# T1593.001 Social Media

> As of 2026-10-05, T1593.001 (Social Media) appears in 11 tracked threats, first reported 2026-04-21 and most recently 2026-09-24, with linked actors including WageMole, APT38, Andariel; it most often appears alongside T1657 (Financial Theft).

- **Tracked threats:** 11 (1 critical, 7 high, 2 medium, 1 low)
- **First seen:** 2026-04-21
- **Last seen:** 2026-09-24
- **Threat actors:** 6
- **Detection rules:** 14 (counts only; Blue tier and above)

## Key facts

- **ID:** T1593.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Parent:** T1593
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1593/001/

## Activity timeline

T1593.001 first appeared in tracked threats on 2026-04-21 and was most recently reported on 2026-09-24. The busiest month was 2026-08 with 5 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1593.001 Social Media is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of [T1593 Search Open Websites/Domains](https://intel.threadlinqs.com/technique/T1593). Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 1 critical, 7 high, 2 medium, 1 low.

Threats that use T1593.001 most often also use [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (8 threats), [T1684.001 Impersonation](https://intel.threadlinqs.com/technique/T1684.001) (7 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (6 threats), [T1585.001 Social Media Accounts](https://intel.threadlinqs.com/technique/T1585.001) (6 threats), [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

6 tracked threat actors appear in the threats that use T1593.001; the most frequent are [WageMole](https://intel.threadlinqs.com/actor/WageMole) (2), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (1), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (1), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1593.001.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Threat actors using it

- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1
- [UNC5342](https://intel.threadlinqs.com/actor/UNC5342) — 1

## Tracked threats

11 tracked threats use T1593.001.

- [UK establishes National Centre for Information Defence to counter Russian state disinformation operations](https://intel.threadlinqs.com/threat/TL-2026-2638) — high — 2026-09-24
- ["Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAs](https://intel.threadlinqs.com/threat/TL-2026-2322) — high — 2026-09-03
- [Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicry](https://intel.threadlinqs.com/threat/TL-2026-2088) — high — 2026-08-20
- [Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chains](https://intel.threadlinqs.com/threat/TL-2026-2050) — high — 2026-08-17
- [BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detection](https://intel.threadlinqs.com/threat/TL-2026-1964) — medium — 2026-08-09
- [Ransomware Gangs Shift Targeting from Executives to Mid-Level IT/Finance Managers (Zscaler ThreatLabz…](https://intel.threadlinqs.com/threat/TL-2026-1955) — high — 2026-08-09
- [Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraud](https://intel.threadlinqs.com/threat/TL-2026-1826) — low — 2026-08-03
- [GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous…](https://intel.threadlinqs.com/threat/TL-2026-1610) — high — 2026-07-22
- [Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing) Persuasiveness Gap: 16.5% Compliance, 70.3%…](https://intel.threadlinqs.com/threat/TL-2026-1431) — medium — 2026-07-17
- [KelpDAO LayerZero Bridge Exploit — $292M rsETH Minted Against Non-Existent Burn (Lazarus Group, April 2026)](https://intel.threadlinqs.com/threat/TL-2026-0416) — critical — 2026-04-23
- [Void Dokkaebi (Contagious Interview / Famous Chollima) — DPRK Fake Job Interview Campaign Delivering…](https://intel.threadlinqs.com/threat/TL-2026-0402) — high — 2026-04-21

## Detection coverage

Threadlinqs maintains 14 detection rules mapped to T1593.001 (SPL 3, KQL 6, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.

14 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1593 Search Open Websites/Domains](https://intel.threadlinqs.com/technique/T1593) — 79 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1593.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
