Activity timeline
T1593.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 5 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1593.001 Social Media is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of T1593 Search Open Websites/Domains. Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 1 critical, 7 high, 2 medium, 1 low.
Threats that use T1593.001 most often also use T1657 Financial Theft (8 threats), T1684.001 Impersonation (7 threats), T1036.005 Match Legitimate Resource Name or Location (6 threats), T1585.001 Social Media Accounts (6 threats), T1566.002 Spearphishing Link (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
6 tracked threat actors appear in the threats that use T1593.001; the most frequent are WageMole (2), APT38 (1), Andariel (1), Contagious Interview (1), Lazarus Group (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1593.001.
Threat actors using it
Tracked threats
11 tracked threats use T1593.001.
- UK establishes National Centre for Information Defence to counter Russian state disinformation operationshigh
- "Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAshigh
- Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicryhigh
- Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chainshigh
- BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detectionmedium
- Ransomware Gangs Shift Targeting from Executives to Mid-Level IT/Finance Managers (Zscaler ThreatLabz…high
- Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraudlow
- GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous…high
- Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing) Persuasiveness Gap: 16.5% Compliance, 70.3%…medium
- KelpDAO LayerZero Bridge Exploit — $292M rsETH Minted Against Non-Existent Burn (Lazarus Group, April 2026)critical
- Void Dokkaebi (Contagious Interview / Famous Chollima) — DPRK Fake Job Interview Campaign Delivering…high
Detection coverage
Threadlinqs maintains 14 detection rules mapped to T1593.001 (SPL 3, KQL 6, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1593 Search Open Websites/Domains — 79 tracked threats at the technique level.