Activity timeline
T1598.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 13 reports, and 41 of the 41 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1598.003 Spearphishing Link is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of T1598 Phishing for Information. Threadlinqs maps 41 of 2623 tracked threats (1.6%) to it; by severity that is 2 critical, 19 high, 18 medium, 2 low.
Threats that use T1598.003 most often also use T1566.002 Spearphishing Link (39 threats), T1204.001 Malicious Link (31 threats), T1583.001 Domains (31 threats), T1684.001 Impersonation (28 threats), T1657 Financial Theft (18 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
11 tracked threat actors appear in the threats that use T1598.003; the most frequent are EvilTokens (2), Balonx (1), Ghost Stadium (1), Kali365 (1), ShinyHunters (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1598.003.
Data sources
Telemetry that can reveal T1598.003, per MITRE ATT&CK.
- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 41 tracked threats that use T1598.003.
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)high
- Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data…high
- Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breachmedium
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…medium
- Fake American Express "non-compliance" card-lock phishing campaign targets Australiansmedium
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…high
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google…medium
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Detailsmedium
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flowmedium
- Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via…medium
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltrationhigh
- Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capabilityhigh
- Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)medium
- BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypasscritical
- Invisible Unicode Tag Characters Used to Evade Phishing Detection in Financial Scam Campaignhigh
- Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Timelow
- Polymorphic Phishing Page at addresses.performs.vu Regenerates Its Code on Every Load, Defeating Hash-Based…medium
- Balonx Sistema PhaaS Campaign — AI Voice Calls and Fake Banking Pages Targeting Mexican Financial Institutionshigh
- Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)high
- Coldcard Security Audit Phishing Campaign Installs ConnectWise ScreenConnect RATcritical
- Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraudlow
- LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation"medium
- AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…high
- Russian FSB/GRU Actors (UNC5792, UNC4221) Phish Signal Backup Recovery Keys for Persistent Account Takeoverhigh
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Paymentsmedium
- Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectivenessmedium
- Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action…medium
- 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing…medium
- UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal Credentialshigh
- Phishing Campaign Impersonates LastPass and Bitwarden Security Alerts to Deliver Fake DocuSign Pagesmedium
Detection coverage
Threadlinqs maintains 87 detection rules mapped to T1598.003 (SPL 35, KQL 26, Sigma 26). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1598 Phishing for Information — 98 tracked threats at the technique level.