MITRE ATT&CK Technique
T1114.002Remote Email Collection
- First Reported
- Sep 15, 2026
- Latest Reported
- Sep 22, 2026
Official Description
Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as [MailSniper](https://attack.mitre.org/software/S0413) can be used to automate searches for specific keywords.
- Tactics
- Collection
- Platforms
- Office Suite, Windows
- Parent Technique
- T1114 · Email Collection
- MITRE Version
- 1.3
- Last Modified
- May 12, 2026
Reported Context (2)
- The operator used a remote-desktop host to access captured mailboxes manually. CSuite Campaign Uses Phishing, M365 Session Theft and Remote-Access Tools Against US and EU Organizations
- The attacker reportedly monitored compromised inboxes and downloaded replies as .eml files. Report: Revolut Hackers Used Infostealer-Stolen Government Credentials in Social-Engineering Scheme
MITRE ATT&CK (28)
Vendors (8)
Products (10)
Tools (3)
Industries (7)
Countries (8)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.