Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1598.003 Spearphishing Link |
GroupKimsuky | Kimsuky has used links in e-mail to steal account information including web beacons for target profiling. Kimsuky has also utilized QR codes (also known as Quishing) to direct victims to malicious links through the reliance of a mobile device to scan a code with an embedded malicious URL. |
| T1598.003 Spearphishing Link |
GroupPatchwork | Patchwork has used embedded image tags (known as web bugs) with unique, per-recipient tracking links in their emails for the purpose of identifying which recipients opened messages. |
| T1598.003 Spearphishing Link |
GroupDragonfly | Dragonfly has used spearphishing with PDF attachments containing malicious links that redirected to credential harvesting websites. |
| T1598.003 Spearphishing Link |
GroupAPT32 | APT32 has used malicious links to direct users to web pages designed to harvest credentials. |
| T1598.003 Spearphishing Link |
GroupSandworm Team | Sandworm Team has crafted spearphishing emails with hyperlinks designed to trick unwitting recipients into revealing their account credentials. |
| T1598.003 Spearphishing Link |
GroupCURIUM | CURIUM used malicious links to adversary-controlled resources for credential harvesting. |
| T1598.003 Spearphishing Link |
GroupSidewinder | Sidewinder has sent e-mails with malicious links to credential harvesting websites. |
| T1598.003 Spearphishing Link |
GroupMustang Panda | Mustang Panda has delivered web bugs to profile their intended targets. |
| T1598.003 Spearphishing Link |
GroupZIRCONIUM | ZIRCONIUM has used web beacons in e-mails to track hits to attacker-controlled URL's. |
| T1598.003 Spearphishing Link |
GroupScattered Spider | Scattered Spider has used domains mirroring corporate login portals to socially engineer victims into providing credentials. |
| T1598.003 Spearphishing Link |
GroupSilent Librarian | Silent Librarian has used links in e-mails to direct victims to credential harvesting websites designed to appear like the targeted organization's login page. |
| T1598.003 Spearphishing Link |
GroupStar Blizzard | Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites. |
| T1598.003 Spearphishing Link |
GroupAPT28 | APT28 has conducted credential phishing campaigns with links that redirect to credential harvesting sites. |
| T1598.003 Spearphishing Link |
GroupMoonstone Sleet | Moonstone Sleet used spearphishing messages containing items such as tracking pixels to determine if users interacted with malicious messages. |
| T1598.003 Spearphishing Link |
GroupMagic Hound | Magic Hound has used SMS and email messages with links designed to steal credentials or track victims. |
| T1598.003 Spearphishing Link |
GroupShinyHunters | ShinyHunters has used spearphishing emails with malicious links to gain initial access and credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.