ATT&CK · T1213.005 · sub-technique
Messaging Applications
Tactics: collection
About
Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information. The following is a brief list of example information that may hold potential value to an adversary and may also be found on messaging applications: * Testing / development credentials (i.e., Chat Messages) * Source code snippets * Links to network shares and other internal resources * Proprietary data * Discussions about ongoing incident response efforts In addition to exfiltrating data from messaging applications, adversaries may leverage data from chat messages in order to improve their targeting - for example, by learning more about an environment or evading ongoing incident response efforts.
Used by actors
3 known groups
Software
1 malware/tools implement this
Corpus indicators tagged with this technique
0 indicators in the corpus carry T1213.005.
No corpus indicators are tagged with this technique yet.