Skip to content
Every technique
T1534No distinct observable

Internal Spearphishing

Lateral MovementLinux, macOS, Office Suite, SaaS, Windows

Where this stands

A reviewer read the telemetry and concluded there is nothing here to detect that a sibling technique does not already cover.

No analytic in this brief carries a signal that distinguishes 'internal spearphishing from an already-compromised trusted account' from ordinary activity or from sibling techniques. AN0147 (Windows) needs a correlation across a logon anomaly (4624/4648/4625/4672), an internal mail send and a follow-on execution that Sigma cannot join, and each event in isolation — a logon, a process creation — carries no internal-origin marker; none of the four logSources include a mail-transport or O365-audit source that could show sender/recipient are both internal. […]

Covered instead by T1204, T1566.001, T1566.002.

What the technique is

After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization. Internal spearphishing is multi-staged campaign where a legitimate account is initially compromised either by controlling the user's device or by compromising the account credentials of the user. Adversaries may then attempt to take advantage of the trusted internal account to increase the likelihood of tricking more victims into falling for phish attempts, often incorporating Impersonation. For example, adversaries may leverage Spearphishing Attachment or Spearphishing Link as part of internal spearphishing to deliver a payload or redirect to an external site to capture credentials through Input Capture on sites that mimic login interfaces. Adversaries may also leverage internal chat apps, such as Microsoft Teams, to spread malicious content or engage users in attempts to capture sensitive information and/or credentials.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN0147

    Sequence of internal email sent from a recently compromised user account (preceded by abnormal logon or device activity), with attachments or links leading to execution or credential harvesting. Defender observes: internal mail delivery to peers with high entropy attachments, followed by click events, process initiation, or credential prompts.

  • AN0148

    Delivery of suspicious internal communication (e.g., Thunderbird, Evolution) using compromised internal accounts. Sequence of: unexpected user activity + mail transfer logs + download or execution of attachments.

  • AN0149

    Abnormal Apple Mail use, including internal email relays followed by file execution or script events (e.g., attachments launched via Preview, terminal triggered from Mail.app)

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.