Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.002 Spearphishing Link |
GroupMustard Tempest | Mustard Tempest has sent victims emails containing links to compromised websites. |
| T1566.002 Spearphishing Link |
GroupKimsuky | Kimsuky has sent spearphishing emails containing a link to a document that contained malicious macros or took the victim to an actor-controlled domain. |
| T1566.002 Spearphishing Link |
GroupEXOTIC LILY | EXOTIC LILY has relied on victims to open malicious links in e-mails for execution. |
| T1566.002 Spearphishing Link |
GroupTA577 | TA577 has sent emails containing links to malicious JavaScript files. |
| T1566.002 Spearphishing Link |
GroupPatchwork | Patchwork has used spearphishing with links to deliver files with exploits to initial victims. |
| T1566.002 Spearphishing Link |
GroupEvilnum | Evilnum has sent spearphishing emails containing a link to a zip file hosted on Google Drive. |
| T1566.002 Spearphishing Link |
GroupAPT32 | APT32 has sent spearphishing emails containing malicious links. |
| T1566.002 Spearphishing Link |
GroupMuddyWater | MuddyWater has sent targeted spearphishing e-mails with malicious links. |
| T1566.002 Spearphishing Link |
GroupStorm-1811 | Storm-1811 has distributed malicious links to victims that redirect to EvilProxy-based phishing sites to harvest credentials. |
| T1566.002 Spearphishing Link |
GroupFIN7 | FIN7 has conducted broad phishing campaigns using malicious links. Additionally, FIN7 has sent spearphishing emails containing a typosquatted link to “ip-sccanner[.]com.” |
| T1566.002 Spearphishing Link |
GroupSandworm Team | Sandworm Team has crafted phishing emails containing malicious hyperlinks. |
| T1566.002 Spearphishing Link |
GroupMachete | Machete has sent phishing emails that contain a link to an external server with ZIP and RAR archives. |
| T1566.002 Spearphishing Link |
GroupSidewinder | Sidewinder has sent e-mails with malicious links often crafted for specific targets. |
| T1566.002 Spearphishing Link |
GroupMustang Panda | Mustang Panda has delivered malicious links to their intended targets. Mustang Panda has distributed spear-phishing emails with embedded links that direct the victim to a malicious archive hosted on Google or Dropbox. |
| T1566.002 Spearphishing Link |
GroupZIRCONIUM | ZIRCONIUM has used malicious links in e-mails to deliver malware. |
| T1566.002 Spearphishing Link |
GroupAPT39 | APT39 leveraged spearphishing emails with malicious links to initially compromise victims. |
| T1566.002 Spearphishing Link |
GroupTA2541 | TA2541 has used spearphishing e-mails with malicious links to deliver malware. |
| T1566.002 Spearphishing Link |
GroupOilRig | OilRig has sent spearphising emails with malicious links to potential victims. |
| T1566.002 Spearphishing Link |
GroupAPT1 | APT1 has sent spearphishing emails containing hyperlinks to malicious files. |
| T1566.002 Spearphishing Link |
GroupConfucius | Confucius has sent malicious links to victims through email campaigns. |
| T1566.002 Spearphishing Link |
GroupBlackTech | BlackTech has used spearphishing e-mails with links to cloud services to deliver malware. |
| T1566.002 Spearphishing Link |
GroupLeviathan | Leviathan has sent spearphishing emails with links, often using a fraudulent lookalike domain and stolen branding. |
| T1566.002 Spearphishing Link |
GroupTurla | Turla attempted to trick targets into clicking on a link featuring a seemingly legitimate domain from Adobe.com to download their malware and gain initial access. |
| T1566.002 Spearphishing Link |
GroupTA505 | TA505 has sent spearphishing emails containing malicious links. |
| T1566.002 Spearphishing Link |
GroupRedCurl | RedCurl has used phishing emails with malicious links to gain initial access. |
| T1566.002 Spearphishing Link |
GroupMofang | Mofang delivered spearphishing emails with malicious links included. |
| T1566.002 Spearphishing Link |
GroupAPT29 | APT29 has used spearphishing with a link to trick victims into clicking on a link to a zip file containing malicious files. |
| T1566.002 Spearphishing Link |
GroupMirrorFace | MirrorFace has embedded OneDrive URLs in emails leading to malicious file installation. |
| T1566.002 Spearphishing Link |
GroupLazyScripter | LazyScripter has used spam emails that contain a link that redirects the victim to download a malicious document. |
| T1566.002 Spearphishing Link |
GroupWindshift | Windshift has sent spearphishing emails with links to harvest credentials and deliver malware. |
| T1566.002 Spearphishing Link |
GroupLuminousMoth | LuminousMoth has sent spearphishing emails containing a malicious Dropbox download link. |
| T1566.002 Spearphishing Link |
GroupAPT42 | APT42 has sent spearphishing emails containing malicious links. |
| T1566.002 Spearphishing Link |
GroupAPT-C-36 | APT-C-36 has sent emails containing a link that appear to lead to an urgent notification from a government institution, at times using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. |
| T1566.002 Spearphishing Link |
GroupLazarus Group | Lazarus Group has sent malicious links to victims via email. |
| T1566.002 Spearphishing Link |
GroupEarth Lusca | Earth Lusca has sent spearphishing emails to potential targets that contained a malicious link. |
| T1566.002 Spearphishing Link |
GroupFIN4 | FIN4 has used spearphishing emails (often sent from compromised accounts) containing malicious links. |
| T1566.002 Spearphishing Link |
GroupCobalt Group | Cobalt Group has sent emails with URLs pointing to malicious documents. |
| T1566.002 Spearphishing Link |
GroupWizard Spider | Wizard Spider has sent phishing emails containing a link to an actor-controlled Google Drive document or other free online file hosting services. |
| T1566.002 Spearphishing Link |
GroupMolerats | Molerats has sent phishing emails with malicious links included. |
| T1566.002 Spearphishing Link |
GroupTransparent Tribe | Transparent Tribe has embedded links to malicious downloads in e-mails. |
| T1566.002 Spearphishing Link |
GroupWIRTE | WIRTE has sent targeted spearphishing emails with malicious links directing victims to malware downloads. |
| T1566.002 Spearphishing Link |
GroupMagic Hound | Magic Hound has sent malicious URL links through email to victims. In some cases the URLs were shortened or linked to Word documents with malicious macros that executed PowerShells scripts to download Pupy. |
| T1566.002 Spearphishing Link |
GroupAPT33 | APT33 has sent spearphishing emails containing links to .hta files. |
| T1566.002 Spearphishing Link |
GroupFIN8 | FIN8 has distributed targeted emails containing links to malicious documents with embedded macros. |
| T1566.003 Spearphishing via Service |
GroupEXOTIC LILY | EXOTIC LILY has used the e-mail notification features of legitimate file sharing services for spearphishing. |
| T1566.003 Spearphishing via Service |
GroupFIN6 | FIN6 has used fake job advertisements sent via LinkedIn to spearphish targets. |
| T1566.003 Spearphishing via Service |
GroupStorm-1811 | Storm-1811 has used Microsoft Teams to send messages and initiate voice calls to victims posing as IT support personnel. |
| T1566.003 Spearphishing via Service |
GroupCURIUM | CURIUM has used social media to deliver malicious files to victims. |
| T1566.003 Spearphishing via Service |
GroupContagious Interview | Contagious Interview has used fake job advertisements and messages sent via social media to spearphish targets. Contagious Interview has also leveraged hiring websites to solicit victims. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Sekoia ClickFake 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1566.003 Spearphishing via Service |
GroupOilRig | OilRig has used LinkedIn to send spearphishing links. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.