Activity timeline
T1608.005 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 12 reports, and 39 of the 39 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1608.005 Link Target is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1608 Stage Capabilities. Threadlinqs maps 39 of 2623 tracked threats (1.5%) to it; by severity that is 1 critical, 21 high, 16 medium, 1 low.
Threats that use T1608.005 most often also use T1566.002 Spearphishing Link (34 threats), T1583.001 Domains (29 threats), T1204.001 Malicious Link (28 threats), T1684.001 Impersonation (27 threats), T1583.006 Web Services (22 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
9 tracked threat actors appear in the threats that use T1608.005; the most frequent are Kali365 (2), APT44 (1), Ghost Stadium (1), Kali365 PhaaS operators (1), Outsider Enterprise (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1608.005.
Data sources
Telemetry that can reveal T1608.005, per MITRE ATT&CK.
- Internet Scan — Response Content
Threat actors using it
Tracked threats
The 30 most recent of 39 tracked threats that use T1608.005.
- Fake American Express "non-compliance" card-lock phishing campaign targets Australiansmedium
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvestershigh
- Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…high
- Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac usershigh
- UK establishes National Centre for Information Defence to counter Russian state disinformation operationshigh
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentialsmedium
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google…medium
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Detailsmedium
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flowmedium
- Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via…medium
- ScreenConnect Backdoor Delivered via SSA-Impersonation Phishing Luremedium
- Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructurehigh
- Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visitmedium
- Polymorphic Phishing Page at addresses.performs.vu Regenerates Its Code on Every Load, Defeating Hash-Based…medium
- Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Accessmedium
- U.S. Defense Manufacturer IEH Corporation Breached via Phishing, Potential Export-Controlled Data Exposurehigh
- Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…high
- Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraudlow
- LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation"medium
- Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security Flaws Including 7 Critical Sandbox-Escape /…critical
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Paymentsmedium
- Check Point Q2 2026 Brand Phishing Report: Microsoft Leads at 23%, ChatGPT Enters Top 10 Impersonated Brandsmedium
- Google Ads MMC Sync Phishing Campaign Uses Fake Maintenance Notices for Credential Theftmedium
- Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts…high
- O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment via Live-Operator Phone Phishing to Hijack…high
- Browser-in-the-Browser Phishing Campaign Impersonates 34+ Brands' Job Postings to Steal Google Account…high
- CalPhishing: Phishing Campaign Abusing Microsoft 365 Groups and Outlook Calendar Invites for Persistent…high
- Zscaler ThreatLabz 2026 Report: Encrypted Phishing & AiTM/BiTM Initial-Access Campaigns Targeting the Public…high
- Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares[.]com /…high
- GHOST STADIUM — FIFA World Cup 2026 Phishing Operation: 4,300+ Fraudulent Domains and 300+ Cloned fifa.com…high
Detection coverage
Threadlinqs maintains 76 detection rules mapped to T1608.005 (SPL 22, KQL 24, Sigma 30). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1608 Stage Capabilities — 250 tracked threats at the technique level.