Threadlinqs IntelligenceStart free

ATT&CK techniqueStealth (formerly Defense Evasion)

T1684.001 Impersonation

Stealth (formerly Defense Evasion)EnterpriseSub-technique

As of 2026-10-05, T1684.001 (Impersonation) appears in 228 tracked threats, first reported 2026-01-27 and most recently 2026-10-04, with linked actors including ShinyHunters, UNC6671, The Com; it most often appears alongside T1657 (Financial Theft).

Tracked threats
22819 critical, 142 high, 60 medium, 5 low
First seen
2026-01-27
Last seen
2026-10-04
Threat actors
63In the threats using it
Detection rules
9Blue tier and above

Data as of:

Activity timeline

T1684.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 64 reports, and 228 of the 228 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1684.001 Impersonation is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1684 Social Engineering. Threadlinqs maps 228 of 2623 tracked threats (8.7%) to it; by severity that is 19 critical, 142 high, 60 medium, 5 low.

Threats that use T1684.001 most often also use T1657 Financial Theft (117 threats), T1566 Phishing (99 threats), T1583 Acquire Infrastructure (88 threats), T1566.002 Spearphishing Link (85 threats), T1027 Obfuscated Files or Information (79 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

63 tracked threat actors appear in the threats that use T1684.001; the most frequent are ShinyHunters (7), UNC6671 (7), The Com (5), UNC6240 (5), UNC6395 (5).

Threat actors using it

Tracked threats

The 30 most recent of 228 tracked threats that use T1684.001.

Detection coverage

Threadlinqs maintains 9 detection rules mapped to T1684.001 (SPL 4, KQL 3, Sigma 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

9 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Parent technique

T1684 Social Engineering — 0 tracked threats at the technique level.