Has placed specific content in phishing emails to target members of particular political parties.1
Gather Victim Org Information T1591
- Tactic
- Reconnaissance
- Platform
- PRE
- Version
- 1.1
- Created
- 02 October 2020
- Last modified
- 12 May 2026
Adversaries may gather information about the victim's organization that can be used during targeting. Information about an organization may include a variety of details, including the names of divisions/departments, specifics of business operations, as well as the roles and responsibilities of key employees.
Gather Victim Org Information MITRE reference T1591
7 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Has gathered information on victim organizations through email and social media interaction.1
Has conducted extensive reconnaissance pre-compromise to gain information about the targeted organization.1
Has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others.1 Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest.2
Has compiled a list of victims by filtering companies by revenue using Zoominfo, which is a service that provides business information.1
Has studied publicly available information about a targeted organization to tailor spearphishing efforts against specific departments and/or individuals.1
All 7 groups for this technique · 6 newest in this preview
2 campaigns have been recorded using this technique. Listed newest first; dates are year-granularity and attribution is MITRE’s.
During Operation Digital Eye, threat actors concealed malicious activity by using terms that aligned with the technological context of the targeted organization.1
For Operation Dream Job, Lazarus Group gathered victim organization information to identify specific targets.1
All 2 campaigns for this technique
Offense vs defense T1591
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
Gather Victim Org Information detection strategy DET0890
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of Gather Victim Org Information
AN2022 · PRE
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls. Efforts should focus on minimizing the amount and sensitivity of data available to external parties.