Sub-technique of T1566 Phishing.View on attack.mitre.org
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this case, the malicious emails contain links. Generally, the links will be accompanied by social engineering text and require the user to actively click or copy and paste a URL into a browser, leveraging User Execution. The visited website may compromise the web browser using an exploit, or the user will be prompted to download applications, documents, zip files, or even executables depending on the pretext for the email in the first place.
Adversaries may also include links that are intended to interact directly with an email reader, including embedded images intended to exploit the end system directly. Additionally, adversaries may use seemingly benign links that abuse special characters to mimic legitimate websites (known as an "IDN homograph attack"). URLs may also be obfuscated by taking advantage of quirks in the URL schema, such as the acceptance of integer- or hexadecimal-based hostname formats and the automatic discarding of text before an “@” symbol: for example, `hxxp://google.com@1157586937`.
Adversaries may also utilize links to perform consent phishing/spearphishing campaigns to Steal Application Access Tokens that grant immediate access to the victim environment. For example, a user may be lured into granting adversaries permissions/access via a malicious OAuth 2.0 request URL that when accepted by the user provide permissions/access for malicious applications. These stolen access tokens allow the adversary to perform various actions on behalf of the user via API calls.
Similarly, malicious links may also target device-based authorization, such as OAuth 2.0 device authorization grant flow which is typically used to authenticate devices without UIs/browsers. Known as “device code phishing,” an adversary may send a link that directs the victim to a malicious authorization page where the user is tricked into entering a code/credentials that produces a device token.
Rules on DetectionCode tagged with T1566.002.
| Rule | Level | Log source |
|---|---|---|
| Potential Malicious Usage of CloudTrail System Manager | high | aws / NULL |
| Suspicious Email Delivered In Microsoft 365 | medium | m365 / NULL |
| Suspicious Execution via macOS Script Editor | medium | macos / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Azure AD Device Code Authentication | TTP | NULL | Azure Active Directory |
| O365 Email Reported By Admin Found Malicious | TTP | NULL | Office 365 Universal Audit Log |
| O365 Email Reported By User Found Malicious | TTP | NULL | Office 365 Universal Audit Log |
| O365 Threat Intelligence Suspicious Email Delivered | Anomaly | NULL | Office 365 Universal Audit Log |
| O365 ZAP Activity Detection | Anomaly | NULL | Office 365 Universal Audit Log |
| Process Creating LNK file in Suspicious Location | Anomaly | NULL | Sysmon EventID 11 |
| Windows Defender ASR Audit Events | Anomaly | NULL | Windows Event Log Defender 1122, Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 1132, Windows Event Log Defender 1134 |
| Windows Defender ASR Block Events | Anomaly | NULL | Windows Event Log Defender 1121, Windows Event Log Defender 1126, Windows Event Log Defender 1129, Windows Event Log Defender 1131, Windows Event Log Defender 1133 |
| Windows Defender ASR Rules Stacking | Hunting | NULL | Windows Event Log Defender 1121, Windows Event Log Defender 1122, Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 1129, Windows Event Log Defender 1131, Windows Event Log Defender 1133, Windows Event Log Defender 1134, Windows Event Log Defender 5007 |
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has sent emails containing a link that appear to lead to an urgent notification from a government institution, at times using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. |
| GroupAPT1 | APT1 has sent spearphishing emails containing hyperlinks to malicious files. |
| GroupAPT29 | APT29 has used spearphishing with a link to trick victims into clicking on a link to a zip file containing malicious files. |
| GroupAPT3 | APT3 has sent spearphishing emails containing malicious links. |
| GroupAPT32 | APT32 has sent spearphishing emails containing malicious links. |
| GroupAPT33 | APT33 has sent spearphishing emails containing links to .hta files. |
| GroupAPT39 | APT39 leveraged spearphishing emails with malicious links to initially compromise victims. |
| GroupAPT42 | APT42 has sent spearphishing emails containing malicious links. |
| Used by | Procedure example |
|---|---|
| ToolAADInternals | AADInternals can send "consent phishing" emails containing malicious links designed to steal users’ access tokens. |
| MalwareAppleJeus | AppleJeus has been distributed via spearphishing link. |
| MalwareBazar | Bazar has been spread via emails with embedded malicious links. |
| MalwareBumblebee | Bumblebee has been spread through e-mail campaigns with malicious links. |
| MalwareDarkGate | DarkGate is distributed in phishing emails containing links to distribute malicious VBS or MSI files. DarkGate uses applications such as Microsoft Teams for distributing links to payloads. |
| MalwareEmotet | Emotet has been delivered by phishing emails containing links. |
| MalwareGrandoreiro | Grandoreiro has been spread via malicious links embedded in e-mails. |
| MalwareGuLoader | GuLoader has been spread in phishing campaigns using malicious web links. |
| Used by | Procedure example |
|---|---|
| CampaignC0011 | During C0011, Transparent Tribe sent emails containing a malicious link to student targets in India. |
| CampaignC0021 | During C0021, the threat actors sent phishing emails with unique malicious links, likely for tracking victim clicks. |
| CampaignNight Dragon | During Night Dragon, threat actors sent spearphishing emails containing links to compromised websites where malware was downloaded. |
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace sent spearphishing emails with malicious OneDrive links. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email. |
| CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors sent spearphishing emails containing a malicious link. |
| CampaignOperation Spalax | During Operation Spalax, the threat actors sent phishing emails to victims that contained a malicious link. |
| CampaignPikabot Distribution February 2024 | Pikabot Distribution February 2024 utilized emails with hyperlinks leading to malicious ZIP archive files containing scripts to download and install Pikabot. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.