# T1598.003 Spearphishing Link

> As of 2026-10-05, T1598.003 (Spearphishing Link) appears in 41 tracked threats, first reported 2026-02-22 and most recently 2026-10-04, with linked actors including EvilTokens, Balonx, Ghost Stadium; it most often appears alongside T1566.002 (Spearphishing Link).

- **Tracked threats:** 41 (2 critical, 19 high, 18 medium, 2 low)
- **First seen:** 2026-02-22
- **Last seen:** 2026-10-04
- **Threat actors:** 11
- **Detection rules:** 87 (counts only; Blue tier and above)

## Key facts

- **ID:** T1598.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Parent:** T1598
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1598/003/

## Activity timeline

T1598.003 first appeared in tracked threats on 2026-02-22 and was most recently reported on 2026-10-04. The busiest month was 2026-09 with 13 reports, and 41 of the 41 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1598.003 Spearphishing Link is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of [T1598 Phishing for Information](https://intel.threadlinqs.com/technique/T1598). Threadlinqs maps 41 of 2623 tracked threats (1.6%) to it; by severity that is 2 critical, 19 high, 18 medium, 2 low.

Threats that use T1598.003 most often also use [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (39 threats), [T1204.001 Malicious Link](https://intel.threadlinqs.com/technique/T1204.001) (31 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (31 threats), [T1684.001 Impersonation](https://intel.threadlinqs.com/technique/T1684.001) (28 threats), [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (18 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

11 tracked threat actors appear in the threats that use T1598.003; the most frequent are [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens) (2), [Balonx](https://intel.threadlinqs.com/actor/Balonx) (1), [Ghost Stadium](https://intel.threadlinqs.com/actor/Ghost%20Stadium) (1), [Kali365](https://intel.threadlinqs.com/actor/Kali365) (1), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1598.003.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1054 Software Configuration](https://attack.mitre.org/mitigations/M1054/)

## Data sources

Telemetry that can reveal T1598.003, per MITRE ATT&CK.

- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens) — 2
- [Balonx](https://intel.threadlinqs.com/actor/Balonx) — 1
- [Ghost Stadium](https://intel.threadlinqs.com/actor/Ghost%20Stadium) — 1
- [Kali365](https://intel.threadlinqs.com/actor/Kali365) — 1
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1
- [Storm-2372](https://intel.threadlinqs.com/actor/Storm-2372) — 1
- [Storm-2755](https://intel.threadlinqs.com/actor/Storm-2755) — 1
- [UNC5792](https://intel.threadlinqs.com/actor/UNC5792) — 1
- [UTA0304](https://intel.threadlinqs.com/actor/UTA0304) — 1
- [UTA0307](https://intel.threadlinqs.com/actor/UTA0307) — 1
- [Unnamed](https://intel.threadlinqs.com/actor/Unnamed) — 1

## Tracked threats

The 30 most recent of 41 tracked threats that use T1598.003.

- [China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)](https://intel.threadlinqs.com/threat/TL-2026-2884) — high — 2026-10-04
- [Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data…](https://intel.threadlinqs.com/threat/TL-2026-2839) — high — 2026-10-02
- [Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breach](https://intel.threadlinqs.com/threat/TL-2026-2842) — medium — 2026-10-01
- [Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…](https://intel.threadlinqs.com/threat/TL-2026-2770) — medium — 2026-09-29
- [Fake American Express "non-compliance" card-lock phishing campaign targets Australians](https://intel.threadlinqs.com/threat/TL-2026-2758) — medium — 2026-09-29
- [Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…](https://intel.threadlinqs.com/threat/TL-2026-2595) — high — 2026-09-21
- [Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google…](https://intel.threadlinqs.com/threat/TL-2026-2567) — medium — 2026-09-18
- [Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details](https://intel.threadlinqs.com/threat/TL-2026-2562) — medium — 2026-09-18
- [Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow](https://intel.threadlinqs.com/threat/TL-2026-2556) — medium — 2026-09-18
- [Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via…](https://intel.threadlinqs.com/threat/TL-2026-2548) — medium — 2026-09-17
- [Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-2472) — high — 2026-09-13
- [Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability](https://intel.threadlinqs.com/threat/TL-2026-2468) — high — 2026-09-12
- [Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)](https://intel.threadlinqs.com/threat/TL-2026-2451) — medium — 2026-09-11
- [BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2374) — critical — 2026-09-07
- [Invisible Unicode Tag Characters Used to Evade Phishing Detection in Financial Scam Campaign](https://intel.threadlinqs.com/threat/TL-2026-2331) — high — 2026-09-04
- [Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time](https://intel.threadlinqs.com/threat/TL-2026-2289) — low — 2026-09-02
- [Polymorphic Phishing Page at addresses.performs.vu Regenerates Its Code on Every Load, Defeating Hash-Based…](https://intel.threadlinqs.com/threat/TL-2026-2183) — medium — 2026-08-28
- [Balonx Sistema PhaaS Campaign — AI Voice Calls and Fake Banking Pages Targeting Mexican Financial Institutions](https://intel.threadlinqs.com/threat/TL-2026-2072) — high — 2026-08-19
- [Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)](https://intel.threadlinqs.com/threat/TL-2026-2024) — high — 2026-08-15
- [Coldcard Security Audit Phishing Campaign Installs ConnectWise ScreenConnect RAT](https://intel.threadlinqs.com/threat/TL-2026-1896) — critical — 2026-08-05
- [Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraud](https://intel.threadlinqs.com/threat/TL-2026-1826) — low — 2026-08-03
- [LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation"](https://intel.threadlinqs.com/threat/TL-2026-1818) — medium — 2026-08-02
- [AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…](https://intel.threadlinqs.com/threat/TL-2026-1777) — high — 2026-07-30
- [Russian FSB/GRU Actors (UNC5792, UNC4221) Phish Signal Backup Recovery Keys for Persistent Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1814) — high — 2026-07-29
- [Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments](https://intel.threadlinqs.com/threat/TL-2026-1765) — medium — 2026-07-29
- [Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectiveness](https://intel.threadlinqs.com/threat/TL-2026-1702) — medium — 2026-07-25
- [Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action…](https://intel.threadlinqs.com/threat/TL-2026-1611) — medium — 2026-07-22
- [700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing…](https://intel.threadlinqs.com/threat/TL-2026-1519) — medium — 2026-07-19
- [UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal Credentials](https://intel.threadlinqs.com/threat/TL-2026-1509) — high — 2026-07-19
- [Phishing Campaign Impersonates LastPass and Bitwarden Security Alerts to Deliver Fake DocuSign Pages](https://intel.threadlinqs.com/threat/TL-2026-1315) — medium — 2026-07-14

## Related CVEs

CVEs referenced by the tracked threats that use T1598.003, most frequent first.

- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)

## Detection coverage

Threadlinqs maintains 87 detection rules mapped to T1598.003 (SPL 35, KQL 26, Sigma 26). Rule content is available to Blue tier accounts and above; this page shows counts only.

87 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1598 Phishing for Information](https://intel.threadlinqs.com/technique/T1598) — 98 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1598.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
