Technique with 4 sub-techniques.View on attack.mitre.org
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms. Phishing may also involve social engineering techniques, such as posing as a trusted source, as well as evasive techniques such as removing or manipulating emails or metadata/headers from compromised accounts being abused to send messages (e.g., Email Hiding Rules). Another way to accomplish this is by Email Spoofing the identity of the sender, which can be used to fool both the human recipient as well as automated security tools, or by including the intended target as a party to an existing email thread that includes malicious files or links (i.e., "thread hijacking").
Victims may also receive phishing messages that instruct them to call a phone number where they are directed to visit a malicious URL, download malware, or install adversary-accessible remote management tools onto their computer (i.e., User Execution).
Rules on DetectionCode tagged with T1566 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Azure AD Device Code Authentication | TTP | NULL | Azure Active Directory | T1566.002 |
| Detect DNS requests to Phishing Sites leveraging EvilGinx2 | TTP | NULL | T1566.003 | |
| Detect Outlook exe writing a zip file | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 11 | T1566.001 |
| Email Attachments With Lots Of Spaces | Anomaly | NULL | T1566.001 | |
| Gdrive suspicious file sharing | Hunting | NULL | T1566 | |
| GSuite Email Suspicious Attachment | Anomaly | NULL | G Suite Gmail | T1566.001 |
| Gsuite Email Suspicious Subject With Attachment | Anomaly | NULL | G Suite Gmail | T1566.001 |
| Gsuite Email With Known Abuse Web Service Link | Anomaly | NULL | G Suite Gmail | T1566.001 |
| Gsuite suspicious calendar invite | Hunting | NULL | T1566 | |
| Gsuite Suspicious Shared File Name | Anomaly | NULL | G Suite Drive | T1566.001 |
| Linux Ghostscript Exploitation | TTP | NULL | Sysmon for Linux EventID 1 | T1566 |
| MSHTML Module Load in Office Product | TTP | NULL | Sysmon EventID 7 | T1566.001 |
| O365 Email Reported By Admin Found Malicious | TTP | NULL | Office 365 Universal Audit Log | T1566.001 T1566.002 |
| O365 Email Reported By User Found Malicious | TTP | NULL | Office 365 Universal Audit Log | T1566.001 T1566.002 |
| O365 Safe Links Detection | TTP | NULL | Office 365 Universal Audit Log | T1566.001 |
| O365 Threat Intelligence Suspicious Email Delivered | Anomaly | NULL | Office 365 Universal Audit Log | T1566.001 T1566.002 |
| O365 ZAP Activity Detection | Anomaly | NULL | Office 365 Universal Audit Log | T1566.001 T1566.002 |
| Office Application Drop Executable | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 11 | T1566.001 |
| Office Application Spawn Regsvr32 process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Office Application Spawn rundll32 process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Office Document Creating Schedule Task | TTP | NULL | Sysmon EventID 7 | T1566.001 |
| Office Document Executing Macro Code | TTP | NULL | Sysmon EventID 7 | T1566.001 |
| Office Document Spawned Child Process To Download | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Office Product Spawn CMD Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Office Product Spawning BITSAdmin | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Office Product Spawning CertUtil | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Office Product Spawning MSHTA | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Office Product Spawning Rundll32 with no DLL | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Office Product Spawning Windows Script Host | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Office Product Spawning Wmic | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Office Product Writing cab or inf | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Sysmon EventID 11 | T1566.001 |
| Office Spawning Control | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Process Creating LNK file in Suspicious Location | Anomaly | NULL | Sysmon EventID 11 | T1566.002 |
| Suspicious Email - UBA Anomaly | Anomaly | NULL | T1566 | |
| Suspicious Email Attachment Extensions | Anomaly | NULL | T1566.001 | |
| Windows CAB File on Disk | Anomaly | NULL | Sysmon EventID 11 | T1566.001 |
| Windows Defender ASR Audit Events | Anomaly | NULL | Windows Event Log Defender 1122, Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 1132, Windows Event Log Defender 1134 | T1566.001 T1566.002 |
| Windows Defender ASR Block Events | Anomaly | NULL | Windows Event Log Defender 1121, Windows Event Log Defender 1126, Windows Event Log Defender 1129, Windows Event Log Defender 1131, Windows Event Log Defender 1133 | T1566.001 T1566.002 |
