Activity timeline
T1684.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 64 reports, and 228 of the 228 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1684.001 Impersonation is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1684 Social Engineering. Threadlinqs maps 228 of 2623 tracked threats (8.7%) to it; by severity that is 19 critical, 142 high, 60 medium, 5 low.
Threats that use T1684.001 most often also use T1657 Financial Theft (117 threats), T1566 Phishing (99 threats), T1583 Acquire Infrastructure (88 threats), T1566.002 Spearphishing Link (85 threats), T1027 Obfuscated Files or Information (79 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
63 tracked threat actors appear in the threats that use T1684.001; the most frequent are ShinyHunters (7), UNC6671 (7), The Com (5), UNC6240 (5), UNC6395 (5).
Threat actors using it
Tracked threats
The 30 most recent of 228 tracked threats that use T1684.001.
- Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…high
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…high
- Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARCmedium
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)high
- EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…high
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data…high
- Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breachmedium
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFAhigh
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishingmedium
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+…medium
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verificationhigh
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…medium
- Fake American Express "non-compliance" card-lock phishing campaign targets Australiansmedium
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…high
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvestershigh
- Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…high
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…medium
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Scriptmedium
- Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Usersmedium
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…critical
- SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…high
- UK establishes National Centre for Information Defence to counter Russian state disinformation operationshigh
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentialsmedium
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)high
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…high
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google…medium
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Detailsmedium
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flowmedium
- Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Datahigh
Detection coverage
Threadlinqs maintains 9 detection rules mapped to T1684.001 (SPL 4, KQL 3, Sigma 2). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1684 Social Engineering — 0 tracked threats at the technique level.