FORENSIA

ATT&CK · T1566.003 · sub-technique

Spearphishing via Service

Tactics: initial-access

About

Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries send messages through various social media services, personal webmail, and other non-enterprise controlled services. These services are more likely to have a less-strict security policy than an enterprise. As with most kinds of spearphishing, the goal is to generate rapport with the target or get the target's interest in some way. Adversaries will create fake social media accounts and message employees for potential job opportunities. Doing so allows a plausible reason for asking about services, policies, and software that's running in an environment. The adversary can then send malicious links or attachments through these services. A common example is to build rapport with a target via social media, then send content to a personal webmail service that the target uses on their work computer. This allows an adversary to bypass some email restrictions on the work account, and the target is more likely to open the file since it's something they were expecting. If the payload doesn't work as expected, the adversary can continue normal communications and troubleshoot with the target on how to get it working.

Platforms: Linux, macOS, WindowsParent: T1566 PhishingMITRE ATT&CK ↗

Corpus indicators tagged with this technique

98 indicators in the corpus carry T1566.003.

IndicatorTypeFamilySevSrc
a648db354820ea4d02940cb1702b35974513b7aae83f6dffaacaac4ba31f9295hash803
4fcfa88fffacbce30bbe2136753c9ab5a4c092940d2406fd9d44d5118e745b9dhash803
9d0a55c545c4147956db2c2667c4ed931a2875309147548b1dfdd216228f5f73hash803
e0a6a71c605d9a4076147e9537f82f79f1e1eccadc874595160aa4637ff4088chash803
3e7066e44132e64360a30974b6ea3671hash803
584a9448dda46bd590d7a2f86228100d2ae6e0d6d990c1a4459ed5ee28e07ae8hash803
0ffb16209def5500ff4380d9e8093437hash803
0857148fb0bc4aa7adf967ede2307bdb4fc427065d5b6a6db132688a5a8e1eb8hash803
8c9b6542f73c5c7fe455b52f5101314407da4f65ff48e7ebf6896605e607c8d0hash803
66a3836b9a17771bce2161f6b73cbc2494a91e49d6aa30d2d53711e8d10de60dhash803
a75eab31d7ff06b6864960ad7e633be3f9730ff3d3873e4539c8f425fc632dadhash803
6894a51278ec89118276c2dd2dc36e6f9ea2790ahashphishing802
febb622cd9eeb5c8860dcef4cbfd4b74hashphishing802
de82998ad5fcd63deae030803388e0fb4290d6223fda82368fd25b99b823f0d2hash803
40b41979b317406f8abc601677a3b93aaf6ef8ab8ac188b8f383735e388f13b5hash803
2d2a251a88632f010fd9671789746908eeccaa5bc5c0a5d25e4649efe4f5b15dhash803
7b2c661cfb69e9c75df90d5102647bb014c28ad5hash803
483a36fb9e4aef9704aa1e4edfb88c492dfe4140hash803
314f4b59535d1b783e1c20c2be00f9e30f8ed27b2e21fad06a73b47ea43279efhash803
3119cf37b8267db8a2dcd11d9a83d5237d7ef1e42388e7c9afa2831b91da8a2dhash803
https://ws.ztts88.cyou/upload.phpurl753
https://ws.ztts88.cyou/file/cg.exeurl753
https://nwphotoblog.comurl753
http://panel.securehubcloud.com/loginurlphishing752
103.214.172.33ip702
206.238.115.58ip702
154.211.86.110ip702
allegro-stroe.comdomain651
allegrostroe.shopdomain651
nasdaqpro.topdomain651

Showing the top 30 by severity of 98.