T1566.001Spearphishing Attachment
T1566.001 — Spearphishing Attachment is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 61 detection use cases covering it and 82 threat-intel articles citing it.
Initial Access
61Use cases
82Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1566 · Phishing
Use cases covering this technique (61)
Abnormal Security: malicious email opened Email attachment opened from external sender Email Attachments With Lots Of Spaces Suspicious Email Attachment Extensions GSuite Email Suspicious Attachment Gsuite Email Suspicious Subject With Attachment Gsuite Email With Known Abuse Web Service Link Gsuite Suspicious Shared File Name O365 Email Reported By Admin Found Malicious O365 Email Reported By User Found Malicious O365 Safe Links Detection O365 Threat Intelligence Suspicious Email Delivered O365 ZAP Activity Detection Detect Outlook exe writing a zip file Windows CAB File on Disk Windows Defender ASR Audit Events Windows Defender ASR Block Events Windows Defender ASR Rules Stacking Windows ISO LNK File Creation Windows Office Product Dropped Cab or Inf File Windows Office Product Dropped Uncommon File Windows Office Product Loaded MSHTML Module Windows Office Product Loading Taskschd DLL Windows Office Product Loading VBE7 DLL Windows Office Product Spawned Child Process For Download Windows Office Product Spawned Control Windows Office Product Spawned MSDT Windows Office Product Spawned Rundll32 With No DLL Windows Office Product Spawned Uncommon Process Windows Phishing PDF File Executes URL Link Windows Phishing Recent ISO Exec Registry Windows Spearphishing Attachment Onenote Spawn Mshta Windows Universal Data Link File Creation Windows Spearphishing Attachment Connect To None MS Office Domain MSHTML Module Load in Office Product Office Application Drop Executable Office Application Spawn Regsvr32 process Office Application Spawn rundll32 process Office Document Creating Schedule Task Office Document Executing Macro Code Office Document Spawned Child Process To Download Office Product Spawn CMD Process Office Product Spawning BITSAdmin Office Product Spawning CertUtil Office Product Spawning MSHTA Office Product Spawning Rundll32 with no DLL Office Product Spawning Windows Script Host Office Product Spawning Wmic Office Product Writing cab or inf Office Spawning Control Windows Office Product Spawning MSDT Winword Spawning Cmd Winword Spawning PowerShell Winword Spawning Windows Script Host [LLM] ISO File Dropped to Downloads — RoguePlanet Defender Exploit Precursor [LLM] Claude 'Appeal Request' phishing email with PDF attachment lure [LLM] Screening Serpens recruitment lure — Hiring Portal.zip + job requisition PDFs [LLM] Mailcow quarantine XSS via EICAR + HTML in attachment filename (GHSA-2xjc-rg88-jvpp) [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP [LLM] APT28 MacroMaze: Office or Edge HTTP traffic to webhook.site (INCLUDEPICTURE tracker + exfil) [LLM] Inbound email with HTML attachment linking to unpkg.com Beamglea packageArticles citing this technique (82)
high Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility art-74
crit Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models art-87
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-220
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-537
crit ESET Threat Report H2 2025 art-647
high Defense in Depth art-1278