{ "type": "bundle", "id": "bundle--ab462d82-debd-4eb6-8a39-4df992e034e2", "objects": [ { "type": "attack-pattern", "spec_version": "2.1", "id": "attack-pattern--e6a5397a-9515-4ba6-80e5-8f1fe273b7a5", "created_by_ref": "identity--f1a0f560-2d9e-4c5d-bf47-7e96e805de82", "created": "2024-11-22T16:43:58.221781Z", "modified": "2024-11-22T16:43:58.221781Z", "name": "Copy Account Imagery", "description": "Account imagery copied from an existing account.

Analysts may use reverse image search tools to try to identify previous uses of account imagery (e.g. a profile picture) by other accounts.

Threat Actors have been known to copy existing accounts\u2019 imagery to impersonate said accounts, or to provide imagery for unrelated accounts which aren\u2019t intended to impersonate the original assets\u2019 owner.

Associated Techniques and Sub-techniques
T0143.003: Impersonated Persona: Actors may copy existing accounts\u2019 imagery in an attempt to impersonate them.
T0143.004: Parody Persona: Actors may copy existing accounts\u2019 imagery as part of a parody of that account.", "kill_chain_phases": [ { "kill_chain_name": "mitre-attack", "phase_name": "establish-assets" } ], "external_references": [ { "source_name": "mitre-attack", "url": "https://github.com/DISARMFoundation/DISARMframeworks/blob/main/generated_pages/techniques/T0145.001.md", "external_id": "T0145.001" } ], "object_marking_refs": [ "marking-definition--f79f25d2-8b96-4580-b169-eb7b613a7c31" ], "x_mitre_is_subtechnique": true, "x_mitre_platforms": [ "Windows", "Linux", "Mac" ], "x_mitre_version": "2.1" } ] }