# T1566.003 Spearphishing via Service

> As of 2026-10-05, T1566.003 (Spearphishing via Service) appears in 62 tracked threats, first reported 2026-02-16 and most recently 2026-10-04, with linked actors including APT38, Andariel, Lazarus Group; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 62 (6 critical, 52 high, 4 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-10-04
- **Threat actors:** 36
- **Detection rules:** 86 (counts only; Blue tier and above)

## Key facts

- **ID:** T1566.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access
- **Matrix:** Enterprise
- **Parent:** T1566
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1566/003/

## Activity timeline

T1566.003 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 13 reports, and 62 of the 62 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1566.003 Spearphishing via Service is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix, as a sub-technique of [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566). Threadlinqs maps 62 of 2623 tracked threats (2.4%) to it; by severity that is 6 critical, 52 high, 4 medium.

Threats that use T1566.003 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (41 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (38 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (35 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (32 threats), [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (30 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

36 tracked threat actors appear in the threats that use T1566.003; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (8), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (6), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (6), [WageMole](https://intel.threadlinqs.com/actor/WageMole) (5), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (4).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1566.003.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)

## Data sources

Telemetry that can reveal T1566.003, per MITRE ATT&CK.

- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 8
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 6
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 6
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 5
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 4
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 3
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 3
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 2
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 2
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 2
- [Iran Ministry of Intelligence](https://intel.threadlinqs.com/actor/Iran%20Ministry%20of%20Intelligence) — 2
- [Milk Dragon](https://intel.threadlinqs.com/actor/Milk%20Dragon) — 2

## Tracked threats

The 30 most recent of 62 tracked threats that use T1566.003.

- [Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…](https://intel.threadlinqs.com/threat/TL-2026-2919) — high — 2026-10-04
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…](https://intel.threadlinqs.com/threat/TL-2026-2901) — high — 2026-10-04
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFA](https://intel.threadlinqs.com/threat/TL-2026-2834) — high — 2026-10-01
- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — high — 2026-09-29
- [DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…](https://intel.threadlinqs.com/threat/TL-2026-2635) — high — 2026-09-23
- [North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via…](https://intel.threadlinqs.com/threat/TL-2026-2581) — high — 2026-09-19
- [KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Software](https://intel.threadlinqs.com/threat/TL-2026-2555) — high — 2026-09-17
- [Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists](https://intel.threadlinqs.com/threat/TL-2026-2543) — high — 2026-09-16
- [Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies](https://intel.threadlinqs.com/threat/TL-2026-2534) — high — 2026-09-16
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusion](https://intel.threadlinqs.com/threat/TL-2026-2326) — high — 2026-09-04
- ["Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAs](https://intel.threadlinqs.com/threat/TL-2026-2322) — high — 2026-09-03
- [Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft Teams](https://intel.threadlinqs.com/threat/TL-2026-2302) — high — 2026-09-02
- [Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts](https://intel.threadlinqs.com/threat/TL-2026-2296) — high — 2026-09-02
- ["The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware…](https://intel.threadlinqs.com/threat/TL-2026-2155) — high — 2026-08-26
- [Void Dokkaebi Ships Cython-Compiled InvisibleFerret Malware as .pyd/.so Files to Evade Script Detection](https://intel.threadlinqs.com/threat/TL-2026-2145) — high — 2026-08-25
- [SynkLoader: Modular Multi-Language Loader Deployed via Microsoft Teams Phishing, Likely Ransomware Precursor](https://intel.threadlinqs.com/threat/TL-2026-2131) — high — 2026-08-24
- [Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicry](https://intel.threadlinqs.com/threat/TL-2026-2088) — high — 2026-08-20
- [Post-DEF CON Phishing Campaign Abuses Google Apps Script Sidebar to Deliver AMOS Stealer and NetSupport RAT](https://intel.threadlinqs.com/threat/TL-2026-2449) — high — 2026-08-19
- [TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platforms](https://intel.threadlinqs.com/threat/TL-2026-2019) — medium — 2026-08-14
- [UAC-0145 (Sandworm subcluster) trojanizes WireGuard VPN client "SopraVPN" in fake IT recruitment campaign…](https://intel.threadlinqs.com/threat/TL-2026-1973) — high — 2026-08-10
- [Ransomware Moves up the Org Chart: Managers Are Prime Targets (Zscaler ThreatLabz, 351 Victims / 334…](https://intel.threadlinqs.com/threat/TL-2026-2897) — high — 2026-08-06
- [Coldcard Security Audit Phishing Campaign Installs ConnectWise ScreenConnect RAT](https://intel.threadlinqs.com/threat/TL-2026-1896) — critical — 2026-08-05
- [CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive…](https://intel.threadlinqs.com/threat/TL-2026-1857) — high — 2026-08-04
- [GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPs](https://intel.threadlinqs.com/threat/TL-2026-1768) — high — 2026-07-30
- [Russian FSB/GRU Actors (UNC5792, UNC4221) Phish Signal Backup Recovery Keys for Persistent Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1814) — high — 2026-07-29
- [Check Point Q2 2026 Brand Phishing Report: Microsoft Leads at 23%, ChatGPT Enters Top 10 Impersonated Brands](https://intel.threadlinqs.com/threat/TL-2026-1731) — medium — 2026-07-27
- [EtherHiding on macOS: Blockchain-Resolved C2 via Polygon Smart Contract](https://intel.threadlinqs.com/threat/TL-2026-1670) — high — 2026-07-24
- [North Korean Contagious Interview Campaign Deploys OtterCookie via SVG Steganography to Steal Developer…](https://intel.threadlinqs.com/threat/TL-2026-1571) — high — 2026-07-20
- [ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaign](https://intel.threadlinqs.com/threat/TL-2026-1570) — high — 2026-07-20

## Related CVEs

CVEs referenced by the tracked threats that use T1566.003, most frequent first.

- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)
- [CVE-2026-85046](https://intel.threadlinqs.com/cve/CVE-2026-85046)

## Detection coverage

Threadlinqs maintains 86 detection rules mapped to T1566.003 (SPL 30, KQL 27, Sigma 29). Rule content is available to Blue tier accounts and above; this page shows counts only.

86 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) — 641 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1566.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
