Has sent thread hijacked messages from compromised emails.1
- Tactic
- Resource Development
- Platform
- PRE
- Version
- 1.1
- Created
- 01 October 2020
- Last modified
- 12 May 2026
- Contributors
- Tristan Bennett, Seamless Intelligence; Bryan Onel
Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Compromised email accounts can also be used in the acquisition of infrastructure (ex: Domains).
Email Accounts MITRE reference T1586.002
14 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Has used compromised email accounts to conduct spearphishing against contacts of the original victim.1
Has payed employees, suppliers, and business partners of target organizations for credentials.12
Has compromised legitimate email accounts to use in their spearphishing operations.1
Has compromised legitimate email accounts to use in their spear-phishing operations.1
Has regularly used compromised email accounts in spearphishing campaigns.12
All 14 groups for this technique · 6 newest in this preview
2 campaigns have been recorded using this technique. Listed newest first; dates are year-granularity and attribution is MITRE’s.
During Salesforce Data Exfiltration, threat actors used compromised emails to create Salesforce trial accounts.1
During Operation AkaiRyū, MirrorFace used compromised accounts to send spearphishing emails.1
All 2 campaigns for this technique
Offense vs defense T1586.002
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
Email Accounts detection strategy DET0861
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of Email Accounts
AN1993 · PRE
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: Phishing).
This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.