TEMP_Heretic is a threat actor that has been observed engaging in targeted spear-phishing campaigns. They exploit vulnerabilities in email platforms, such as Zimbra, to exfiltrate emails from government, military, and media organizations. They use multiple outlook.com email addresses and manually craft content for each email before sending it.
Executive Summary
TEMP_Heretic is a moderate-level threat actor known for conducting targeted spear-phishing campaigns against government, military, and media organizations. Their primary method involves exploiting vulnerabilities in email platforms like Zimbra to exfiltrate sensitive communications. TEMP_Heretic's activities are indicative of an organized effort to gather intelligence, likely for espionage or strategic gain.
Goals & Targeting
TEMP_Heretic likely operates with the goal of collecting intelligence and maintaining access to critical communications channels. Their targeting of government and military organizations indicates an intent to gather information of national security importance, while their focus on media organizations may suggest an interest in disseminating or controlling sensitive information. The actor's targeting profile aligns with a moderate-level threat group seeking to impact specific high-value sectors.
Enhanced Description
TEMP_Heretic is a cyber threat actor that specializes in targeted phishing campaigns. They have demonstrated the ability to compromise email systems by exploiting vulnerabilities in platforms like Zimbra, allowing them to extract sensitive information from government, military, and media organizations. TEMP_Heretic's operations are characterized by their use of carefully crafted phishing emails sent from Outlook.com accounts, indicating a focus on avoiding detection while maximizing the effectiveness of their campaigns. Their targeting suggests a strategic interest in sectors that handle classified or sensitive data.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TEMP_Heretic has been active since at least 2017, targeting high-value individuals within government and military organizations. Their campaigns often involve long-term operational planning, with a focus on maintaining persistence and avoiding detection. The actor's use of Outlook.com accounts suggests an effort to blend in with legitimate email traffic while conducting their activities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the data provided, with several gaps. The exact origin and full capabilities of TEMP_Heretic remain unclear. There is limited information on their toolset beyond email exploitation techniques. Additionally, the long-term operational patterns and scope of their campaigns are not fully understood.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics