Cloud Security Office Hours Banner

Mitnick / Novell 1994

Step-by-step kill chain mapped to MITRE ATT&CK Cloud, sourced from official post-mortems and primary technical analyses.

1993-1995 (fugitive period) Critical On-Premises / Dial-Up

Kevin Mitnick / Novell - War Dialing → Pretexting → The Voicemail Trap That Named the Hacker → The Watched Honeypot

Kevin Mitnick was already a fugitive - the FBI's most wanted hacker, living under a false identity in Denver - when he turned to Novell, one target on a long list he worked for proprietary source code. Novell knew early: he war-dialed the entire San Jose campus hunting for modems, phones ringing desk after desk, which told the network team someone was seriously trying to get in. His pretext calls mapped the humans rather than the systems - along the way he learned that network administrator Shawn Nunley controlled the modems, hijacked employee Gabe Nault's voicemail and planted an out-of-office greeting in his own voice to survive verification, and found Nunley's home phone number. The late-night call asking for policy-breaking inbound modem access was the tell; Nunley played along, asked him to leave a voicemail, and taped it - the first and only direct evidence naming the hacker, and the lynchpin of the federal case. Then Novell turned the tables entirely: it granted the requested access on 1-800-37-TCPIP, a number that existed for no purpose but to capture his caller ID, and routed him through a terminal server where every keystroke was watched live and every session recorded. Mitnick spotted the caller-ID trap and dialed around it - but never knew he was in a fishbowl. Novell kept him off the ATM system that held all NetWare source, and all he ever downloaded was inconsequential code.

Every keystroke watched live through the honeypot terminal server
2.5 years as fugitive targeting multiple companies
25 counts in federal indictment
1 cassette tape - the first direct evidence naming Mitnick
Threat actor: Kevin Mitnick ("Condor"), FBI's Most Wanted
📄 Wired - Mitnick Meets His Pigeon (Shawn Nunley) ↗ 📄 Federal indictment details ↗ 📄 Malicious Life - Mitnick Part 2 ↗
ℹ️ Shawn Nunley (CSOH founder) was the Novell network administrator who set the voicemail trap in this chain. For the full story - including how the government's primary witness became one of Mitnick's closest friends - read the Kevin Mitnick - In Memoriam tribute on this site.
🔍 Reconnaissance - Open Source Intelligence
01
Mitnick researches Novell's internal org structure, employee names, and technical lingo
T1591 - Gather Victim Org Information T1589 - Gather Victim Identity Info

Novell was one stop on a long target list - the federal indictment also names Motorola, Nokia, Fujitsu, Sun Microsystems, and NEC - and the tradecraft was the same everywhere. Before making a single call, Mitnick invested significant time learning everything publicly available about his target. He gathered employee names from directory listings, understood Novell's internal team structures, learned real internal project names, and immersed himself in NetWare technical documentation so he could speak fluently about the product - a prerequisite for any convincing pretext. As he wrote in The Art of Deception: "When you know the lingo and terminology, it establishes credibility - you're legit, a coworker slogging in the trenches just like your targets."

Sources used: Phone directories, technical manuals, product documentation, prior calls to gather names
Goal: Build enough authentic detail to withstand scrutiny from a real Novell employee
Mitnick's method: "Pretext calls" - low-stakes calls to gather information for higher-stakes calls later
OSINTPretexting PrepT1591Phone Phreaking
☎️ First Contact at Scale - War Dialing the Campus
02
Mitnick war-dials the entire San Jose campus - and tips Novell off
T1595 - Active Scanning

Already a fugitive, Mitnick opened the campaign the old-fashioned way: war dialing - sweeping Novell's San Jose campus phone ranges number by number, hunting for a modem that would answer. Desk phones rang sequentially through the building, one after another, for anyone paying attention to hear. Novell's network team was paying attention. Before Mitnick ever got anything, the defenders knew somebody was seriously trying to get in - they just didn't know who. In this chain, detection precedes access.

Technique: War dialing - automated sequential calls across the campus phone ranges, listening for modem carriers
The giveaway: Phones ringing desk after desk in sequence - a scan you can hear
Defender state: Persistent threat confirmed, identity unknown - the hunt for the hacker starts here
War DialingPhone PhreakingModem HuntingTip-OffT1595
🎭 Pretexting and Elicitation - Mapping the Humans
03
Pretext calls map the org - and identify the man who controls the modems
T1589 - Gather Victim Identity Info T1598 - Phishing for Information

Mitnick worked Novell by phone, presenting himself as a legitimate employee or developer with a plausible reason for calling - real names, correct internal terminology, manufactured urgency, a different pretext for each target. His genius was psychological: he assessed each target's willingness to cooperate in the first few seconds and adapted in real time. What the calls harvested was not credentials but intelligence. Somewhere in those conversations he learned who Shawn Nunley was - and that Nunley controlled the modems and all inbound access. Around the same time he broke into the real Gabe Nault's voicemail and recorded an out-of-office greeting in his own voice, pre-poisoning the verification channel for the pretext to come. Eventually, he found Nunley's home phone number.

Psychological levers: Authority (internal employee), urgency (time pressure), likeability (charm), reciprocity (a reasonable favour)
Mitnick on reading targets: "I'm always on the watch for signs that give me a read on how cooperative a person is"
Intelligence gained: Who controls inbound modem access (Shawn Nunley) + his home phone number
Pre-positioned bypass: Hijacked Gabe Nault's voicemail, planted a Vail out-of-office greeting in his own voice
PretextingElicitationVoicemail HijackVerification BypassT1589T1598
🪤 The Turn - A Defender Sets a Trap
04
Mitnick calls Novell's network administrator at home - and the request itself is the tell
T1566.004 - Phishing: Voice T1684.001 - Social Engineering: Impersonation

Armed with what the elicitation calls had taught him, Mitnick went straight for the gatekeeper. Late one night, Shawn Nunley - the network administrator responsible for all of Novell's inbound connectivity - got a call at home from "Gabe Nault", a real Novell employee. The pretext was immaculate: the caller name-dropped Snowbird, a real internal top-secret project; he was on vacation in Vail and needed to make emergency code changes that could not wait; and the vacation story checked out, because the greeting on the real Gabe Nault's voicemail - the one Mitnick had planted there himself - backed it word for word. What he wanted was direct inbound modem access. That request was the tell. Modem access at Novell ran through a secure dial-back system keyed to known phone numbers, plus manager approval - and Nunley owned that system. No genuine employee needed what this caller was asking for. Rather than confront him and burn the contact, Nunley played it cool: he could not grant the access from home anyway, so it would have to wait until morning - "but in case I forget, please leave me a voicemail."

The pretext: Real employee name (Gabe Nault) + real project (Snowbird) + a vacation story he could "prove"
The pre-positioned bypass: Mitnick had hijacked the real employee's voicemail and planted the out-of-office greeting in his own voice, so call-back verification would confirm the imposter
The tell: The request itself - direct inbound dial access violated the dial-back policy and its approval workflow
The counter: Don't tip off the attacker - stall politely and convert the contact into a recorded artifact
Pretext RecognizedVerification BypassPolicy KnowledgeDial-Back ControlDefender's Trap
📼 Evidence Capture - The Tape
05
The voicemail is recorded to cassette - the first direct evidence naming the hacker

The voicemail was waiting the next morning, and Nunley immediately recorded it onto a cassette for safekeeping. Its significance is hard to overstate. Across years of intrusions at company after company, investigators had collected no physical evidence directly tying the crimes to Kevin Mitnick himself. A voice on tape, soliciting policy-breaking access to Novell's network, was the first and only direct evidence that the hacker was, in fact, Mitnick. As Nunley later put it: "You can't cross-examine a keystroke." That recording became the primary evidence in the federal case - the lynchpin that turned suspicion into a prosecutable identity. There is a fitting symmetry in it: Mitnick had weaponized a voicemail box to sell the pretext, and a voicemail box is what finally named him.

What the tape proved: The intruder's identity - the one element no log or keystroke capture could establish
Evidence before the tape: No physical evidence tying Mitnick to a major crime
Role in the case: Primary evidence in the federal prosecution; Nunley became the primary witness
Voicemail TrapCassette TapeDirect EvidenceAttribution
🍯 The Counter-Offensive - A Honeypot Named 1-800-37-TCPIP
06
Novell grants the access - on a number that exists only to identify him

With the tape in hand, Novell did the counterintuitive thing: it gave "Gabe Nault" exactly what he had asked for. The dial-in came up on 1-800-37-TCPIP, a number provisioned for no purpose other than to see who called it - toll-free billing delivers the caller's number (ANI) to the account paying for the call, so every inbound call would unmask him. Mitnick knew the phone system too well for that. He recognized what an 800 number would give away, dug through the phone system to find the DID number the 800 line translated to, and dialed that directly instead, sidestepping the caller-ID capture. What he could not sidestep was where the line landed.

The lure: 1-800-37-TCPIP - a dedicated dial-in provisioned solely for this one intruder
The mechanism: Toll-free ANI delivery - the callee sees the caller's number
The evasion: Mitnick located the underlying DID number and dialed it directly, bypassing the ANI capture
His side: Dialing in at night from Denver, living as "Eric Weiss", cloned cell phones his standard practice for hiding location
HoneypotANI CaptureDID BypassPhone PhreakingControlled Access
👁 Full-Take Monitoring - The Fishbowl
07
Every keystroke watched live - terminal server in front, NutCracker recording behind

The DID trick bought Mitnick nothing that mattered, because the line terminated on a terminal server Novell controlled. The network team watched every keystroke of every session in real time, and an early version of NutCracker, hooked to the ethernet side of the terminal server, captured and recorded the sessions. The defenders did not just observe - they played with him: interrupting sessions when he got close to systems that mattered, or simply when they got bored. The most wanted hacker in America believed he was inside Novell. He was inside an instrumented box Novell had built for him.

