# T1608.005 Link Target

> As of 2026-10-05, T1608.005 (Link Target) appears in 39 tracked threats, first reported 2026-02-16 and most recently 2026-09-29, with linked actors including Kali365, APT44, Ghost Stadium; it most often appears alongside T1566.002 (Spearphishing Link).

- **Tracked threats:** 39 (1 critical, 21 high, 16 medium, 1 low)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-29
- **Threat actors:** 9
- **Detection rules:** 76 (counts only; Blue tier and above)

## Key facts

- **ID:** T1608.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1608
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1608/005/

## Activity timeline

T1608.005 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-29. The busiest month was 2026-09 with 12 reports, and 39 of the 39 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1608.005 Link Target is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1608 Stage Capabilities](https://intel.threadlinqs.com/technique/T1608). Threadlinqs maps 39 of 2623 tracked threats (1.5%) to it; by severity that is 1 critical, 21 high, 16 medium, 1 low.

Threats that use T1608.005 most often also use [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (34 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (29 threats), [T1204.001 Malicious Link](https://intel.threadlinqs.com/technique/T1204.001) (28 threats), [T1684.001 Impersonation](https://intel.threadlinqs.com/technique/T1684.001) (27 threats), [T1583.006 Web Services](https://intel.threadlinqs.com/technique/T1583.006) (22 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1608.005; the most frequent are [Kali365](https://intel.threadlinqs.com/actor/Kali365) (2), [APT44](https://intel.threadlinqs.com/actor/APT44) (1), [Ghost Stadium](https://intel.threadlinqs.com/actor/Ghost%20Stadium) (1), [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) (1), [Outsider Enterprise](https://intel.threadlinqs.com/actor/Outsider%20Enterprise) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1608.005.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1608.005, per MITRE ATT&CK.

- Internet Scan — Response Content

## Threat actors using it

- [Kali365](https://intel.threadlinqs.com/actor/Kali365) — 2
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 1
- [Ghost Stadium](https://intel.threadlinqs.com/actor/Ghost%20Stadium) — 1
- [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) — 1
- [Outsider Enterprise](https://intel.threadlinqs.com/actor/Outsider%20Enterprise) — 1
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 1
- [Storm-2755](https://intel.threadlinqs.com/actor/Storm-2755) — 1
- [Turla](https://intel.threadlinqs.com/actor/Turla) — 1
- [UNC6692](https://intel.threadlinqs.com/actor/UNC6692) — 1

## Tracked threats

The 30 most recent of 39 tracked threats that use T1608.005.

- [Fake American Express "non-compliance" card-lock phishing campaign targets Australians](https://intel.threadlinqs.com/threat/TL-2026-2758) — medium — 2026-09-29
- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — high — 2026-09-27
- [Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…](https://intel.threadlinqs.com/threat/TL-2026-2673) — high — 2026-09-26
- [Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac users](https://intel.threadlinqs.com/threat/TL-2026-2651) — high — 2026-09-25
- [UK establishes National Centre for Information Defence to counter Russian state disinformation operations](https://intel.threadlinqs.com/threat/TL-2026-2638) — high — 2026-09-24
- [Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials](https://intel.threadlinqs.com/threat/TL-2026-2626) — medium — 2026-09-23
- [Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google…](https://intel.threadlinqs.com/threat/TL-2026-2567) — medium — 2026-09-18
- [Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details](https://intel.threadlinqs.com/threat/TL-2026-2562) — medium — 2026-09-18
- [Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow](https://intel.threadlinqs.com/threat/TL-2026-2556) — medium — 2026-09-18
- [Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via…](https://intel.threadlinqs.com/threat/TL-2026-2548) — medium — 2026-09-17
- [ScreenConnect Backdoor Delivered via SSA-Impersonation Phishing Lure](https://intel.threadlinqs.com/threat/TL-2026-2594) — medium — 2026-09-14
- [Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2372) — high — 2026-09-07
- [Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit](https://intel.threadlinqs.com/threat/TL-2026-2246) — medium — 2026-08-30
- [Polymorphic Phishing Page at addresses.performs.vu Regenerates Its Code on Every Load, Defeating Hash-Based…](https://intel.threadlinqs.com/threat/TL-2026-2183) — medium — 2026-08-28
- [Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Access](https://intel.threadlinqs.com/threat/TL-2026-2129) — medium — 2026-08-24
- [U.S. Defense Manufacturer IEH Corporation Breached via Phishing, Potential Export-Controlled Data Exposure](https://intel.threadlinqs.com/threat/TL-2026-1960) — high — 2026-08-09
- [Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…](https://intel.threadlinqs.com/threat/TL-2026-1930) — high — 2026-08-07
- [Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraud](https://intel.threadlinqs.com/threat/TL-2026-1826) — low — 2026-08-03
- [LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation"](https://intel.threadlinqs.com/threat/TL-2026-1818) — medium — 2026-08-02
- [Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security Flaws Including 7 Critical Sandbox-Escape /…](https://intel.threadlinqs.com/threat/TL-2026-1770) — critical — 2026-07-30
- [Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments](https://intel.threadlinqs.com/threat/TL-2026-1765) — medium — 2026-07-29
- [Check Point Q2 2026 Brand Phishing Report: Microsoft Leads at 23%, ChatGPT Enters Top 10 Impersonated Brands](https://intel.threadlinqs.com/threat/TL-2026-1731) — medium — 2026-07-27
- [Google Ads MMC Sync Phishing Campaign Uses Fake Maintenance Notices for Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-2535) — medium — 2026-07-21
- [Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts…](https://intel.threadlinqs.com/threat/TL-2026-1479) — high — 2026-07-18
- [O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment via Live-Operator Phone Phishing to Hijack…](https://intel.threadlinqs.com/threat/TL-2026-1186) — high — 2026-07-10
- [Browser-in-the-Browser Phishing Campaign Impersonates 34+ Brands' Job Postings to Steal Google Account…](https://intel.threadlinqs.com/threat/TL-2026-1139) — high — 2026-07-06
- [CalPhishing: Phishing Campaign Abusing Microsoft 365 Groups and Outlook Calendar Invites for Persistent…](https://intel.threadlinqs.com/threat/TL-2026-0930) — high — 2026-06-23
- [Zscaler ThreatLabz 2026 Report: Encrypted Phishing & AiTM/BiTM Initial-Access Campaigns Targeting the Public…](https://intel.threadlinqs.com/threat/TL-2026-0878) — high — 2026-06-19
- [Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares\[.\]com /…](https://intel.threadlinqs.com/threat/TL-2026-0799) — high — 2026-06-15
- [GHOST STADIUM — FIFA World Cup 2026 Phishing Operation: 4,300+ Fraudulent Domains and 300+ Cloned fifa.com…](https://intel.threadlinqs.com/threat/TL-2026-0704) — high — 2026-06-07

## Related CVEs

CVEs referenced by the tracked threats that use T1608.005, most frequent first.

- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)

## Detection coverage

Threadlinqs maintains 76 detection rules mapped to T1608.005 (SPL 22, KQL 24, Sigma 30). Rule content is available to Blue tier accounts and above; this page shows counts only.

76 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1608 Stage Capabilities](https://intel.threadlinqs.com/technique/T1608) — 250 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1608.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
