T1204.001Malicious Link
T1204.001 — Malicious Link is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 12 detection use cases covering it and 184 threat-intel articles citing it.
Execution
12Use cases
184Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1204 · User Execution
Use cases covering this technique (12)
Phishing-link click correlated to endpoint execution User clicked through a Safe Links warning page Click on URL whose host doesn't match the sender domain [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Windows ISO LNK File Creation Windows PowerShell FakeCAPTCHA Clipboard Execution [LLM] Quishing delivery: inbound email with QR-code image/PDF attachment and no scannable body URL [LLM] JWR phishing-kit landing: victim beacon + ws-worker.js load in web proxy telemetry [LLM] Safe Links click resolving through a cloud-PaaS redirect chain into AitM phishing [LLM] ClickFix execution reaching CaptiveCrunch infrastructure or dropping svchost32 [LLM] QR-code PDF phishing attachment resolving to workers.dev / pamconj M365 harvesting page (UAT-11764) [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIPArticles citing this technique (184)
crit Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware art-28
crit Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner art-38
high Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware art-40
high Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers art-44
crit APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit art-48
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories art-51
high Curiouser and Curiouser art-52
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55
high OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning art-69
high DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt art-82
crit A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices art-85
crit Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo art-86
crit Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers art-88
high Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets art-90
crit The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications art-96
crit Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS art-101
crit Begun, the Patch Wars have art-253
crit ESET Threat Report H1 2026 art-312
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-408
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-448
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-468
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-592
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-673
crit ESET Threat Report H2 2025 art-762
high Defense in Depth art-1415
high Ethical hacking techniques art-1721
high Ethical Hacking: Top Tools art-1725
crit API Security Guide art-1774
high Securing the web (forward) art-1826
high Cybersecurity Hygiene 101 art-1847
crit Secure Python URL validation art-1960
high Snyk joins OpenSSF: Tackling open source supply chain security with a developer-first approach art-3089
crit XSS Attacks: The Next Wave art-3664