Activity timeline
T1598.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 8 reports, and 18 of the 18 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1598.004 Spearphishing Voice is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of T1598 Phishing for Information. Threadlinqs maps 18 of 2623 tracked threats (0.7%) to it; by severity that is 14 high, 3 medium, 1 low.
Threats that use T1598.004 most often also use T1657 Financial Theft (12 threats), T1684.001 Impersonation (12 threats), T1566.002 Spearphishing Link (11 threats), T1204.001 Malicious Link (9 threats), T1566.004 Spearphishing Voice (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
9 tracked threat actors appear in the threats that use T1598.004; the most frequent are Scattered Spider (2), ALPHV (1), BlackCat (1), Kali365 PhaaS operators (1), Luna Moth (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1598.004.
Data sources
Telemetry that can reveal T1598.004, per MITRE ATT&CK.
- Application Log — Application Log Content
Threat actors using it
Tracked threats
18 tracked threats use T1598.004.
- Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Timelow
- Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusionhigh
- "The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware…high
- Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Accessmedium
- Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicryhigh
- Pokémon Center Confirms Customer Data Breach via CEVA Logistics Supply-Chain Compromisehigh
- Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)high
- ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customersmedium
- Copybara Android RAT Delivered via Fake N26 Support Vishing Callshigh
- Russian FSB/GRU Actors (UNC5792, UNC4221) Phish Signal Backup Recovery Keys for Persistent Account Takeoverhigh
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storagehigh
- Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accountshigh
- Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattackhigh
- Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and…high
- Callback Phishing Campaign Impersonates Robinhood With Fake Sign-In Alerts (LevelBlue SpiderLabs)high
- Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise…high
- ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens…high
- Malwarebytes Subscription Renewal Scam — Fake-Invoice / Refund-Bait Callback Phishing Campaign ("Account…medium
Detection coverage
Threadlinqs maintains 31 detection rules mapped to T1598.004 (SPL 12, KQL 9, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1598 Phishing for Information — 98 tracked threats at the technique level.