# T1598 Phishing for Information

> As of 2026-10-05, T1598 (Phishing for Information) appears in 98 tracked threats, first reported 2026-01-19 and most recently 2026-10-04, with linked actors including ShinyHunters, Scattered LAPSUS$ Hunters, The Com; it most often appears alongside T1566 (Phishing).

- **Tracked threats:** 98 (12 critical, 64 high, 20 medium, 2 low)
- **First seen:** 2026-01-19
- **Last seen:** 2026-10-04
- **Threat actors:** 54
- **Detection rules:** 66 (counts only; Blue tier and above)

## Key facts

- **ID:** T1598
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1598/

## Activity timeline

T1598 first appeared in tracked threats on 2026-01-19 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 37 reports, and 98 of the 98 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1598 Phishing for Information is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix. Threadlinqs maps 98 of 2623 tracked threats (3.7%) to it; by severity that is 12 critical, 64 high, 20 medium, 2 low.

Threats that use T1598 most often also use [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) (83 threats), [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) (60 threats), [T1589 Gather Victim Identity Information](https://intel.threadlinqs.com/technique/T1589) (50 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (46 threats), [T1204 User Execution](https://intel.threadlinqs.com/technique/T1204) (46 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

54 tracked threat actors appear in the threats that use T1598; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (6), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (4), [The Com](https://intel.threadlinqs.com/actor/The%20Com) (4), [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) (4), [Chaos](https://intel.threadlinqs.com/actor/Chaos) (3).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1598.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1054 Software Configuration](https://attack.mitre.org/mitigations/M1054/)

## Data sources

Telemetry that can reveal T1598, per MITRE ATT&CK.

- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 6
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 4
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 4
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 4
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 3
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 3
- [Storm-2372](https://intel.threadlinqs.com/actor/Storm-2372) — 3
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 3
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Kali365](https://intel.threadlinqs.com/actor/Kali365) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2

## Tracked threats

The 30 most recent of 98 tracked threats that use T1598.

