# T1598.004 Spearphishing Voice

> As of 2026-10-05, T1598.004 (Spearphishing Voice) appears in 18 tracked threats, first reported 2026-06-24 and most recently 2026-09-02, with linked actors including Scattered Spider, ALPHV, BlackCat; it most often appears alongside T1657 (Financial Theft).

- **Tracked threats:** 18 (14 high, 3 medium, 1 low)
- **First seen:** 2026-06-24
- **Last seen:** 2026-09-02
- **Threat actors:** 9
- **Detection rules:** 31 (counts only; Blue tier and above)

## Key facts

- **ID:** T1598.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Parent:** T1598
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1598/004/

## Activity timeline

T1598.004 first appeared in tracked threats on 2026-06-24 and was most recently reported on 2026-09-02. The busiest month was 2026-07 with 8 reports, and 18 of the 18 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1598.004 Spearphishing Voice is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of [T1598 Phishing for Information](https://intel.threadlinqs.com/technique/T1598). Threadlinqs maps 18 of 2623 tracked threats (0.7%) to it; by severity that is 14 high, 3 medium, 1 low.

Threats that use T1598.004 most often also use [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (12 threats), [T1684.001 Impersonation](https://intel.threadlinqs.com/technique/T1684.001) (12 threats), [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (11 threats), [T1204.001 Malicious Link](https://intel.threadlinqs.com/technique/T1204.001) (9 threats), [T1566.004 Spearphishing Voice](https://intel.threadlinqs.com/technique/T1566.004) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1598.004; the most frequent are [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (2), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (1), [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) (1), [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) (1), [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1598.004.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)

## Data sources

Telemetry that can reveal T1598.004, per MITRE ATT&CK.

- Application Log — Application Log Content

## Threat actors using it

- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 2
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 1
- [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) — 1
- [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) — 1
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1
- [Silent Ransom Group](https://intel.threadlinqs.com/actor/Silent%20Ransom%20Group) — 1
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 1
- [UNC5792](https://intel.threadlinqs.com/actor/UNC5792) — 1

## Tracked threats

18 tracked threats use T1598.004.

- [Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time](https://intel.threadlinqs.com/threat/TL-2026-2289) — low — 2026-09-02
- [Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion](https://intel.threadlinqs.com/threat/TL-2026-2176) — high — 2026-08-28
- ["The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware…](https://intel.threadlinqs.com/threat/TL-2026-2155) — high — 2026-08-26
- [Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Access](https://intel.threadlinqs.com/threat/TL-2026-2129) — medium — 2026-08-24
- [Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicry](https://intel.threadlinqs.com/threat/TL-2026-2088) — high — 2026-08-20
- [Pokémon Center Confirms Customer Data Breach via CEVA Logistics Supply-Chain Compromise](https://intel.threadlinqs.com/threat/TL-2026-2054) — high — 2026-08-18
- [Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)](https://intel.threadlinqs.com/threat/TL-2026-2024) — high — 2026-08-15
- [ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers](https://intel.threadlinqs.com/threat/TL-2026-2007) — medium — 2026-08-13
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [Russian FSB/GRU Actors (UNC5792, UNC4221) Phish Signal Backup Recovery Keys for Persistent Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1814) — high — 2026-07-29
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — high — 2026-07-26
- [Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts](https://intel.threadlinqs.com/threat/TL-2026-1641) — high — 2026-07-22
- [Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack](https://intel.threadlinqs.com/threat/TL-2026-1429) — high — 2026-07-17
- [Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and…](https://intel.threadlinqs.com/threat/TL-2026-1347) — high — 2026-07-15
- [Callback Phishing Campaign Impersonates Robinhood With Fake Sign-In Alerts (LevelBlue SpiderLabs)](https://intel.threadlinqs.com/threat/TL-2026-1171) — high — 2026-07-10
- [Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1161) — high — 2026-07-10
- [ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens…](https://intel.threadlinqs.com/threat/TL-2026-1037) — high — 2026-07-01
- [Malwarebytes Subscription Renewal Scam — Fake-Invoice / Refund-Bait Callback Phishing Campaign ("Account…](https://intel.threadlinqs.com/threat/TL-2026-0936) — medium — 2026-06-24

## Related CVEs

CVEs referenced by the tracked threats that use T1598.004, most frequent first.

- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)

## Detection coverage

Threadlinqs maintains 31 detection rules mapped to T1598.004 (SPL 12, KQL 9, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

31 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1598 Phishing for Information](https://intel.threadlinqs.com/technique/T1598) — 98 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1598.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
