# T1566 Phishing

> As of 2026-10-05, T1566 (Phishing) appears in 641 tracked threats, first reported 2022-04-07 and most recently 2026-10-04, with linked actors including APT28, APT38, Forest Blizzard; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 641 (101 critical, 440 high, 88 medium, 4 low)
- **First seen:** 2022-04-07
- **Last seen:** 2026-10-04
- **Threat actors:** 171
- **Detection rules:** 314 (counts only; Blue tier and above)

## Key facts

- **ID:** T1566
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1566/

## Activity timeline

T1566 first appeared in tracked threats on 2022-04-07 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 215 reports, and 640 of the 641 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1566 Phishing is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix. Threadlinqs maps 641 of 2623 tracked threats (24.4%) to it; by severity that is 101 critical, 440 high, 88 medium, 4 low.

Threats that use T1566 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (400 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (364 threats), [T1204 User Execution](https://intel.threadlinqs.com/technique/T1204) (362 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (333 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (327 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

171 tracked threat actors appear in the threats that use T1566; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (15), [APT38](https://intel.threadlinqs.com/actor/APT38) (13), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (13), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (13), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (12).

## Mitigations

MITRE ATT&CK lists 6 mitigations for T1566.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)
- [M1054 Software Configuration](https://attack.mitre.org/mitigations/M1054/)

## Data sources

Telemetry that can reveal T1566, per MITRE ATT&CK.

- Application Log — Application Log Content
- File — File Creation
- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 15
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 13
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 13
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 13
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 12
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 12
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 11
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 11
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 10
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 9
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 8
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 8

## Tracked threats

The 30 most recent of 641 tracked threats that use T1566.

- [Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC](https://intel.threadlinqs.com/threat/TL-2026-2891) — medium — 2026-10-04
- [AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…](https://intel.threadlinqs.com/threat/TL-2026-2880) — high — 2026-10-03
- [Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+…](https://intel.threadlinqs.com/threat/TL-2026-2792) — medium — 2026-09-29
- [ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…](https://intel.threadlinqs.com/threat/TL-2026-2730) — high — 2026-09-28
- [Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2707) — medium — 2026-09-27
- [The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments](https://intel.threadlinqs.com/threat/TL-2026-2687) — high — 2026-09-27
- [UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2681) — critical — 2026-09-27
- [AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2668) — medium — 2026-09-26
- [SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…](https://intel.threadlinqs.com/threat/TL-2026-2642) — high — 2026-09-24
- [cPanel/WHM CalDAV/CardDAV and WP Toolkit Flaws Enable Cross-Account Access and Root Privilege Escalation…](https://intel.threadlinqs.com/threat/TL-2026-2636) — critical — 2026-09-23
- [Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials](https://intel.threadlinqs.com/threat/TL-2026-2627) — medium — 2026-09-23
- [Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas](https://intel.threadlinqs.com/threat/TL-2026-2571) — high — 2026-09-18
- [Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image…](https://intel.threadlinqs.com/threat/TL-2026-2566) — high — 2026-09-18
- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…](https://intel.threadlinqs.com/threat/TL-2026-2545) — high — 2026-09-16
- [CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)](https://intel.threadlinqs.com/threat/TL-2026-2533) — critical — 2026-09-16
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…](https://intel.threadlinqs.com/threat/TL-2026-2525) — high — 2026-09-15
- [Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding…](https://intel.threadlinqs.com/threat/TL-2026-2484) — high — 2026-09-13
- [Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…](https://intel.threadlinqs.com/threat/TL-2026-2466) — critical — 2026-09-12
- [Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonation](https://intel.threadlinqs.com/threat/TL-2026-2456) — high — 2026-09-12
- [Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2452) — high — 2026-09-11
- [LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Technique](https://intel.threadlinqs.com/threat/TL-2026-2441) — medium — 2026-09-11
- [ClickFix Lures Deploy MacSync Stealer to Bypass macOS Security](https://intel.threadlinqs.com/threat/TL-2026-2434) — high — 2026-09-10
- [Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teams](https://intel.threadlinqs.com/threat/TL-2026-2430) — medium — 2026-09-10
- [Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2416) — high — 2026-09-09
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…](https://intel.threadlinqs.com/threat/TL-2026-2407) — critical — 2026-09-08
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-2397) — high — 2026-09-08
- [Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence…](https://intel.threadlinqs.com/threat/TL-2026-2390) — high — 2026-09-08
- [Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2](https://intel.threadlinqs.com/threat/TL-2026-2368) — high — 2026-09-07

## Related CVEs

CVEs referenced by the tracked threats that use T1566, most frequent first.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-85880](https://intel.threadlinqs.com/cve/CVE-2026-85880)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2017-7921](https://intel.threadlinqs.com/cve/CVE-2017-7921)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)

## Detection coverage

Threadlinqs maintains 314 detection rules mapped to T1566 (SPL 111, KQL 101, Sigma 102). Rule content is available to Blue tier accounts and above; this page shows counts only.

314 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1566.001 Spearphishing Attachment](https://intel.threadlinqs.com/technique/T1566.001) — 194 tracked threats
- [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) — 308 tracked threats
- [T1566.003 Spearphishing via Service](https://intel.threadlinqs.com/technique/T1566.003) — 62 tracked threats
- [T1566.004 Spearphishing Voice](https://intel.threadlinqs.com/technique/T1566.004) — 50 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1566
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
