Activity timeline
T1566.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 13 reports, and 62 of the 62 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1566.003 Spearphishing via Service is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix, as a sub-technique of T1566 Phishing. Threadlinqs maps 62 of 2623 tracked threats (2.4%) to it; by severity that is 6 critical, 52 high, 4 medium.
Threats that use T1566.003 most often also use T1071.001 Web Protocols (41 threats), T1204.002 Malicious File (38 threats), T1036.005 Match Legitimate Resource Name or Location (35 threats), T1583.001 Domains (32 threats), T1657 Financial Theft (30 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
36 tracked threat actors appear in the threats that use T1566.003; the most frequent are APT38 (8), Andariel (6), Lazarus Group (6), WageMole (5), Contagious Interview (4).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1566.003.
Data sources
Telemetry that can reveal T1566.003, per MITRE ATT&CK.
- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 62 tracked threats that use T1566.003.
- Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…high
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…high
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFAhigh
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…high
- North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via…high
- KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Softwarehigh
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalistshigh
- Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencieshigh
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusionhigh
- "Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAshigh
- Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft Teamshigh
- Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accountshigh
- "The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware…high
- Void Dokkaebi Ships Cython-Compiled InvisibleFerret Malware as .pyd/.so Files to Evade Script Detectionhigh
- SynkLoader: Modular Multi-Language Loader Deployed via Microsoft Teams Phishing, Likely Ransomware Precursorhigh
- Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicryhigh
- Post-DEF CON Phishing Campaign Abuses Google Apps Script Sidebar to Deliver AMOS Stealer and NetSupport RAThigh
- TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platformsmedium
- UAC-0145 (Sandworm subcluster) trojanizes WireGuard VPN client "SopraVPN" in fake IT recruitment campaign…high
- Ransomware Moves up the Org Chart: Managers Are Prime Targets (Zscaler ThreatLabz, 351 Victims / 334…high
- Coldcard Security Audit Phishing Campaign Installs ConnectWise ScreenConnect RATcritical
- CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive…high
- GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPshigh
- Russian FSB/GRU Actors (UNC5792, UNC4221) Phish Signal Backup Recovery Keys for Persistent Account Takeoverhigh
- Check Point Q2 2026 Brand Phishing Report: Microsoft Leads at 23%, ChatGPT Enters Top 10 Impersonated Brandsmedium
- EtherHiding on macOS: Blockchain-Resolved C2 via Polygon Smart Contracthigh
- North Korean Contagious Interview Campaign Deploys OtterCookie via SVG Steganography to Steal Developer…high
- ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaignhigh
Detection coverage
Threadlinqs maintains 86 detection rules mapped to T1566.003 (SPL 30, KQL 27, Sigma 29). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1566 Phishing — 641 tracked threats at the technique level.