# T1566.004 Spearphishing Voice

> As of 2026-10-05, T1566.004 (Spearphishing Voice) appears in 50 tracked threats, first reported 2026-02-02 and most recently 2026-09-29, with linked actors including ShinyHunters, Scattered Spider, UNC6395; it most often appears alongside T1657 (Financial Theft).

- **Tracked threats:** 50 (3 critical, 35 high, 10 medium, 1 low)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-29
- **Threat actors:** 23
- **Detection rules:** 132 (counts only; Blue tier and above)

## Key facts

- **ID:** T1566.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access
- **Matrix:** Enterprise
- **Parent:** T1566
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1566/004/

## Activity timeline

T1566.004 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 16 reports, and 50 of the 50 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1566.004 Spearphishing Voice is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix, as a sub-technique of [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566). Threadlinqs maps 50 of 2623 tracked threats (1.9%) to it; by severity that is 3 critical, 35 high, 10 medium, 1 low.

Threats that use T1566.004 most often also use [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (36 threats), [T1684.001 Impersonation](https://intel.threadlinqs.com/technique/T1684.001) (30 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (24 threats), [T1219 Remote Access Tools](https://intel.threadlinqs.com/technique/T1219) (20 threats), [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (20 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

23 tracked threat actors appear in the threats that use T1566.004; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (7), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (6), [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) (5), [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) (4), [Silent Ransom Group](https://intel.threadlinqs.com/actor/Silent%20Ransom%20Group) (4).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1566.004.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)

## Data sources

Telemetry that can reveal T1566.004, per MITRE ATT&CK.

- Application Log — Application Log Content

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 7
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 6
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 5
- [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) — 4
- [Silent Ransom Group](https://intel.threadlinqs.com/actor/Silent%20Ransom%20Group) — 4
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 4
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 4
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 4
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 3
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 3
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 3
- [Balonx](https://intel.threadlinqs.com/actor/Balonx) — 2

## Tracked threats

The 30 most recent of 50 tracked threats that use T1566.004.

- [AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification](https://intel.threadlinqs.com/threat/TL-2026-2774) — high — 2026-09-29
- [Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…](https://intel.threadlinqs.com/threat/TL-2026-2685) — high — 2026-09-27
- [Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem](https://intel.threadlinqs.com/threat/TL-2026-2663) — 2026-09-26
- [Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script](https://intel.threadlinqs.com/threat/TL-2026-2695) — medium — 2026-09-25
- [Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)](https://intel.threadlinqs.com/threat/TL-2026-2603) — high — 2026-09-21
- [Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…](https://intel.threadlinqs.com/threat/TL-2026-2595) — high — 2026-09-21
- [Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-2472) — high — 2026-09-13
- [Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time](https://intel.threadlinqs.com/threat/TL-2026-2289) — low — 2026-09-02
- ["Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relay](https://intel.threadlinqs.com/threat/TL-2026-2276) — high — 2026-09-01
- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — critical — 2026-09-01
- [ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and…](https://intel.threadlinqs.com/threat/TL-2026-2208) — critical — 2026-08-29
- [Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion](https://intel.threadlinqs.com/threat/TL-2026-2176) — high — 2026-08-28
- [AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock Bypass](https://intel.threadlinqs.com/threat/TL-2026-2164) — high — 2026-08-27
- [Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…](https://intel.threadlinqs.com/threat/TL-2026-2143) — critical — 2026-08-25
- [Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Access](https://intel.threadlinqs.com/threat/TL-2026-2129) — medium — 2026-08-24
- [UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firms](https://intel.threadlinqs.com/threat/TL-2026-2127) — high — 2026-08-24
- [Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…](https://intel.threadlinqs.com/threat/TL-2026-2103) — high — 2026-08-21
- [Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicry](https://intel.threadlinqs.com/threat/TL-2026-2088) — high — 2026-08-20
- [Balonx Sistema PhaaS Campaign — AI Voice Calls and Fake Banking Pages Targeting Mexican Financial Institutions](https://intel.threadlinqs.com/threat/TL-2026-2072) — high — 2026-08-19
- [Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chains](https://intel.threadlinqs.com/threat/TL-2026-2050) — high — 2026-08-17
- [Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)](https://intel.threadlinqs.com/threat/TL-2026-2045) — high — 2026-08-17
- [AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub…](https://intel.threadlinqs.com/threat/TL-2026-2042) — medium — 2026-08-17
- [SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII…](https://intel.threadlinqs.com/threat/TL-2026-2032) — medium — 2026-08-16
- [ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers](https://intel.threadlinqs.com/threat/TL-2026-2007) — medium — 2026-08-13
- [Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents](https://intel.threadlinqs.com/threat/TL-2026-1938) — high — 2026-08-08
- [UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking](https://intel.threadlinqs.com/threat/TL-2026-1926) — high — 2026-08-07
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1776) — high — 2026-07-30
- [Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments](https://intel.threadlinqs.com/threat/TL-2026-1765) — medium — 2026-07-29
- [Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectiveness](https://intel.threadlinqs.com/threat/TL-2026-1702) — medium — 2026-07-25

## Detection coverage

Threadlinqs maintains 132 detection rules mapped to T1566.004 (SPL 46, KQL 41, Sigma 45). Rule content is available to Blue tier accounts and above; this page shows counts only.

132 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) — 641 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1566.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
