# T1589.002 Email Addresses

> As of 2026-10-05, T1589.002 (Email Addresses) appears in 51 tracked threats, first reported 2026-02-22 and most recently 2026-09-23, with linked actors including UNK_OutFlareAZ, EvilTokens, Ghost Stadium; it most often appears alongside T1566.002 (Spearphishing Link).

- **Tracked threats:** 51 (6 critical, 28 high, 17 medium)
- **First seen:** 2026-02-22
- **Last seen:** 2026-09-23
- **Threat actors:** 19
- **Detection rules:** 74 (counts only; Blue tier and above)

## Key facts

- **ID:** T1589.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Parent:** T1589
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1589/002/

## Activity timeline

T1589.002 first appeared in tracked threats on 2026-02-22 and was most recently reported on 2026-09-23. The busiest month was 2026-07 with 20 reports, and 51 of the 51 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1589.002 Email Addresses is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of [T1589 Gather Victim Identity Information](https://intel.threadlinqs.com/technique/T1589). Threadlinqs maps 51 of 2623 tracked threats (1.9%) to it; by severity that is 6 critical, 28 high, 17 medium.

Threats that use T1589.002 most often also use [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (36 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (30 threats), [T1204.001 Malicious Link](https://intel.threadlinqs.com/technique/T1204.001) (26 threats), [T1684.001 Impersonation](https://intel.threadlinqs.com/technique/T1684.001) (25 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (19 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

19 tracked threat actors appear in the threats that use T1589.002; the most frequent are [UNK_OutFlareAZ](https://intel.threadlinqs.com/actor/UNK_OutFlareAZ) (2), [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens) (1), [Ghost Stadium](https://intel.threadlinqs.com/actor/Ghost%20Stadium) (1), [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) (1), [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1589.002.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1589.002, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content

## Threat actors using it

- [UNK_OutFlareAZ](https://intel.threadlinqs.com/actor/UNK_OutFlareAZ) — 2
- [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens) — 1
- [Ghost Stadium](https://intel.threadlinqs.com/actor/Ghost%20Stadium) — 1
- [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) — 1
- [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) — 1
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 1
- [Payouts King](https://intel.threadlinqs.com/actor/Payouts%20King) — 1
- [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) — 1
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1
- [Silent Ransom Group](https://intel.threadlinqs.com/actor/Silent%20Ransom%20Group) — 1
- [Storm-1167](https://intel.threadlinqs.com/actor/Storm-1167) — 1

## Tracked threats

The 30 most recent of 51 tracked threats that use T1589.002.

- [cPanel/WHM CalDAV/CardDAV and WP Toolkit Flaws Enable Cross-Account Access and Root Privilege Escalation…](https://intel.threadlinqs.com/threat/TL-2026-2636) — critical — 2026-09-23
- [Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…](https://intel.threadlinqs.com/threat/TL-2026-2595) — high — 2026-09-21
- [Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image…](https://intel.threadlinqs.com/threat/TL-2026-2566) — high — 2026-09-18
- [OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 /…](https://intel.threadlinqs.com/threat/TL-2026-2476) — high — 2026-09-13
- [Trezor Warns of Phishing Attacks After Third-Party Email Provider Breach ("STM32 Entropy Vulnerability" Lure)](https://intel.threadlinqs.com/threat/TL-2026-2432) — medium — 2026-09-10
- [Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2372) — high — 2026-09-07
- [DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Network](https://intel.threadlinqs.com/threat/TL-2026-2309) — medium — 2026-09-03
- [Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations](https://intel.threadlinqs.com/threat/TL-2026-2263) — medium — 2026-08-31
- [Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit](https://intel.threadlinqs.com/threat/TL-2026-2246) — medium — 2026-08-30
- [ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and…](https://intel.threadlinqs.com/threat/TL-2026-2208) — critical — 2026-08-29
- [Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion](https://intel.threadlinqs.com/threat/TL-2026-2176) — high — 2026-08-28
- [AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock Bypass](https://intel.threadlinqs.com/threat/TL-2026-2164) — high — 2026-08-27
- [CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…](https://intel.threadlinqs.com/threat/TL-2026-2161) — high — 2026-08-26
- [Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Access](https://intel.threadlinqs.com/threat/TL-2026-2129) — medium — 2026-08-24
- [ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers](https://intel.threadlinqs.com/threat/TL-2026-2007) — medium — 2026-08-13
- [Mass Phishing and Scam Campaign Abuses 450+ Compromised Google Workspace Accounts in the Education Sector](https://intel.threadlinqs.com/threat/TL-2026-2004) — high — 2026-08-13
- [BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detection](https://intel.threadlinqs.com/threat/TL-2026-1964) — medium — 2026-08-09
- [U.S. Defense Manufacturer IEH Corporation Breached via Phishing, Potential Export-Controlled Data Exposure](https://intel.threadlinqs.com/threat/TL-2026-1960) — high — 2026-08-09
- [Coldcard Security Audit Phishing Campaign Installs ConnectWise ScreenConnect RAT](https://intel.threadlinqs.com/threat/TL-2026-1896) — critical — 2026-08-05
- [LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation"](https://intel.threadlinqs.com/threat/TL-2026-1818) — medium — 2026-08-02
- [OAuth Consent Phishing Abuses Microsoft's Legitimate Login System to Harvest Microsoft 365 Tokens](https://intel.threadlinqs.com/threat/TL-2026-1778) — high — 2026-07-30
- [AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…](https://intel.threadlinqs.com/threat/TL-2026-1777) — high — 2026-07-30
- [Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments](https://intel.threadlinqs.com/threat/TL-2026-1765) — medium — 2026-07-29
- [Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…](https://intel.threadlinqs.com/threat/TL-2026-1763) — critical — 2026-07-29
- [Check Point Q2 2026 Brand Phishing Report: Microsoft Leads at 23%, ChatGPT Enters Top 10 Impersonated Brands](https://intel.threadlinqs.com/threat/TL-2026-1731) — medium — 2026-07-27
- [Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts](https://intel.threadlinqs.com/threat/TL-2026-1641) — high — 2026-07-22
- [Apple Hide My Email Flaw Exposed Real Email Addresses via Spam-Filter/Bounce Triggering](https://intel.threadlinqs.com/threat/TL-2026-1628) — critical — 2026-07-22
- [Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action…](https://intel.threadlinqs.com/threat/TL-2026-1611) — medium — 2026-07-22
- [GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous…](https://intel.threadlinqs.com/threat/TL-2026-1610) — high — 2026-07-22
- ["The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365)…](https://intel.threadlinqs.com/threat/TL-2026-1593) — high — 2026-07-21

## Related CVEs

CVEs referenced by the tracked threats that use T1589.002, most frequent first.

- [CVE-2026-42897](https://intel.threadlinqs.com/cve/CVE-2026-42897)
- [CVE-2026-68490](https://intel.threadlinqs.com/cve/CVE-2026-68490)

## Detection coverage

Threadlinqs maintains 74 detection rules mapped to T1589.002 (SPL 26, KQL 28, Sigma 20). Rule content is available to Blue tier accounts and above; this page shows counts only.

74 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1589 Gather Victim Identity Information](https://intel.threadlinqs.com/technique/T1589) — 228 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1589.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
