Activity timeline
T1566.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 96 reports, and 308 of the 308 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1566.002 Spearphishing Link is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix, as a sub-technique of T1566 Phishing. Threadlinqs maps 308 of 2623 tracked threats (11.7%) to it; by severity that is 33 critical, 219 high, 53 medium, 2 low.
Threats that use T1566.002 most often also use T1071.001 Web Protocols (178 threats), T1204.001 Malicious Link (156 threats), T1204.002 Malicious File (149 threats), T1027 Obfuscated Files or Information (145 threats), T1583.001 Domains (140 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
101 tracked threat actors appear in the threats that use T1566.002; the most frequent are APT38 (11), Sapphire Sleet (8), Stardust Chollima (8), Andariel (6), Lazarus Group (6).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1566.002.
Data sources
Telemetry that can reveal T1566.002, per MITRE ATT&CK.
- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 308 tracked threats that use T1566.002.
- Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features…critical
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)high
- EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…high
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data…high
- Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breachmedium
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishingmedium
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Accesshigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verificationhigh
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…medium
- Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Datahigh
- Fake American Express "non-compliance" card-lock phishing campaign targets Australiansmedium
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvestershigh
- Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account…high
- Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem
- Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)high
- Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…high
- Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Usersmedium
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…high
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…high
- MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor modulehigh
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentialsmedium
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)high
- Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoorshigh
Detection coverage
Threadlinqs maintains 827 detection rules mapped to T1566.002 (SPL 299, KQL 244, Sigma 284). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1566 Phishing — 641 tracked threats at the technique level.