# T1534 Internal Spearphishing

> As of 2026-10-05, T1534 (Internal Spearphishing) appears in 35 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including Kali365, Kali365 PhaaS operators, Scattered LAPSUS$ Hunters; it most often appears alongside T1528 (Steal Application Access Token).

- **Tracked threats:** 35 (8 critical, 25 high, 2 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-03
- **Threat actors:** 30
- **Detection rules:** 40 (counts only; Blue tier and above)

## Key facts

- **ID:** T1534
- **Framework:** MITRE ATT&CK
- **Tactics:** Lateral Movement
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1534/

## Activity timeline

T1534 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 10 reports, and 35 of the 35 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1534 Internal Spearphishing is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix. Threadlinqs maps 35 of 2623 tracked threats (1.3%) to it; by severity that is 8 critical, 25 high, 2 medium.

Threats that use T1534 most often also use [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (19 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (18 threats), [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) (18 threats), [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) (15 threats), [T1098 Account Manipulation](https://intel.threadlinqs.com/technique/T1098) (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

30 tracked threat actors appear in the threats that use T1534; the most frequent are [Kali365](https://intel.threadlinqs.com/actor/Kali365) (3), [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) (2), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (2), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (2), [Storm-2372](https://intel.threadlinqs.com/actor/Storm-2372) (2).

## Data sources

Telemetry that can reveal T1534, per MITRE ATT&CK.

- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [Kali365](https://intel.threadlinqs.com/actor/Kali365) — 3
- [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) — 2
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 2
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 2
- [Storm-2372](https://intel.threadlinqs.com/actor/Storm-2372) — 2
- [Storm-2992](https://intel.threadlinqs.com/actor/Storm-2992) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 1
- [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1

## Tracked threats

The 30 most recent of 35 tracked threats that use T1534.

- [EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…](https://intel.threadlinqs.com/threat/TL-2026-2873) — high — 2026-10-03
- [SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce Agentforce](https://intel.threadlinqs.com/threat/TL-2026-2710) — high — 2026-09-27
- [OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)](https://intel.threadlinqs.com/threat/TL-2026-2628) — high — 2026-09-23
- [Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)](https://intel.threadlinqs.com/threat/TL-2026-2614) — high — 2026-09-22
- [Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake…](https://intel.threadlinqs.com/threat/TL-2026-2280) — medium — 2026-08-28
- [ADCS ESC1 Privilege Escalation: CISA AA26-237A Red Team Findings and CA Database Hunting Methodology](https://intel.threadlinqs.com/threat/TL-2026-2168) — high — 2026-08-27
- [Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…](https://intel.threadlinqs.com/threat/TL-2026-2091) — high — 2026-08-21
- [Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables Gmail/Slack/X/Claude.ai Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1923) — high — 2026-08-07
- [Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys](https://intel.threadlinqs.com/threat/TL-2026-1793) — high — 2026-07-31
- [OAuth Consent Phishing Abuses Microsoft's Legitimate Login System to Harvest Microsoft 365 Tokens](https://intel.threadlinqs.com/threat/TL-2026-1778) — high — 2026-07-30
- [AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Theft](https://intel.threadlinqs.com/threat/TL-2026-1811) — high — 2026-07-29
- [BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-1719) — high — 2026-07-27
- [Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts](https://intel.threadlinqs.com/threat/TL-2026-1641) — high — 2026-07-22
- [Zimbra Collaboration Suite 10.1.20 Patches Critical Unauthenticated SNMP/Swatchdog Command Injection Plus…](https://intel.threadlinqs.com/threat/TL-2026-1586) — critical — 2026-07-21
- [MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled…](https://intel.threadlinqs.com/threat/TL-2026-1530) — high — 2026-07-19
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [Unpatched Claude for Chrome Extension Flaws Enable Unauthorized Account Actions via Fake Clicks and…](https://intel.threadlinqs.com/threat/TL-2026-1318) — critical — 2026-07-14
- [ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens…](https://intel.threadlinqs.com/threat/TL-2026-1037) — high — 2026-07-01
- [Microsoft Entra ID Device Code Phishing — OAuth 2.0 Device Authorization Grant Abuse (Storm-2372…](https://intel.threadlinqs.com/threat/TL-2026-0943) — high — 2026-06-25
- [CodeStorm AiTM Phishing Kit Abuses Compromised Microsoft 365 Accounts for Real-Time MFA-Bypass Account…](https://intel.threadlinqs.com/threat/TL-2026-0913) — high — 2026-06-23
- [EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing…](https://intel.threadlinqs.com/threat/TL-2026-0888) — high — 2026-06-20
- [phpBB Authentication Bypass and OAuth Account Takeover (CVE-2026-48611 / CVE-2026-48612) — Decade-Old…](https://intel.threadlinqs.com/threat/TL-2026-0789) — critical — 2026-06-14
- [Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day CVE-2026-42897 Exploited In the Wild](https://intel.threadlinqs.com/threat/TL-2026-0780) — critical — 2026-06-11
- [Ubiquiti UniFi OS — Three Max-Severity Pre-Auth Vulnerabilities (CVE-2026-34908 / 34909 / 34910) in Security…](https://intel.threadlinqs.com/threat/TL-2026-0563) — critical — 2026-05-22
- [Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass…](https://intel.threadlinqs.com/threat/TL-2026-0560) — high — 2026-05-22
- [Microsoft Semantic Kernel — Critical RCE & Arbitrary File Write Chain (CVE-2026-26030, CVE-2026-25592)](https://intel.threadlinqs.com/threat/TL-2026-0481) — critical — 2026-05-08
- [PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series &…](https://intel.threadlinqs.com/threat/TL-2026-0465) — critical — 2026-05-06
- [Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM Access Keys (Securelist, May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0451) — high — 2026-05-04
- [W3LL Phishing-as-a-Service Ecosystem Dismantled — FBI/Indonesia Takedown of $20M BEC Platform](https://intel.threadlinqs.com/threat/TL-2026-0373) — high — 2026-04-16
- [Tycoon2FA Phishing-as-a-Service Platform Persists Post-Europol Takedown with Rapid Infrastructure Recovery](https://intel.threadlinqs.com/threat/TL-2026-0257) — critical — 2026-03-20

## Related CVEs

CVEs referenced by the tracked threats that use T1534, most frequent first.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-0300](https://intel.threadlinqs.com/cve/CVE-2026-0300)
- [CVE-2026-25592](https://intel.threadlinqs.com/cve/CVE-2026-25592)
- [CVE-2026-26030](https://intel.threadlinqs.com/cve/CVE-2026-26030)
- [CVE-2026-33000](https://intel.threadlinqs.com/cve/CVE-2026-33000)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2026-34911](https://intel.threadlinqs.com/cve/CVE-2026-34911)
- [CVE-2026-42897](https://intel.threadlinqs.com/cve/CVE-2026-42897)

## Detection coverage

Threadlinqs maintains 40 detection rules mapped to T1534 (SPL 11, KQL 15, Sigma 14). Rule content is available to Blue tier accounts and above; this page shows counts only.

40 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1534
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
