# T1566.001 Spearphishing Attachment

> As of 2026-10-05, T1566.001 (Spearphishing Attachment) appears in 194 tracked threats, first reported 2026-01-14 and most recently 2026-10-02, with linked actors including APT28, Forest Blizzard, APT36; it most often appears alongside T1204.002 (Malicious File).

- **Tracked threats:** 194 (23 critical, 147 high, 24 medium)
- **First seen:** 2026-01-14
- **Last seen:** 2026-10-02
- **Threat actors:** 83
- **Detection rules:** 465 (counts only; Blue tier and above)

## Key facts

- **ID:** T1566.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access
- **Matrix:** Enterprise
- **Parent:** T1566
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1566/001/

## Activity timeline

T1566.001 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 61 reports, and 194 of the 194 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1566.001 Spearphishing Attachment is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix, as a sub-technique of [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566). Threadlinqs maps 194 of 2623 tracked threats (7.4%) to it; by severity that is 23 critical, 147 high, 24 medium.

Threats that use T1566.001 most often also use [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (159 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (128 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (115 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (105 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (96 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

83 tracked threat actors appear in the threats that use T1566.001; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (12), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (8), [APT36](https://intel.threadlinqs.com/actor/APT36) (6), [APT43](https://intel.threadlinqs.com/actor/APT43) (6), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (6).

## Mitigations

MITRE ATT&CK lists 7 mitigations for T1566.001.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)
- [M1054 Software Configuration](https://attack.mitre.org/mitigations/M1054/)

## Data sources

Telemetry that can reveal T1566.001, per MITRE ATT&CK.

- Application Log — Application Log Content
- File — File Creation
- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 12
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 8
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 6
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 6
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 6
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 6
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 6
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 4
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 4
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 4
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 4

## Tracked threats

The 30 most recent of 194 tracked threats that use T1566.001.

- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…](https://intel.threadlinqs.com/threat/TL-2026-2800) — high — 2026-09-30
- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — high — 2026-09-29
- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — high — 2026-09-29
- [SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…](https://intel.threadlinqs.com/threat/TL-2026-2773) — high — 2026-09-29
- [Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…](https://intel.threadlinqs.com/threat/TL-2026-2764) — high — 2026-09-28
- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limited](https://intel.threadlinqs.com/threat/TL-2026-2667) — high — 2026-09-26
- [Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)](https://intel.threadlinqs.com/threat/TL-2026-2659) — high — 2026-09-26
- [Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…](https://intel.threadlinqs.com/threat/TL-2026-2654) — high — 2026-09-25
- [Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…](https://intel.threadlinqs.com/threat/TL-2026-2645) — high — 2026-09-25
- [Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)](https://intel.threadlinqs.com/threat/TL-2026-2614) — high — 2026-09-22
- [France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months](https://intel.threadlinqs.com/threat/TL-2026-2564) — high — 2026-09-18
- [AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and…](https://intel.threadlinqs.com/threat/TL-2026-2559) — medium — 2026-09-18
- [SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2554) — high — 2026-09-17
- [Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators](https://intel.threadlinqs.com/threat/TL-2026-2532) — medium — 2026-09-16
- [Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability](https://intel.threadlinqs.com/threat/TL-2026-2468) — high — 2026-09-12
- [Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)](https://intel.threadlinqs.com/threat/TL-2026-2451) — medium — 2026-09-11
- [Tropic Trooper Spear-Phishing Campaign Uses LNK Loader, DLL Side-Loading via Signed McAfee Binary, and…](https://intel.threadlinqs.com/threat/TL-2026-2427) — high — 2026-09-10
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…](https://intel.threadlinqs.com/threat/TL-2026-2407) — critical — 2026-09-08
- [The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2402) — high — 2026-09-08
- [APT-C-60 Spear-Phishing Campaign Delivering SpyGlace via Proton Drive, RAR/LNK and Legitimate Developer…](https://intel.threadlinqs.com/threat/TL-2026-2371) — high — 2026-09-07
- [Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chain](https://intel.threadlinqs.com/threat/TL-2026-2305) — high — 2026-09-03
- [Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International…](https://intel.threadlinqs.com/threat/TL-2026-2303) — medium — 2026-09-02
- [MoiClient Backdoor: Multi-Stage Evasion via DLL Side-Loading, RPC UAC Bypass, and BYOVD Driver Abuse](https://intel.threadlinqs.com/threat/TL-2026-2288) — high — 2026-09-02
- [Fake Voicemail SVG Phishing Campaign Bypasses Email Filters via MIME Spoofing](https://intel.threadlinqs.com/threat/TL-2026-2230) — high — 2026-08-30
- [Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breach](https://intel.threadlinqs.com/threat/TL-2026-2219) — high — 2026-08-29
- [Fake Beijing Institute of Technology Resume Lure Delivers SNOWLIGHT Shellcode and Fileless VShell RAT to…](https://intel.threadlinqs.com/threat/TL-2026-2217) — high — 2026-08-29
- [APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiye](https://intel.threadlinqs.com/threat/TL-2026-2213) — high — 2026-08-29
- [HOOKEDGE: New BlueDelta (APT28/Fancy Bear) Backdoor Abuses Microsoft Edge and webhook.site for C2](https://intel.threadlinqs.com/threat/TL-2026-2187) — high — 2026-08-28

## Related CVEs

CVEs referenced by the tracked threats that use T1566.001, most frequent first.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-34621](https://intel.threadlinqs.com/cve/CVE-2026-34621)
- [CVE-2012-1854](https://intel.threadlinqs.com/cve/CVE-2012-1854)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2017-8291](https://intel.threadlinqs.com/cve/CVE-2017-8291)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-9715](https://intel.threadlinqs.com/cve/CVE-2020-9715)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-21529](https://intel.threadlinqs.com/cve/CVE-2023-21529)
- [CVE-2023-36424](https://intel.threadlinqs.com/cve/CVE-2023-36424)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-43451](https://intel.threadlinqs.com/cve/CVE-2024-43451)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)

## Detection coverage

Threadlinqs maintains 465 detection rules mapped to T1566.001 (SPL 184, KQL 131, Sigma 150). Rule content is available to Blue tier accounts and above; this page shows counts only.

465 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) — 641 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1566.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
