Spearphishing Link

T1566.002

Sub-technique of T1566 Phishing.View on attack.mitre.org

About this technique

Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this case, the malicious emails contain links. Generally, the links will be accompanied by social engineering text and require the user to actively click or copy and paste a URL into a browser, leveraging User Execution. The visited website may compromise the web browser using an exploit, or the user will be prompted to download applications, documents, zip files, or even executables depending on the pretext for the email in the first place.

Adversaries may also include links that are intended to interact directly with an email reader, including embedded images intended to exploit the end system directly. Additionally, adversaries may use seemingly benign links that abuse special characters to mimic legitimate websites (known as an "IDN homograph attack"). URLs may also be obfuscated by taking advantage of quirks in the URL schema, such as the acceptance of integer- or hexadecimal-based hostname formats and the automatic discarding of text before an “@” symbol: for example, `hxxp://google.com@1157586937`.

Adversaries may also utilize links to perform consent phishing/spearphishing campaigns to Steal Application Access Tokens that grant immediate access to the victim environment. For example, a user may be lured into granting adversaries permissions/access via a malicious OAuth 2.0 request URL that when accepted by the user provide permissions/access for malicious applications. These stolen access tokens allow the adversary to perform various actions on behalf of the user via API calls.

Similarly, malicious links may also target device-based authorization, such as OAuth 2.0 device authorization grant flow which is typically used to authenticate devices without UIs/browsers. Known as “device code phishing,” an adversary may send a link that directs the victim to a malicious authorization page where the user is tricked into entering a code/credentials that produces a device token.

Detection rules12

Rules on DetectionCode tagged with T1566.002.

Sigma3

Splunk9

RuleTypeRiskData source
Azure AD Device Code AuthenticationTTPNULLAzure Active Directory
O365 Email Reported By Admin Found MaliciousTTPNULLOffice 365 Universal Audit Log
O365 Email Reported By User Found MaliciousTTPNULLOffice 365 Universal Audit Log
O365 Threat Intelligence Suspicious Email DeliveredAnomalyNULLOffice 365 Universal Audit Log
O365 ZAP Activity DetectionAnomalyNULLOffice 365 Universal Audit Log
Process Creating LNK file in Suspicious LocationAnomalyNULLSysmon EventID 11
Windows Defender ASR Audit EventsAnomalyNULLWindows Event Log Defender 1122, Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 1132, Windows Event Log Defender 1134
Windows Defender ASR Block EventsAnomalyNULLWindows Event Log Defender 1121, Windows Event Log Defender 1126, Windows Event Log Defender 1129, Windows Event Log Defender 1131, Windows Event Log Defender 1133
Windows Defender ASR Rules StackingHuntingNULLWindows Event Log Defender 1121, Windows Event Log Defender 1122, Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 1129, Windows Event Log Defender 1131, Windows Event Log Defender 1133, Windows Event Log Defender 1134, Windows Event Log Defender 5007

Groups46

Show 22 more

Software31

Show 7 more

Campaigns9

Procedure examples86

Groups46

Used byProcedure example
GroupAPT-C-36

APT-C-36 has sent emails containing a link that appear to lead to an urgent notification from a government institution, at times using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to.

GroupAPT1

APT1 has sent spearphishing emails containing hyperlinks to malicious files.

GroupAPT29

APT29 has used spearphishing with a link to trick victims into clicking on a link to a zip file containing malicious files.

GroupAPT3

APT3 has sent spearphishing emails containing malicious links.

GroupAPT32

APT32 has sent spearphishing emails containing malicious links.

GroupAPT33

APT33 has sent spearphishing emails containing links to .hta files.

GroupAPT39

APT39 leveraged spearphishing emails with malicious links to initially compromise victims.

GroupAPT42

APT42 has sent spearphishing emails containing malicious links.

View all 46 groups examples

Software31

Used byProcedure example
ToolAADInternals

AADInternals can send "consent phishing" emails containing malicious links designed to steal users’ access tokens.

MalwareAppleJeus

AppleJeus has been distributed via spearphishing link.

MalwareBazar

Bazar has been spread via emails with embedded malicious links.

MalwareBumblebee

Bumblebee has been spread through e-mail campaigns with malicious links.

MalwareDarkGate

DarkGate is distributed in phishing emails containing links to distribute malicious VBS or MSI files. DarkGate uses applications such as Microsoft Teams for distributing links to payloads.

MalwareEmotet

Emotet has been delivered by phishing emails containing links.

MalwareGrandoreiro

Grandoreiro has been spread via malicious links embedded in e-mails.

MalwareGuLoader

GuLoader has been spread in phishing campaigns using malicious web links.

View all 31 software examples

Campaigns9

Used byProcedure example
CampaignC0011

During C0011, Transparent Tribe sent emails containing a malicious link to student targets in India.

CampaignC0021

During C0021, the threat actors sent phishing emails with unique malicious links, likely for tracking victim clicks.

CampaignNight Dragon

During Night Dragon, threat actors sent spearphishing emails containing links to compromised websites where malware was downloaded.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace sent spearphishing emails with malicious OneDrive links.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email.

CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors sent spearphishing emails containing a malicious link.

CampaignOperation Spalax

During Operation Spalax, the threat actors sent phishing emails to victims that contained a malicious link.

CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized emails with hyperlinks leading to malicious ZIP archive files containing scripts to download and install Pikabot.

View all 9 campaigns examples

References7

  1. CISA IDN ST05-016 Open source
    CISA. (2019, September 27). Security Tip (ST05-016): Understanding Internationalized Domain Names. Retrieved October 20, 2020.
  2. Mandiant URL Obfuscation 2023 Open source
    Nick Simonian. (2023, May 22). Don't @ Me: URL Obfuscation Through Schema Abuse. Retrieved August 4, 2023.
  3. Microsoft OAuth 2.0 Consent Phishing 2021 Open source
    Microsoft 365 Defender Threat Intelligence Team. (2021, June 14). Microsoft delivers comprehensive solution to battle rise in consent phishing emails. Retrieved December 13, 2021.
  4. Netskope Device Code Phishing 2021 Open source
    Jenko Hwong. (2021, August 10). New Phishing Attacks Exploiting OAuth Authorization Flows (Part 1). Retrieved March 19, 2024.
  5. Optiv Device Code Phishing 2021 Open source
    Optiv. (2021, August 17). Microsoft 365 OAuth Device Code Flow and Phishing. Retrieved March 19, 2024.
  6. SecureWorks Device Code Phishing 2021 Open source
    SecureWorks Counter Threat Unit Research Team. (2021, June 3). OAuth’S Device Code Flow Abused in Phishing Attacks. Retrieved March 19, 2024.
  7. Trend Micro Pawn Storm OAuth 2017 Open source
    Hacquebord, F.. (2017, April 25). Pawn Storm Abuses Open Authentication in Advanced Social Engineering Attacks. Retrieved October 4, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.