Activity timeline
T1598 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 37 reports, and 98 of the 98 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1598 Phishing for Information is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix. Threadlinqs maps 98 of 2623 tracked threats (3.7%) to it; by severity that is 12 critical, 64 high, 20 medium, 2 low.
Threats that use T1598 most often also use T1566 Phishing (83 threats), T1583 Acquire Infrastructure (60 threats), T1589 Gather Victim Identity Information (50 threats), T1027 Obfuscated Files or Information (46 threats), T1204 User Execution (46 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
54 tracked threat actors appear in the threats that use T1598; the most frequent are ShinyHunters (6), Scattered LAPSUS$ Hunters (4), The Com (4), UNC6040 (4), Chaos (3).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1598.
Data sources
Telemetry that can reveal T1598, per MITRE ATT&CK.
- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 98 tracked threats that use T1598.
- Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARCmedium
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+…medium
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvestershigh
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…medium
- Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Datahigh
- Revolut Discloses Data Breach via Government-Impersonation Social Engineering, Exposing Customer Financial…high
- ASCII Smuggling Phishing Campaign Uses Invisible Unicode Tags-Block Characters to Evade Filters, Targeting…high
- Chaos Ransomware Claims MacAllister (macallister.com) — 75GB Data Exfiltration Claimed, Leadership Refused…high
- Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…high
- AnonyMousKIT: AI-Powered Phishing-as-a-Service Platform Stealing Apple IDs from Stolen iPhoneshigh
- Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)high
- Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicryhigh
- ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customersmedium
- BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detectionmedium
- AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671…high
- AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social…critical
- Sumner County Schools (TN) Network Intrusion Delays 2026-27 School Year, Scope of Data Exposure Still…medium
- Mon General Hospital (West Virginia) Notifies Patients After May 2026 Phishing Attack Compromises Employee…high
- Copybara Android RAT Delivered via Fake N26 Support Vishing Callshigh
- North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum…high
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeyshigh
- Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and…high
- Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…high
- Sextortion Scammers Impersonate ShinyHunters, Exploit Leaked Breach Data for Bitcoin Extortionlow
- Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectivenessmedium
- ShinyHunters-Impersonation Sextortion Scam Abuses Emails From 8 Prior Data Leaks, Demands $2,000low
- BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…high
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edgehigh
- Chaos Ransomware Group Deploys msaRAT — Rust-based Malware Abusing Chrome/Edge as C2 Covert Channelhigh
- Apple Hide My Email Flaw Exposed Real Email Addresses via Spam-Filter/Bounce Triggeringcritical
Detection coverage
Threadlinqs maintains 66 detection rules mapped to T1598 (SPL 20, KQL 26, Sigma 20). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1598.001 Spearphishing Service — 4 tracked threats
- T1598.002 Spearphishing Attachment — 4 tracked threats
- T1598.003 Spearphishing Link — 41 tracked threats
- T1598.004 Spearphishing Voice — 18 tracked threats