MITRE ATT&CK Technique
T1071.003Mail Protocols
- First Reported
- Oct 2, 2026
- Latest Reported
- Oct 2, 2026
Official Description
Adversaries may communicate using application layer protocols associated with electronic mail delivery to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Protocols such as SMTP/S, POP3/S, and IMAP that carry electronic mail may be very common in environments. Packets produced from these protocols may have many fields and headers in which data can be concealed. Data could also be concealed within the email messages themselves. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.(Citation: FireEye APT28)
Protocols such as SMTP/S, POP3/S, and IMAP that carry electronic mail may be very common in environments. Packets produced from these protocols may have many fields and headers in which data can be concealed. Data could also be concealed within the email messages themselves. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.(Citation: FireEye APT28)
- Tactics
- Command And Control
- Platforms
- Linux, macOS, Network Devices, Windows
- Parent Technique
- T1071 · Application Layer Protocol
- MITRE Version
- 1.2
- Last Modified
- Oct 24, 2025
Reported Context (1)
- AVERAT connects outbound on port 25, issues EHLO, and requests STARTTLS before its encrypted C2 session. Rapid7 Details BPFDoor and AVERAT Activity Targeting Network-Edge Appliances
Malware (3)
MITRE ATT&CK (27)
Vendors (4)
Products (2)
Tools (2)
Industries (2)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.