Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TEMP_Heretic

Description

TEMP_Heretic is a threat actor that has been observed engaging in targeted spear-phishing campaigns. They exploit vulnerabilities in email platforms, such as Zimbra, to exfiltrate emails from government, military, and media organizations. They use multiple outlook.com email addresses and manually craft content for each email before sending it.

AI Analysis

· 1 week ago

Executive Summary

TEMP_Heretic is a moderate-level threat actor known for conducting targeted spear-phishing campaigns against government, military, and media organizations. Their primary method involves exploiting vulnerabilities in email platforms like Zimbra to exfiltrate sensitive communications. TEMP_Heretic's activities are indicative of an organized effort to gather intelligence, likely for espionage or strategic gain.

Goals & Targeting

TEMP_Heretic likely operates with the goal of collecting intelligence and maintaining access to critical communications channels. Their targeting of government and military organizations indicates an intent to gather information of national security importance, while their focus on media organizations may suggest an interest in disseminating or controlling sensitive information. The actor's targeting profile aligns with a moderate-level threat group seeking to impact specific high-value sectors.

Enhanced Description

TEMP_Heretic is a cyber threat actor that specializes in targeted phishing campaigns. They have demonstrated the ability to compromise email systems by exploiting vulnerabilities in platforms like Zimbra, allowing them to extract sensitive information from government, military, and media organizations. TEMP_Heretic's operations are characterized by their use of carefully crafted phishing emails sent from Outlook.com accounts, indicating a focus on avoiding detection while maximizing the effectiveness of their campaigns. Their targeting suggests a strategic interest in sectors that handle classified or sensitive data.

Key Capabilities

  • Targeted spear-phishing campaigns
  • Exploitation of email platform vulnerabilities
  • Manual crafting of phishing emails
  • Data exfiltration
  • Use of compromised email accounts

MITRE ATT&CK Tactics

Espionage
Collection Activities

ATT&CK Techniques

T1566.001
T1036.004
T1059
T1055
T1486
T1048

Software / Tooling

Zimbra email platform exploits
Custom phishing tools
Email exfiltration tools

Campaigns & Victims

TEMP_Heretic has been active since at least 2017, targeting high-value individuals within government and military organizations. Their campaigns often involve long-term operational planning, with a focus on maintaining persistence and avoiding detection. The actor's use of Outlook.com accounts suggests an effort to blend in with legitimate email traffic while conducting their activities.

IOC Patterns

  • Spear-phishing emails targeting specific individuals
  • Exfiltration of large volumes of email data via compromised Zimbra accounts
  • Use of multiple Outlook.com accounts for phishing attempts
  • Inclusion of malicious links or attachments in crafted messages

Recommended Actions

  • Implement advanced email filtering to detect and block spear-phishing attempts.
  • Conduct regular user training on identifying phishing emails.
  • Monitor network traffic for signs of data exfiltration.
  • Patch and secure email platforms like Zimbra to mitigate known vulnerabilities.

Suggested Tags

APT-like
Espionage
Intelligence Gathering
Data Exfiltration
Government Targeting
Military Targeting
Media Targeting

Confidence Assessment

Moderate confidence in the data provided, with several gaps. The exact origin and full capabilities of TEMP_Heretic remain unclear. There is limited information on their toolset beyond email exploitation techniques. Additionally, the long-term operational patterns and scope of their campaigns are not fully understood.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
Government Targeting
APT-like
Espionage
Intelligence Gathering
Data Exfiltration
Military Targeting
Media Targeting

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.