), and/or initial access (ex: Phishing or Valid Accounts).

Used by actors

3 known groups

Software

0 malware/tools implement this

None mapped.

Corpus indicators tagged with this technique

5 indicators in the corpus carry T1589.003.

IndicatorTypeFamilySevSrc
198.53.64.194ipphishing701
175.155.64.221ipphishing701
185.229.26.83ipphishing701
213.169.49.142ipphishing701
baccarat.com.audomainphishing651