Activity timeline
T1566.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 61 reports, and 194 of the 194 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1566.001 Spearphishing Attachment is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix, as a sub-technique of T1566 Phishing. Threadlinqs maps 194 of 2623 tracked threats (7.4%) to it; by severity that is 23 critical, 147 high, 24 medium.
Threats that use T1566.001 most often also use T1204.002 Malicious File (159 threats), T1071.001 Web Protocols (128 threats), T1027 Obfuscated Files or Information (115 threats), T1082 System Information Discovery (105 threats), T1140 Deobfuscate/Decode Files or Information (96 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
83 tracked threat actors appear in the threats that use T1566.001; the most frequent are APT28 (12), Forest Blizzard (8), APT36 (6), APT43 (6), BlueDelta (6).
Mitigations
MITRE ATT&CK lists 7 mitigations for T1566.001.
Data sources
Telemetry that can reveal T1566.001, per MITRE ATT&CK.
- Application Log — Application Log Content
- File — File Creation
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 194 tracked threats that use T1566.001.
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…high
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…high
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limitedhigh
- Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)high
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…high
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…high
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)high
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Monthshigh
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and…medium
- SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign…high
- Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operatorsmedium
- Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capabilityhigh
- Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)medium
- Tropic Trooper Spear-Phishing Campaign Uses LNK Loader, DLL Side-Loading via Signed McAfee Binary, and…high
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…critical
- The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…high
- APT-C-60 Spear-Phishing Campaign Delivering SpyGlace via Proton Drive, RAR/LNK and Legitimate Developer…high
- Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chainhigh
- Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International…medium
- MoiClient Backdoor: Multi-Stage Evasion via DLL Side-Loading, RPC UAC Bypass, and BYOVD Driver Abusehigh
- Fake Voicemail SVG Phishing Campaign Bypasses Email Filters via MIME Spoofinghigh
- Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breachhigh
- Fake Beijing Institute of Technology Resume Lure Delivers SNOWLIGHT Shellcode and Fileless VShell RAT to…high
- APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiyehigh
- HOOKEDGE: New BlueDelta (APT28/Fancy Bear) Backdoor Abuses Microsoft Edge and webhook.site for C2high
Detection coverage
Threadlinqs maintains 465 detection rules mapped to T1566.001 (SPL 184, KQL 131, Sigma 150). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1566 Phishing — 641 tracked threats at the technique level.