T1566.001Spearphishing Attachment
T1566.001 — Spearphishing Attachment is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 61 detection use cases covering it and 136 threat-intel articles citing it.
Initial Access
61Use cases
136Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1566 · Phishing
Use cases covering this technique (61)
Abnormal Security: malicious email opened Email attachment opened from external sender Email Attachments With Lots Of Spaces Suspicious Email Attachment Extensions GSuite Email Suspicious Attachment Gsuite Email Suspicious Subject With Attachment Gsuite Email With Known Abuse Web Service Link Gsuite Suspicious Shared File Name O365 Email Reported By Admin Found Malicious O365 Email Reported By User Found Malicious O365 Safe Links Detection O365 Threat Intelligence Suspicious Email Delivered O365 ZAP Activity Detection Detect Outlook exe writing a zip file Windows CAB File on Disk Windows Defender ASR Audit Events Windows Defender ASR Block Events Windows Defender ASR Rules Stacking Windows ISO LNK File Creation Windows Office Product Dropped Cab or Inf File Windows Office Product Dropped Uncommon File Windows Office Product Loaded MSHTML Module Windows Office Product Loading Taskschd DLL Windows Office Product Loading VBE7 DLL Windows Office Product Spawned Child Process For Download Windows Office Product Spawned Control Windows Office Product Spawned MSDT Windows Office Product Spawned Rundll32 With No DLL Windows Office Product Spawned Uncommon Process Windows Phishing PDF File Executes URL Link Windows Phishing Recent ISO Exec Registry Windows Spearphishing Attachment Onenote Spawn Mshta Windows Universal Data Link File Creation Windows Spearphishing Attachment Connect To None MS Office Domain MSHTML Module Load in Office Product Office Application Drop Executable Office Application Spawn Regsvr32 process Office Application Spawn rundll32 process Office Document Creating Schedule Task Office Document Executing Macro Code Office Document Spawned Child Process To Download Office Product Spawn CMD Process Office Product Spawning BITSAdmin Office Product Spawning CertUtil Office Product Spawning MSHTA Office Product Spawning Rundll32 with no DLL Office Product Spawning Windows Script Host Office Product Spawning Wmic Office Product Writing cab or inf Office Spawning Control Windows Office Product Spawning MSDT Winword Spawning Cmd Winword Spawning PowerShell Winword Spawning Windows Script Host [LLM] Inbound email from F6 fraud clone domain (ruspromexport-group.ru / info@ruspromexport-group.ru) [LLM] Inbound phishing from BEC sender domain 9i6pokerdepot.com (Q2 2026 ClickUp/pixeldrain chain) [LLM] Inbound HTML-attachment lure exploiting Zimbra XSS (CVE-2025-66376) [LLM] Law-firm / order-confirmation lure delivering device-code phish via cacoo.com and allianceinvestigators.com [LLM] Mailcow quarantine XSS via EICAR + HTML in attachment filename (GHSA-2xjc-rg88-jvpp) [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP [LLM] Inbound email with HTML attachment linking to unpkg.com Beamglea packageArticles citing this technique (136)
crit Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads art-06
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97
crit Begun, the Patch Wars have art-150
crit Winning 54% of the time art-214
crit ESET Threat Report H1 2026 art-221
crit When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website art-246
high Catan and Mouse art-261
high The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration art-312
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-402
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
crit ESET Threat Report H2 2025 art-732
crit CISA KEV: CVE-2024-38226 — Microsoft Publisher Protection Mechanism Failure Vulnerability art-1230
high Defense in Depth art-1391
high Ethical hacking techniques art-1698
high Ethical Hacking: Top Tools art-1702
crit API Security Guide art-1751
high Securing the web (forward) art-1803
high Cybersecurity Hygiene 101 art-1824
crit Secure Python URL validation art-1937
high Securing PHP containers art-2082
crit XSS Attacks: The Next Wave art-3641