# T1684.001 Impersonation

> As of 2026-10-05, T1684.001 (Impersonation) appears in 228 tracked threats, first reported 2026-01-27 and most recently 2026-10-04, with linked actors including ShinyHunters, UNC6671, The Com; it most often appears alongside T1657 (Financial Theft).

- **Tracked threats:** 228 (19 critical, 142 high, 60 medium, 5 low)
- **First seen:** 2026-01-27
- **Last seen:** 2026-10-04
- **Threat actors:** 63
- **Detection rules:** 9 (counts only; Blue tier and above)

## Key facts

- **ID:** T1684.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1684
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1684/001/

## Activity timeline

T1684.001 first appeared in tracked threats on 2026-01-27 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 64 reports, and 228 of the 228 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1684.001 Impersonation is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1684 Social Engineering. Threadlinqs maps 228 of 2623 tracked threats (8.7%) to it; by severity that is 19 critical, 142 high, 60 medium, 5 low.

Threats that use T1684.001 most often also use [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (117 threats), [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) (99 threats), [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) (88 threats), [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (85 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (79 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

63 tracked threat actors appear in the threats that use T1684.001; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (7), [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) (7), [The Com](https://intel.threadlinqs.com/actor/The%20Com) (5), [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) (5), [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) (5).

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 7
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 7
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 5
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 5
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 5
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 4
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 4
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 4
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 4
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 3
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2

## Tracked threats

The 30 most recent of 228 tracked threats that use T1684.001.

- [Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…](https://intel.threadlinqs.com/threat/TL-2026-2919) — high — 2026-10-04
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…](https://intel.threadlinqs.com/threat/TL-2026-2901) — high — 2026-10-04
- [Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC](https://intel.threadlinqs.com/threat/TL-2026-2891) — medium — 2026-10-04
- [China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)](https://intel.threadlinqs.com/threat/TL-2026-2884) — high — 2026-10-04
- [EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…](https://intel.threadlinqs.com/threat/TL-2026-2873) — high — 2026-10-03
- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data…](https://intel.threadlinqs.com/threat/TL-2026-2839) — high — 2026-10-02
- [Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breach](https://intel.threadlinqs.com/threat/TL-2026-2842) — medium — 2026-10-01
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFA](https://intel.threadlinqs.com/threat/TL-2026-2834) — high — 2026-10-01
- [ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing](https://intel.threadlinqs.com/threat/TL-2026-2826) — medium — 2026-10-01
- [Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+…](https://intel.threadlinqs.com/threat/TL-2026-2792) — medium — 2026-09-29
- [AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification](https://intel.threadlinqs.com/threat/TL-2026-2774) — high — 2026-09-29
- [Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…](https://intel.threadlinqs.com/threat/TL-2026-2770) — medium — 2026-09-29
- [Fake American Express "non-compliance" card-lock phishing campaign targets Australians](https://intel.threadlinqs.com/threat/TL-2026-2758) — medium — 2026-09-29
- [Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…](https://intel.threadlinqs.com/threat/TL-2026-2764) — high — 2026-09-28
- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — high — 2026-09-27
- [Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…](https://intel.threadlinqs.com/threat/TL-2026-2673) — high — 2026-09-26
- [AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2668) — medium — 2026-09-26
- [Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script](https://intel.threadlinqs.com/threat/TL-2026-2695) — medium — 2026-09-25
- [Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users](https://intel.threadlinqs.com/threat/TL-2026-2655) — medium — 2026-09-25
- [Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…](https://intel.threadlinqs.com/threat/TL-2026-2650) — critical — 2026-09-25
- [SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…](https://intel.threadlinqs.com/threat/TL-2026-2642) — high — 2026-09-24
- [UK establishes National Centre for Information Defence to counter Russian state disinformation operations](https://intel.threadlinqs.com/threat/TL-2026-2638) — high — 2026-09-24
- [Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials](https://intel.threadlinqs.com/threat/TL-2026-2626) — medium — 2026-09-23
- [Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)](https://intel.threadlinqs.com/threat/TL-2026-2614) — high — 2026-09-22
- [Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…](https://intel.threadlinqs.com/threat/TL-2026-2595) — high — 2026-09-21
- [Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google…](https://intel.threadlinqs.com/threat/TL-2026-2567) — medium — 2026-09-18
- [Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details](https://intel.threadlinqs.com/threat/TL-2026-2562) — medium — 2026-09-18
- [Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow](https://intel.threadlinqs.com/threat/TL-2026-2556) — medium — 2026-09-18
- [Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data](https://intel.threadlinqs.com/threat/TL-2026-2550) — high — 2026-09-17

## Related CVEs

CVEs referenced by the tracked threats that use T1684.001, most frequent first.

- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2017-7921](https://intel.threadlinqs.com/cve/CVE-2017-7921)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2025-20700](https://intel.threadlinqs.com/cve/CVE-2025-20700)
- [CVE-2025-20701](https://intel.threadlinqs.com/cve/CVE-2025-20701)
- [CVE-2025-20702](https://intel.threadlinqs.com/cve/CVE-2025-20702)
- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)
- [CVE-2025-32711](https://intel.threadlinqs.com/cve/CVE-2025-32711)
- [CVE-2025-59536](https://intel.threadlinqs.com/cve/CVE-2025-59536)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2026-21262](https://intel.threadlinqs.com/cve/CVE-2026-21262)
- [CVE-2026-21852](https://intel.threadlinqs.com/cve/CVE-2026-21852)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-44338](https://intel.threadlinqs.com/cve/CVE-2026-44338)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2026-9110](https://intel.threadlinqs.com/cve/CVE-2026-9110)
- [CVE-2026-9111](https://intel.threadlinqs.com/cve/CVE-2026-9111)
- [CVE-2026-9112](https://intel.threadlinqs.com/cve/CVE-2026-9112)
- [CVE-2026-9113](https://intel.threadlinqs.com/cve/CVE-2026-9113)
- [CVE-2026-9114](https://intel.threadlinqs.com/cve/CVE-2026-9114)
- [CVE-2026-9115](https://intel.threadlinqs.com/cve/CVE-2026-9115)
- [CVE-2026-9116](https://intel.threadlinqs.com/cve/CVE-2026-9116)

## Detection coverage

Threadlinqs maintains 9 detection rules mapped to T1684.001 (SPL 4, KQL 3, Sigma 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

9 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

T1684 Social Engineering — 0 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1684.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
