A threat actor exploiting email platform vulnerabilities in targeted phishing campaigns against government, military, and media organizations.
Analyst brief
TEMP_Heretic is a threat actor of unknown specific origin, likely linked to China. It primarily targets government, military, and media organizations. Its main TTPs involve targeted spear-phishing campaigns, exploiting vulnerabilities in email platforms like Zimbra for email exfiltration, and using multiple outlook.com addresses. Defenders must prioritize patching email platform vulnerabilities, enhancing detection rules for suspicious outlook.com-originating emails, and conducting user awareness training to identify manually crafted, targeted phishing content.
TEMP_Heretic
unknown
TEMP_Heretic is a threat actor that has been observed engaging in targeted spear-phishing campaigns. They exploit vulnerabilities in email platforms, such as Zimbra, to exfiltrate emails from government, military, and media organizations. They use multiple outlook.com email addresses and manually craft content for each email before sending it.