# T1114.001 Local Email Collection

> As of 2026-10-05, T1114.001 (Local Email Collection) appears in 13 tracked threats, first reported 2026-02-05 and most recently 2026-09-23, with linked actors including APT28, BlueDelta, Cavern Manticore; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 13 (7 critical, 6 high)
- **First seen:** 2026-02-05
- **Last seen:** 2026-09-23
- **Threat actors:** 8
- **Detection rules:** 30 (counts only; Blue tier and above)

## Key facts

- **ID:** T1114.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection
- **Matrix:** Enterprise
- **Parent:** T1114
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1114/001/

## Activity timeline

T1114.001 first appeared in tracked threats on 2026-02-05 and was most recently reported on 2026-09-23. The busiest month was 2026-09 with 4 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1114.001 Local Email Collection is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix, as a sub-technique of [T1114 Email Collection](https://intel.threadlinqs.com/technique/T1114). Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 7 critical, 6 high.

Threats that use T1114.001 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (9 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (8 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (6 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (5 threats), [T1547.001 Registry Run Keys / Startup Folder](https://intel.threadlinqs.com/technique/T1547.001) (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1114.001; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (2), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (1), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (1), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (1), [Iran Ministry of Intelligence](https://intel.threadlinqs.com/actor/Iran%20Ministry%20of%20Intelligence) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1114.001.

- [M1041 Encrypt Sensitive Information](https://attack.mitre.org/mitigations/M1041/)
- [M1060 Out-of-Band Communications Channel](https://attack.mitre.org/mitigations/M1060/)

## Data sources

Telemetry that can reveal T1114.001, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1
- [Iran Ministry of Intelligence](https://intel.threadlinqs.com/actor/Iran%20Ministry%20of%20Intelligence) — 1
- [Security](https://intel.threadlinqs.com/actor/Security) — 1
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 1
- [Warlock](https://intel.threadlinqs.com/actor/Warlock) — 1

## Tracked threats

13 tracked threats use T1114.001.

- [cPanel/WHM CalDAV/CardDAV and WP Toolkit Flaws Enable Cross-Account Access and Root Privilege Escalation…](https://intel.threadlinqs.com/threat/TL-2026-2636) — critical — 2026-09-23
- [Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists](https://intel.threadlinqs.com/threat/TL-2026-2543) — high — 2026-09-16
- [Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies](https://intel.threadlinqs.com/threat/TL-2026-2534) — high — 2026-09-16
- [SmokeLoader Backdoor/Loader: Process Hollowing Injection into explorer.exe with Anti-VM/Anti-Debug Evasion…](https://intel.threadlinqs.com/threat/TL-2026-2482) — high — 2026-09-13
- [Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection](https://intel.threadlinqs.com/threat/TL-2026-2082) — critical — 2026-08-20
- [Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relay](https://intel.threadlinqs.com/threat/TL-2026-2053) — high — 2026-08-17
- [Kynx Stealer: MaaS Infostealer Targeting Crypto Wallets, Gaming Platforms, and AI Coding Tools](https://intel.threadlinqs.com/threat/TL-2026-1943) — critical — 2026-08-08
- [Unpatched Claude for Chrome Extension Flaws Enable Unauthorized Account Actions via Fake Clicks and…](https://intel.threadlinqs.com/threat/TL-2026-1318) — critical — 2026-07-14
- [Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign](https://intel.threadlinqs.com/threat/TL-2026-0984) — critical — 2026-06-28
- [Targeted Espionage Campaign Against a Global Stock Exchange Executive via Incremental Outlook OST Mailbox…](https://intel.threadlinqs.com/threat/TL-2026-0755) — high — 2026-06-10
- [APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via…](https://intel.threadlinqs.com/threat/TL-2026-0133) — high — 2026-02-23
- [RoundCube Webmail Active Exploitation — CVE-2025-49113 Deserialization RCE (CVSS 9.9) + CVE-2025-68461 XSS…](https://intel.threadlinqs.com/threat/TL-2026-0130) — critical — 2026-02-22
- [SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub…](https://intel.threadlinqs.com/threat/TL-2026-0103) — critical — 2026-02-05

## Related CVEs

CVEs referenced by the tracked threats that use T1114.001, most frequent first.

- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-68461](https://intel.threadlinqs.com/cve/CVE-2025-68461)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-23760](https://intel.threadlinqs.com/cve/CVE-2026-23760)
- [CVE-2026-24423](https://intel.threadlinqs.com/cve/CVE-2026-24423)
- [CVE-2026-68490](https://intel.threadlinqs.com/cve/CVE-2026-68490)

## Detection coverage

Threadlinqs maintains 30 detection rules mapped to T1114.001 (SPL 8, KQL 12, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

30 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1114 Email Collection](https://intel.threadlinqs.com/technique/T1114) — 129 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1114.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
