T1204.001Malicious Link
T1204.001 — Malicious Link is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 9 detection use cases covering it and 130 threat-intel articles citing it.
Execution
9Use cases
130Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1204 · User Execution
Use cases covering this technique (9)
Phishing-link click correlated to endpoint execution User clicked through a Safe Links warning page Click on URL whose host doesn't match the sender domain [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Windows ISO LNK File Creation Windows PowerShell FakeCAPTCHA Clipboard Execution [LLM] Phishing email click landing on Sniper Dz infrastructure (URL/click correlation) [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP [LLM] User-targeted SvelteSpill exploit URL delivered or clicked (CVE-2026-27118)Articles citing this technique (130)
crit ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities art-37
high Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility art-74
crit Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models art-87
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-130
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-220
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-429
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-537
crit ESET Threat Report H2 2025 art-647
high Defense in Depth art-1278