Real-world descriptions of how a group, tool or campaign used a technique.
14 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.003 Spearphishing via Service |
GroupEXOTIC LILY | EXOTIC LILY has used the e-mail notification features of legitimate file sharing services for spearphishing. |
| T1566.003 Spearphishing via Service |
GroupFIN6 | FIN6 has used fake job advertisements sent via LinkedIn to spearphish targets. |
| T1566.003 Spearphishing via Service |
GroupStorm-1811 | Storm-1811 has used Microsoft Teams to send messages and initiate voice calls to victims posing as IT support personnel. |
| T1566.003 Spearphishing via Service |
GroupCURIUM | CURIUM has used social media to deliver malicious files to victims. |
| T1566.003 Spearphishing via Service |
GroupContagious Interview | Contagious Interview has used fake job advertisements and messages sent via social media to spearphish targets. Contagious Interview has also leveraged hiring websites to solicit victims. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Sekoia ClickFake 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1566.003 Spearphishing via Service |
GroupOilRig | OilRig has used LinkedIn to send spearphishing links. |
| T1566.003 Spearphishing via Service |
GroupAPT29 | APT29 has used the legitimate mailing service Constant Contact to send phishing e-mails. |
| T1566.003 Spearphishing via Service |
GroupDark Caracal | Dark Caracal spearphished victims via Facebook and Whatsapp. |
| T1566.003 Spearphishing via Service |
GroupWindshift | Windshift has used fake personas on social media to engage and target victims. |
| T1566.003 Spearphishing via Service |
GroupToddyCat | ToddyCat has sent loaders configured to run Ninja as zip archives via Telegram. |
| T1566.003 Spearphishing via Service |
GroupLazarus Group | Lazarus Group has used social media platforms, including LinkedIn and Twitter, to send spearphishing messages. |
| T1566.003 Spearphishing via Service |
GroupMoonstone Sleet | Moonstone Sleet has used social media services to spear phish victims to deliver trojainized software. |
| T1566.003 Spearphishing via Service |
GroupMagic Hound | Magic Hound used various social media channels (such as LinkedIn) as well as messaging services (such as WhatsApp) to spearphish victims. |
| T1566.003 Spearphishing via Service |
GroupAjax Security Team | Ajax Security Team has used various social media channels to spearphish victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.