# T1566.002 Spearphishing Link

> As of 2026-10-05, T1566.002 (Spearphishing Link) appears in 308 tracked threats, first reported 2026-01-27 and most recently 2026-10-04, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 308 (33 critical, 219 high, 53 medium, 2 low)
- **First seen:** 2026-01-27
- **Last seen:** 2026-10-04
- **Threat actors:** 101
- **Detection rules:** 827 (counts only; Blue tier and above)

## Key facts

- **ID:** T1566.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access
- **Matrix:** Enterprise
- **Parent:** T1566
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1566/002/

## Activity timeline

T1566.002 first appeared in tracked threats on 2026-01-27 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 96 reports, and 308 of the 308 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1566.002 Spearphishing Link is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix, as a sub-technique of [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566). Threadlinqs maps 308 of 2623 tracked threats (11.7%) to it; by severity that is 33 critical, 219 high, 53 medium, 2 low.

Threats that use T1566.002 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (178 threats), [T1204.001 Malicious Link](https://intel.threadlinqs.com/technique/T1204.001) (156 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (149 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (145 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (140 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

101 tracked threat actors appear in the threats that use T1566.002; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (11), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (8), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (8), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (6), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (6).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1566.002.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1054 Software Configuration](https://attack.mitre.org/mitigations/M1054/)

## Data sources

Telemetry that can reveal T1566.002, per MITRE ATT&CK.

- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 11
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 8
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 8
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 6
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 6
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 4
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 4
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 4
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 4
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 4
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 4
- [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) — 4

## Tracked threats

The 30 most recent of 308 tracked threats that use T1566.002.

- [Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features…](https://intel.threadlinqs.com/threat/TL-2026-2894) — critical — 2026-10-04
- [China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)](https://intel.threadlinqs.com/threat/TL-2026-2884) — high — 2026-10-04
- [EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…](https://intel.threadlinqs.com/threat/TL-2026-2873) — high — 2026-10-03
- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data…](https://intel.threadlinqs.com/threat/TL-2026-2839) — high — 2026-10-02
- [Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breach](https://intel.threadlinqs.com/threat/TL-2026-2842) — medium — 2026-10-01
- [ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing](https://intel.threadlinqs.com/threat/TL-2026-2826) — medium — 2026-10-01
- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…](https://intel.threadlinqs.com/threat/TL-2026-2802) — high — 2026-09-30
- [Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access](https://intel.threadlinqs.com/threat/TL-2026-2788) — high — 2026-09-29
- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — high — 2026-09-29
- [AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification](https://intel.threadlinqs.com/threat/TL-2026-2774) — high — 2026-09-29
- [Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…](https://intel.threadlinqs.com/threat/TL-2026-2770) — medium — 2026-09-29
- [Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Data](https://intel.threadlinqs.com/threat/TL-2026-2768) — high — 2026-09-29
- [Fake American Express "non-compliance" card-lock phishing campaign targets Australians](https://intel.threadlinqs.com/threat/TL-2026-2758) — medium — 2026-09-29
- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — high — 2026-09-27
- [Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account…](https://intel.threadlinqs.com/threat/TL-2026-2672) — high — 2026-09-26
- [Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem](https://intel.threadlinqs.com/threat/TL-2026-2663) — 2026-09-26
- [Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)](https://intel.threadlinqs.com/threat/TL-2026-2659) — high — 2026-09-26
- [Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2670) — high — 2026-09-25
- [Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users](https://intel.threadlinqs.com/threat/TL-2026-2655) — medium — 2026-09-25
- [Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…](https://intel.threadlinqs.com/threat/TL-2026-2654) — high — 2026-09-25
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…](https://intel.threadlinqs.com/threat/TL-2026-2647) — high — 2026-09-25
- [Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…](https://intel.threadlinqs.com/threat/TL-2026-2645) — high — 2026-09-25
- [MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor module](https://intel.threadlinqs.com/threat/TL-2026-2641) — high — 2026-09-24
- [Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…](https://intel.threadlinqs.com/threat/TL-2026-2634) — medium — 2026-09-23
- [Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials](https://intel.threadlinqs.com/threat/TL-2026-2626) — medium — 2026-09-23
- [Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)](https://intel.threadlinqs.com/threat/TL-2026-2614) — high — 2026-09-22
- [Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors](https://intel.threadlinqs.com/threat/TL-2026-2599) — high — 2026-09-21

## Related CVEs

CVEs referenced by the tracked threats that use T1566.002, most frequent first.

- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2026-15764](https://intel.threadlinqs.com/cve/CVE-2026-15764)
- [CVE-2026-15765](https://intel.threadlinqs.com/cve/CVE-2026-15765)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-68820](https://intel.threadlinqs.com/cve/CVE-2026-68820)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2019-11580](https://intel.threadlinqs.com/cve/CVE-2019-11580)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-38003](https://intel.threadlinqs.com/cve/CVE-2021-38003)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2024-42009](https://intel.threadlinqs.com/cve/CVE-2024-42009)
- [CVE-2024-43451](https://intel.threadlinqs.com/cve/CVE-2024-43451)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)
- [CVE-2025-24054](https://intel.threadlinqs.com/cve/CVE-2025-24054)
- [CVE-2025-33053](https://intel.threadlinqs.com/cve/CVE-2025-33053)
- [CVE-2025-39391](https://intel.threadlinqs.com/cve/CVE-2025-39391)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2025-68461](https://intel.threadlinqs.com/cve/CVE-2025-68461)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-103922](https://intel.threadlinqs.com/cve/CVE-2026-103922)
- [CVE-2026-10702](https://intel.threadlinqs.com/cve/CVE-2026-10702)
- [CVE-2026-12957](https://intel.threadlinqs.com/cve/CVE-2026-12957)
- [CVE-2026-12958](https://intel.threadlinqs.com/cve/CVE-2026-12958)

## Detection coverage

Threadlinqs maintains 827 detection rules mapped to T1566.002 (SPL 299, KQL 244, Sigma 284). Rule content is available to Blue tier accounts and above; this page shows counts only.

827 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) — 641 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1566.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
