FORENSIA

ATT&CK · T1598

Phishing for Information

Tactics: reconnaissance

About

Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Phishing for information is different from Phishing in that the objective is gathering data from the victim rather than executing malicious code. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass credential harvesting campaigns. Adversaries may also try to obtain information directly through the exchange of emails, instant messages, or other electronic conversation means. Victims may also receive phishing messages that direct them to call a phone number where the adversary attempts to collect confidential information. Phishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Establish Accounts or Compromise Accounts) and/or sending multiple, seemingly urgent messages. Another way to accomplish this is by Email Spoofing the identity of the sender, which can be used to fool both the human recipient as well as automated security tools. Phishing for information may also involve evasive techniques, such as removing or manipulating emails or metadata/headers from compromised accounts being abused to send messages (e.g., Email Hiding Rules).

Platforms: PREMITRE ATT&CK ↗

Used by actors

5 known groups

Software

0 malware/tools implement this

None mapped.

Corpus indicators tagged with this technique

384 indicators in the corpus carry T1598.

IndicatorTypeFamilySevSrc
584a9448dda46bd590d7a2f86228100d2ae6e0d6d990c1a4459ed5ee28e07ae8hash803
a648db354820ea4d02940cb1702b35974513b7aae83f6dffaacaac4ba31f9295hash803
3119cf37b8267db8a2dcd11d9a83d5237d7ef1e42388e7c9afa2831b91da8a2dhash803
a75eab31d7ff06b6864960ad7e633be3f9730ff3d3873e4539c8f425fc632dadhash803
0ffb16209def5500ff4380d9e8093437hash803
483a36fb9e4aef9704aa1e4edfb88c492dfe4140hash803
9d0a55c545c4147956db2c2667c4ed931a2875309147548b1dfdd216228f5f73hash803
e0a6a71c605d9a4076147e9537f82f79f1e1eccadc874595160aa4637ff4088chash803
8c9b6542f73c5c7fe455b52f5101314407da4f65ff48e7ebf6896605e607c8d0hash803
8e5546c83d764e1287b55cbe868a45344a6f0afa9782d798d03b2b7cfc53ec38hashphishing801
ec7b0bc82c00464d8e0a59bc19c585e2hashphishing801
2d2a251a88632f010fd9671789746908eeccaa5bc5c0a5d25e4649efe4f5b15dhash803
0857148fb0bc4aa7adf967ede2307bdb4fc427065d5b6a6db132688a5a8e1eb8hash803
7b2c661cfb69e9c75df90d5102647bb014c28ad5hash803
40b41979b317406f8abc601677a3b93aaf6ef8ab8ac188b8f383735e388f13b5hash803
3e7066e44132e64360a30974b6ea3671hash803
4fe8bec780537aa223406965415c1f85e83eec1f4e2181cf82e2a7b7516026e6hashphishing801
de82998ad5fcd63deae030803388e0fb4290d6223fda82368fd25b99b823f0d2hash803
4fcfa88fffacbce30bbe2136753c9ab5a4c092940d2406fd9d44d5118e745b9dhash803
314f4b59535d1b783e1c20c2be00f9e30f8ed27b2e21fad06a73b47ea43279efhash803
66a3836b9a17771bce2161f6b73cbc2494a91e49d6aa30d2d53711e8d10de60dhash803
84ecdca915f1af822ccc8a04479f5179104f353csha1phishing781
3b8bb7631b39f455d31544b55ba97b49ab1888c1sha1phishing781
9bd164dd3f50d196c7dff4f6c1b0f1345ac96d9asha1phishing781
https://ws.ztts88.cyou/file/cg.exeurl753
http://xupqrnn.one/us?__theme_site_ticket=urlphishing751
https://usps.xupqnqz.one/uqjmwurlphishing751
https://admin-zone.tbpay.uk/users/tenant`urlphishing752
http://91.215.85.103/pay_or_leak/instructure_affected_schools_list.txturlphishing754
https://nwphotoblog.comurl753

Showing the top 30 by severity of 384.