Activity timeline
T1114.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 4 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1114.001 Local Email Collection is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix, as a sub-technique of T1114 Email Collection. Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 7 critical, 6 high.
Threats that use T1114.001 most often also use T1071.001 Web Protocols (9 threats), T1005 Data from Local System (8 threats), T1082 System Information Discovery (6 threats), T1190 Exploit Public-Facing Application (5 threats), T1547.001 Registry Run Keys / Startup Folder (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
8 tracked threat actors appear in the threats that use T1114.001; the most frequent are APT28 (2), BlueDelta (1), Cavern Manticore (1), Forest Blizzard (1), Iran Ministry of Intelligence (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1114.001.
Data sources
Telemetry that can reveal T1114.001, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
Threat actors using it
Tracked threats
13 tracked threats use T1114.001.
- cPanel/WHM CalDAV/CardDAV and WP Toolkit Flaws Enable Cross-Account Access and Root Privilege Escalation…critical
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalistshigh
- Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencieshigh
- SmokeLoader Backdoor/Loader: Process Hollowing Injection into explorer.exe with Anti-VM/Anti-Debug Evasion…high
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injectioncritical
- Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relayhigh
- Kynx Stealer: MaaS Infostealer Targeting Crypto Wallets, Gaming Platforms, and AI Coding Toolscritical
- Unpatched Claude for Chrome Extension Flaws Enable Unauthorized Account Actions via Fake Clicks and…critical
- Kali365/Octopi365 Device Code Phishing-as-a-Service Campaigncritical
- Targeted Espionage Campaign Against a Global Stock Exchange Executive via Incremental Outlook OST Mailbox…high
- APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via…high
- RoundCube Webmail Active Exploitation — CVE-2025-49113 Deserialization RCE (CVSS 9.9) + CVE-2025-68461 XSS…critical
- SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub…critical
Detection coverage
Threadlinqs maintains 30 detection rules mapped to T1114.001 (SPL 8, KQL 12, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1114 Email Collection — 129 tracked threats at the technique level.