The choke point: All sessions terminated on a Novell-controlled terminal server
Live monitoring: Real-time keystroke visibility for the network team
Session recording: An early version of NutCracker on the ethernet side, capturing full sessions
Active control: Sessions interrupted at will - especially near sensitive systems
Keystroke MonitoringSession RecordingTerminal ServerHoneypot Ops
🚫 Containment - The ATM Source Vault Stays Shut
08
Mitnick finds the source-code system - and Novell keeps him out of it

Watching his sessions, the team could see what Mitnick was learning as he learned it. He discovered the existence of ATM, the internal system where Novell stored all of its source code - the real prize. Because the defenders could see him coming, he never reached it: sessions that headed toward ATM got cut. Over the course of the operation he did manage to download some source code, but only inconsequential material. The federal indictment would later charge him with copying proprietary Novell software, and that is true as far as it goes. What it does not say is that everything he took from Novell, he took on camera, out of the shallow end of the pool.

The prize: ATM - the internal repository holding all NetWare source code
The block: Sessions cut whenever he closed in on it - he never reached ATM
Actual take: Inconsequential source code, downloaded under full surveillance
Legal record: The 25-count indictment includes copying proprietary Novell software
ContainmentSource CodeDamage LimitedUnder Surveillance
🚨 Capture and Aftermath
09
Arrest in Raleigh - the primary witness turns due-process dissenter, then lifelong friend

Mitnick stayed loose for some time after the tape - dialing into Novell's fishbowl while the wider pursuit continued, until Tsutomu Shimomura helped track him to Raleigh, North Carolina, a chase that is its own famous story - but when the FBI finally had him, the Novell tape anchored the case, and Nunley worked with the prosecution as its primary witness for five years. He grew increasingly troubled that Mitnick was held without a bail hearing and without access to the evidence against him; when a senior prosecutor told him on the record that the point was "sending a message to other would-be hackers", Nunley parted ways with the DOJ and contacted Mitnick's defence team. Mitnick was released on a plea deal - and the man who trapped him became one of his closest friends for the rest of his life. It's one of the most extraordinary adversary-to-friend trajectories in the history of computer crime.

Arrest: February 15, 1995 - Raleigh, North Carolina apartment
Found with: Cloned cellular phones, 100+ cloned phone codes, multiple pieces of false identification
Sentence: 46 months + 22 months for supervised release violation (5 years total, including 8 months solitary)
Shawn Nunley: Set the trap → primary witness → challenged the DOJ over due process → lifelong friend of Mitnick
FBI Arrest 1995Primary WitnessDue ProcessCloned Phones

🛡 How to Defend Against This Chain

A defender who spots a pretext can end an entire campaign - if they don't tip off the attacker. The only direct evidence that ever named Mitnick existed because one admin recognized a policy-breaking request, stayed friendly, and steered the attacker into leaving a recorded artifact. Teach staff the play: don't confront, don't comply - stall politely, capture everything, and escalate to security while the pretext is still warm.
When you know the attacker is coming, choose the terrain: grant access you fully instrument. Novell gave "Gabe Nault" his dial-up - on a number that existed only to identify him, into a terminal server that showed every keystroke live, with sessions recorded off the ethernet side and operators ready to cut any session that got close to something real. The attacker spent his effort where the defenders could see everything and he could reach nothing. Honeypots, canary tokens, and instrumented jump hosts are the modern versions of the same play.
Implement a call-back verification procedure for any credential or access request by phone. Never provide passwords, dial-up numbers, or system access to an inbound caller - regardless of how convincing they sound. Hang up and call back on a number you independently verify from your internal directory - and make sure verification reaches a live human, not a mailbox. Mitnick anticipated call-back checks and planted his "proof" in advance: a hijacked voicemail greeting, in his own voice, on the very number a verifier would dial.
Train support staff to recognise the three pressure levers: authority, urgency, and likeability. Mitnick used all three in every call. When someone is very charming, very knowledgeable, and very urgent all at once - that combination itself is a red flag. Slow down, verify, never let urgency override procedure.
Restrict what information support staff can provide and to whom. Credentials, dial-up numbers, and system access details should never be distributed by phone without a formal verification workflow. The support desk should have a written procedure and authority to refuse without penalty.
Monitor dial-up and remote access connections for unusual times or locations. Mitnick connected at night from Denver. Anomalous remote access - unusual hours, unknown caller ID, high volume of data transferred - should trigger a review.
Security awareness training is not optional - it is the primary control against social engineering. The trap in this chain worked because the defender knew the access policy cold: the moment a request violated the dial-back procedure, the pretext collapsed no matter how good the backstory was. Regular training that pairs realistic scenarios with clear policy - not just policy documents - is the difference between a staff member who pauses and verifies and one who helps an attacker.
This attack still works today. Vishing (voice phishing) remains one of the top two attack vectors today. The tools have changed - attackers now use AI voice cloning, LinkedIn for OSINT, and SMS as a follow-up - but the psychology is identical to what Mitnick did in 1994. The defence is also identical: verify independently, never let urgency override process.

Related defense topics