Activity timeline
T1204.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 67 reports, and 218 of the 218 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1204.001 Malicious Link is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of T1204 User Execution. Threadlinqs maps 218 of 2623 tracked threats (8.3%) to it; by severity that is 34 critical, 141 high, 41 medium, 2 low.
Threats that use T1204.001 most often also use T1566.002 Spearphishing Link (156 threats), T1071.001 Web Protocols (108 threats), T1583.001 Domains (103 threats), T1027 Obfuscated Files or Information (86 threats), T1036.005 Match Legitimate Resource Name or Location (76 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
53 tracked threat actors appear in the threats that use T1204.001; the most frequent are ShinyHunters (3), APT28 (2), APT38 (2), EvilTokens (2), Greatness PhaaS Operators (2).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1204.001.
Data sources
Telemetry that can reveal T1204.001, per MITRE ATT&CK.
- File — File Creation
- Network Traffic — Network Connection Creation, Network Traffic Content
Threat actors using it
Tracked threats
The 30 most recent of 218 tracked threats that use T1204.001.
- Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…high
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…high
- Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features…critical
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)high
- EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…high
- Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data…high
- Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)critical
- Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breachmedium
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFAhigh
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishingmedium
- Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)critical
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verificationhigh
- Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Datahigh
- Fake American Express "non-compliance" card-lock phishing campaign targets Australiansmedium
- GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking…medium
- Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…high
- Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account…high
- Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK…medium
- Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)high
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…high
- Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac usershigh
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…high
- Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…high
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentialsmedium
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentialsmedium
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)high
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…high
- Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Installcritical
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…high
- Click2Shell WordPress Exploit Chain Lets Attackers Gain RCE With a Single Malicious Linkcritical
Detection coverage
Threadlinqs maintains 517 detection rules mapped to T1204.001 (SPL 201, KQL 160, Sigma 156). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1204 User Execution — 571 tracked threats at the technique level.