T1204.001Malicious Link
T1204.001 — Malicious Link is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 12 detection use cases covering it and 177 threat-intel articles citing it.
Execution
12Use cases
177Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1204 · User Execution
Use cases covering this technique (12)
Phishing-link click correlated to endpoint execution User clicked through a Safe Links warning page Click on URL whose host doesn't match the sender domain [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Windows ISO LNK File Creation Windows PowerShell FakeCAPTCHA Clipboard Execution [LLM] Operation BlueDash fake Teams/Zoom update payload-host infrastructure contact [LLM] InsureTrap malvertising: Google Ads referrer landing on free-hosting insurance phish [LLM] ChatGPT AgentForger CSRF link: Agent Builder URL with initial_assistant_prompt param [LLM] Financial_report.bat dropper downloaded from ClickUp attachment host [LLM] Joro proxy-mode confused-deputy: browser POSTs to loopback API 127.0.0.1:9090 (CVE-2026-53649) [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIPArticles citing this technique (177)
crit Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation art-01
crit Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads art-09
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-77
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-78
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-100
crit Begun, the Patch Wars have art-151
crit Winning 54% of the time art-215
crit [GHSA / CRITICAL] CVE-2026-53649: Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE art-220
crit ESET Threat Report H1 2026 art-222
crit When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website art-247
high Catan and Mouse art-262
high The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration art-312
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-362
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-402
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-422
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-551
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
crit ESET Threat Report H2 2025 art-732
high Defense in Depth art-1391
high Ethical hacking techniques art-1698
high Ethical Hacking: Top Tools art-1702
crit API Security Guide art-1751
high Securing the web (forward) art-1803
high Cybersecurity Hygiene 101 art-1824
crit Secure Python URL validation art-1937
high Snyk joins OpenSSF: Tackling open source supply chain security with a developer-first approach art-3066
crit XSS Attacks: The Next Wave art-3641