Activity timeline
T1566.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 16 reports, and 50 of the 50 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1566.004 Spearphishing Voice is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix, as a sub-technique of T1566 Phishing. Threadlinqs maps 50 of 2623 tracked threats (1.9%) to it; by severity that is 3 critical, 35 high, 10 medium, 1 low.
Threats that use T1566.004 most often also use T1657 Financial Theft (36 threats), T1684.001 Impersonation (30 threats), T1583.001 Domains (24 threats), T1219 Remote Access Tools (20 threats), T1566.002 Spearphishing Link (20 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
23 tracked threat actors appear in the threats that use T1566.004; the most frequent are ShinyHunters (7), Scattered Spider (6), UNC6395 (5), Luna Moth (4), Silent Ransom Group (4).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1566.004.
Data sources
Telemetry that can reveal T1566.004, per MITRE ATT&CK.
- Application Log — Application Log Content
Threat actors using it
Tracked threats
The 30 most recent of 50 tracked threats that use T1566.004.
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verificationhigh
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…high
- Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Scriptmedium
- Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)high
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…high
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltrationhigh
- Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Timelow
- "Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relayhigh
- BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suitecritical
- ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and…critical
- Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusionhigh
- AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock Bypasshigh
- Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…critical
- Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Accessmedium
- UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firmshigh
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…high
- Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicryhigh
- Balonx Sistema PhaaS Campaign — AI Voice Calls and Fake Banking Pages Targeting Mexican Financial Institutionshigh
- Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chainshigh
- Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)high
- AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub…medium
- SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII…medium
- ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customersmedium
- Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidentshigh
- UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijackinghigh
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deploymenthigh
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Paymentsmedium
- Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectivenessmedium
Detection coverage
Threadlinqs maintains 132 detection rules mapped to T1566.004 (SPL 46, KQL 41, Sigma 45). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1566 Phishing — 641 tracked threats at the technique level.