Adversaries may communicate using application layer protocols associated with electronic mail delivery to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as SMTP/S, POP3/S, and IMAP that carry electronic mail may be very common in environments. Packets produced from these protocols may have many fields and headers in which data can be concealed. Data could also be concealed within the email messages themselves. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.(Citation: FireEye APT28)

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Filter Network Traffic
is blocked by Network Intrusion Prevention
is blocked by Detection of Mail Protocol-Based C2 Activity (SMTP, IMAP, POP3)
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Covert Channel Analysis
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Network Connection Termination
is blocked by Session Integrity
is blocked by Domain Name Service (DNS) Resolution
is blocked by Architecture & Provisioning for Name / Address Resolution Service
is blocked by Secure Name / Address Resolution Service (Recursive or Caching Resolver)
is blocked by Out-of-Band Channels
Impressum Deutsch Englisch