- [Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC](https://intel.threadlinqs.com/threat/TL-2026-2891) — medium — 2026-10-04
- [Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+…](https://intel.threadlinqs.com/threat/TL-2026-2792) — medium — 2026-09-29
- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — high — 2026-09-27
- [AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2668) — medium — 2026-09-26
- [Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data](https://intel.threadlinqs.com/threat/TL-2026-2550) — high — 2026-09-17
- [Revolut Discloses Data Breach via Government-Impersonation Social Engineering, Exposing Customer Financial…](https://intel.threadlinqs.com/threat/TL-2026-2498) — high — 2026-09-14
- [ASCII Smuggling Phishing Campaign Uses Invisible Unicode Tags-Block Characters to Evade Filters, Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2338) — high — 2026-09-05
- [Chaos Ransomware Claims MacAllister (macallister.com) — 75GB Data Exfiltration Claimed, Leadership Refused…](https://intel.threadlinqs.com/threat/TL-2026-2209) — high — 2026-08-28
- [Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…](https://intel.threadlinqs.com/threat/TL-2026-2170) — high — 2026-08-26
- [AnonyMousKIT: AI-Powered Phishing-as-a-Service Platform Stealing Apple IDs from Stolen iPhones](https://intel.threadlinqs.com/threat/TL-2026-2141) — high — 2026-08-24
- [Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)](https://intel.threadlinqs.com/threat/TL-2026-2109) — high — 2026-08-21
- [Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicry](https://intel.threadlinqs.com/threat/TL-2026-2088) — high — 2026-08-20
- [ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers](https://intel.threadlinqs.com/threat/TL-2026-2007) — medium — 2026-08-13
- [BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detection](https://intel.threadlinqs.com/threat/TL-2026-1964) — medium — 2026-08-09
- [AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671…](https://intel.threadlinqs.com/threat/TL-2026-1963) — high — 2026-08-09
- [AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social…](https://intel.threadlinqs.com/threat/TL-2026-1900) — critical — 2026-08-04
- [Sumner County Schools (TN) Network Intrusion Delays 2026-27 School Year, Scope of Data Exposure Still…](https://intel.threadlinqs.com/threat/TL-2026-1824) — medium — 2026-08-02
- [Mon General Hospital (West Virginia) Notifies Patients After May 2026 Phishing Attack Compromises Employee…](https://intel.threadlinqs.com/threat/TL-2026-1810) — high — 2026-08-01
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum…](https://intel.threadlinqs.com/threat/TL-2026-1794) — high — 2026-07-31
- [Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys](https://intel.threadlinqs.com/threat/TL-2026-1793) — high — 2026-07-31
- [Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and…](https://intel.threadlinqs.com/threat/TL-2026-1741) — high — 2026-07-28
- [Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…](https://intel.threadlinqs.com/threat/TL-2026-1734) — high — 2026-07-28
- [Sextortion Scammers Impersonate ShinyHunters, Exploit Leaked Breach Data for Bitcoin Extortion](https://intel.threadlinqs.com/threat/TL-2026-1722) — low — 2026-07-27
- [Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectiveness](https://intel.threadlinqs.com/threat/TL-2026-1702) — medium — 2026-07-25
- [ShinyHunters-Impersonation Sextortion Scam Abuses Emails From 8 Prior Data Leaks, Demands $2,000](https://intel.threadlinqs.com/threat/TL-2026-1685) — low — 2026-07-25
- [BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…](https://intel.threadlinqs.com/threat/TL-2026-1678) — high — 2026-07-24
- [Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge](https://intel.threadlinqs.com/threat/TL-2026-1663) — high — 2026-07-23
- [Chaos Ransomware Group Deploys msaRAT — Rust-based Malware Abusing Chrome/Edge as C2 Covert Channel](https://intel.threadlinqs.com/threat/TL-2026-1656) — high — 2026-07-23
- [Apple Hide My Email Flaw Exposed Real Email Addresses via Spam-Filter/Bounce Triggering](https://intel.threadlinqs.com/threat/TL-2026-1628) — critical — 2026-07-22

## Related CVEs

CVEs referenced by the tracked threats that use T1598, most frequent first.

- [CVE-2019-3568](https://intel.threadlinqs.com/cve/CVE-2019-3568)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2025-32711](https://intel.threadlinqs.com/cve/CVE-2025-32711)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-59382](https://intel.threadlinqs.com/cve/CVE-2025-59382)
- [CVE-2025-62858](https://intel.threadlinqs.com/cve/CVE-2025-62858)
- [CVE-2025-66273](https://intel.threadlinqs.com/cve/CVE-2025-66273)
- [CVE-2025-66279](https://intel.threadlinqs.com/cve/CVE-2025-66279)
- [CVE-2025-66280](https://intel.threadlinqs.com/cve/CVE-2025-66280)
- [CVE-2025-66281](https://intel.threadlinqs.com/cve/CVE-2025-66281)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2026-22893](https://intel.threadlinqs.com/cve/CVE-2026-22893)
- [CVE-2026-24724](https://intel.threadlinqs.com/cve/CVE-2026-24724)
- [CVE-2026-26239](https://intel.threadlinqs.com/cve/CVE-2026-26239)
- [CVE-2026-26240](https://intel.threadlinqs.com/cve/CVE-2026-26240)
- [CVE-2026-26241](https://intel.threadlinqs.com/cve/CVE-2026-26241)
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)

## Detection coverage

Threadlinqs maintains 66 detection rules mapped to T1598 (SPL 20, KQL 26, Sigma 20). Rule content is available to Blue tier accounts and above; this page shows counts only.

66 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1598.001 Spearphishing Service — 4 tracked threats
- T1598.002 Spearphishing Attachment — 4 tracked threats
- [T1598.003 Spearphishing Link](https://intel.threadlinqs.com/technique/T1598.003) — 41 tracked threats
- [T1598.004 Spearphishing Voice](https://intel.threadlinqs.com/technique/T1598.004) — 18 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1598
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
