Phishing

T1566

Technique with 4 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms. Phishing may also involve social engineering techniques, such as posing as a trusted source, as well as evasive techniques such as removing or manipulating emails or metadata/headers from compromised accounts being abused to send messages (e.g., Email Hiding Rules). Another way to accomplish this is by Email Spoofing the identity of the sender, which can be used to fool both the human recipient as well as automated security tools, or by including the intended target as a party to an existing email thread that includes malicious files or links (i.e., "thread hijacking").

Victims may also receive phishing messages that instruct them to call a phone number where they are directed to visit a malicious URL, download malware, or install adversary-accessible remote management tools onto their computer (i.e., User Execution).

Detection rules99

Rules on DetectionCode tagged with T1566 or one of its sub-techniques.

Sigma26

RuleLevelLog sourceTechnique
HTML Help HH.EXE Suspicious Child Processhighwindows / process_creationT1566 T1566.001
ISO File Created Within Temp Foldershighwindows / file_eventT1566.001
Office Macro File Creation From Suspicious Processhighwindows / file_eventT1566.001
Okta FastPass Phishing Detectionhighokta / NULLT1566
Password Protected ZIP File Opened (Email Attachment)highwindows / NULLT1566.001
Phishing Pattern ISO in Archivehighwindows / process_creationT1566
Potential Malicious Usage of CloudTrail System Managerhighaws / NULLT1566 T1566.002
Suspicious Double Extension File Executionhighwindows / process_creationT1566.001
Suspicious Execution From Outlook Temporary Folderhighwindows / process_creationT1566.001
Suspicious External WebDAV ExecutionhighNULL / proxyT1566
Suspicious File Created in Outlook Temporary Directoryhighwindows / file_eventT1566.001
Suspicious HH.EXE Executionhighwindows / process_creationT1566 T1566.001
Suspicious HWP Sub Processeshighwindows / process_creationT1566.001
Suspicious Microsoft OneNote Child Processhighwindows / process_creationT1566 T1566.001
Arbitrary Shell Command Execution Via Settingcontent-Msmediumwindows / process_creationT1566.001

Splunk73

RuleTypeRiskData sourceTechnique
Azure AD Device Code AuthenticationTTPNULLAzure Active DirectoryT1566.002
Detect DNS requests to Phishing Sites leveraging EvilGinx2TTPNULLT1566.003
Detect Outlook exe writing a zip fileAnomalyNULLSysmon EventID 1 AND Sysmon EventID 11T1566.001
Email Attachments With Lots Of SpacesAnomalyNULLT1566.001
Gdrive suspicious file sharingHuntingNULLT1566
GSuite Email Suspicious AttachmentAnomalyNULLG Suite GmailT1566.001
Gsuite Email Suspicious Subject With AttachmentAnomalyNULLG Suite GmailT1566.001
Gsuite Email With Known Abuse Web Service LinkAnomalyNULLG Suite GmailT1566.001
Gsuite suspicious calendar inviteHuntingNULLT1566
Gsuite Suspicious Shared File NameAnomalyNULLG Suite DriveT1566.001
Linux Ghostscript ExploitationTTPNULLSysmon for Linux EventID 1T1566
MSHTML Module Load in Office ProductTTPNULLSysmon EventID 7T1566.001
O365 Email Reported By Admin Found MaliciousTTPNULLOffice 365 Universal Audit LogT1566.001 T1566.002
O365 Email Reported By User Found MaliciousTTPNULLOffice 365 Universal Audit LogT1566.001 T1566.002
O365 Safe Links DetectionTTPNULLOffice 365 Universal Audit LogT1566.001

Sub-techniques4

IDNameExamples
T1566.001Spearphishing Attachment149
T1566.002Spearphishing Link86
T1566.003Spearphishing via Service16
T1566.004Spearphishing Voice2

Groups8

Software3

Campaigns0

None recorded.

Procedure examples11

Groups8

Used byProcedure example
GroupAppleJeus

AppleJeus has used spearphishing emails to distribute malicious payloads.

GroupAxiom

Axiom has used spear phishing to initially compromise victims.

GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has conducted malicious spam (malspam) campaigns to gain access to victim's machines.

GroupINC Ransom

INC Ransom has used phishing to gain initial access.

GroupKimsuky

Kimsuky has used spearphishing to gain initial access and intelligence.

GroupMuddyWater

MuddyWater has sent phishing emails to targets from the email address support@microsoftonlines[.]com.

GroupSea Turtle

Sea Turtle used spear phishing to gain initial access to victims.

GroupVOID MANTICORE

VOID MANTICORE has emailed victims threatening messages. VOID MANTICORE has used phishing as an initial access vector.

Software3

Used byProcedure example
MalwareHikit

Hikit has been spread through spear phishing.

MalwareINC Ransomware

INC Ransomware campaigns have used spearphishing emails for initial access.

MalwareRoyal

Royal has been spread through the use of phishing campaigns including "call back phishing" where victims are lured into calling a number provided through email.

References8

  1. CISA Remote Monitoring and Management Software Open source
    CISA. (n.d.). Protecting Against Malicious Use of Remote Monitoring and Management Software. Retrieved February 2, 2023.
  2. Microsoft OAuth Spam 2022 Open source
    Microsoft. (2023, September 22). Malicious OAuth applications abuse cloud email services to spread spam. Retrieved March 13, 2023.
  3. Palo Alto Unit 42 VBA Infostealer 2014 Open source
    Vicky Ray and Rob Downs. (2014, October 29). Examining a VBA-Initiated Infostealer Campaign. Retrieved March 13, 2023.
  4. Proofpoint-spoof Open source
    Proofpoint. (n.d.). What Is Email Spoofing?. Retrieved February 24, 2023.
  5. Unit42 Luna Moth Open source
    Kristopher Russo. (n.d.). Luna Moth Callback Phishing Campaign. Retrieved February 2, 2023.
  6. cyberproof-double-bounce Open source
    Itkin, Liora. (2022, September 1). Double-bounced attacks with email spoofing . Retrieved February 24, 2023.
  7. phishing-krebs Open source
    Brian Krebs. (2024, March 28). Thread Hijacking: Phishes That Prey on Your Curiosity. Retrieved September 27, 2024.
  8. sygnia Luna Month Open source
    Oren Biderman, Tomer Lahiyani, Noam Lifshitz, Ori Porag. (n.d.). LUNA MOTH: THE THREAT ACTORS BEHIND RECENT FALSE SUBSCRIPTION SCAMS. Retrieved February 2, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.