| Windows Defender ASR Rules Stacking | Hunting | NULL | Windows Event Log Defender 1121, Windows Event Log Defender 1122, Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 1129, Windows Event Log Defender 1131, Windows Event Log Defender 1133, Windows Event Log Defender 1134, Windows Event Log Defender 5007 | T1566.001 T1566.002 |
| Windows InProcServer32 New Outlook Form | Anomaly | NULL | Sysmon EventID 13 | T1566 |
| Windows ISO LNK File Creation | Hunting | NULL | Sysmon EventID 11 | T1566.001 |
| Windows Office Product Dropped Cab or Inf File | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 11, Windows Event Log Security 4688 AND Sysmon EventID 11 | T1566.001 |
| Windows Office Product Dropped Uncommon File | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 11 | T1566.001 |
| Windows Office Product Loaded MSHTML Module | Anomaly | NULL | Sysmon EventID 7 | T1566.001 |
| Windows Office Product Loading Taskschd DLL | Anomaly | NULL | Sysmon EventID 7 | T1566.001 |
| Windows Office Product Loading VBE7 DLL | Anomaly | NULL | Sysmon EventID 7 | T1566.001 |
| Windows Office Product Spawned Child Process For Download | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Windows Office Product Spawned Control | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Windows Office Product Spawned MSDT | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Windows Office Product Spawned Rundll32 With No DLL | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Windows Office Product Spawned Uncommon Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Windows Office Product Spawning MSDT | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Windows Phishing Outlook Drop Dll In FORM Dir | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 11 | T1566 |
| Windows Phishing PDF File Executes URL Link | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Windows Phishing Recent ISO Exec Registry | Hunting | NULL | Sysmon EventID 13 | T1566.001 |
| Windows Spearphishing Attachment Connect To None MS Office Domain | Hunting | NULL | Sysmon EventID 22 | T1566.001 |
| Windows Spearphishing Attachment Onenote Spawn Mshta | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Windows Universal Data Link File Creation | Anomaly | NULL | Sysmon EventID 11 | T1566.001 |
| Winword Spawning Cmd | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Winword Spawning PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Winword Spawning Windows Script Host | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1566.001 |
| Zscaler Adware Activities Threat Blocked | Anomaly | NULL | T1566 | |
| Zscaler Behavior Analysis Threat Blocked | Anomaly | NULL | T1566 | |
| Zscaler CryptoMiner Downloaded Threat Blocked | Anomaly | NULL | T1566 | |
| Zscaler Employment Search Web Activity | Anomaly | NULL | T1566 | |
| Zscaler Exploit Threat Blocked | TTP | NULL | T1566 | |
| Zscaler Legal Liability Threat Blocked | Anomaly | NULL | T1566 | |
| Zscaler Malware Activity Threat Blocked | Anomaly | NULL | T1566 | |
| Zscaler Phishing Activity Threat Blocked | Anomaly | NULL | T1566 | |
| Zscaler Potentially Abused File Download | Anomaly | NULL | T1566 | |
| Zscaler Privacy Risk Destinations Threat Blocked | Anomaly | NULL | T1566 | |
| Zscaler Scam Destinations Threat Blocked | Anomaly | NULL | T1566 | |
| Zscaler Virus Download threat blocked | Anomaly | NULL | T1566 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAppleJeus | AppleJeus has used spearphishing emails to distribute malicious payloads. |
| GroupAxiom | Axiom has used spear phishing to initially compromise victims. |
| GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has conducted malicious spam (malspam) campaigns to gain access to victim's machines. |
| GroupINC Ransom | INC Ransom has used phishing to gain initial access. |
| GroupKimsuky | Kimsuky has used spearphishing to gain initial access and intelligence. |
| GroupMuddyWater | MuddyWater has sent phishing emails to targets from the email address support@microsoftonlines[.]com. |
| GroupSea Turtle | Sea Turtle used spear phishing to gain initial access to victims. |
| GroupVOID MANTICORE | VOID MANTICORE has emailed victims threatening messages. VOID MANTICORE has used phishing as an initial access vector. |
| Used by | Procedure example |
|---|---|
| MalwareHikit | Hikit has been spread through spear phishing. |
| MalwareINC Ransomware | INC Ransomware campaigns have used spearphishing emails for initial access. |
| MalwareRoyal | Royal has been spread through the use of phishing campaigns including "call back phishing" where victims are lured into calling a number provided through email. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.