T1566.001Spearphishing Attachment
T1566.001 — Spearphishing Attachment is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 60 detection use cases covering it and 101 threat-intel articles citing it.
Initial Access
60Use cases
101Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1566 · Phishing
Use cases covering this technique (60)
Abnormal Security: malicious email opened Email attachment opened from external sender Email Attachments With Lots Of Spaces Suspicious Email Attachment Extensions GSuite Email Suspicious Attachment Gsuite Email Suspicious Subject With Attachment Gsuite Email With Known Abuse Web Service Link Gsuite Suspicious Shared File Name O365 Email Reported By Admin Found Malicious O365 Email Reported By User Found Malicious O365 Safe Links Detection O365 Threat Intelligence Suspicious Email Delivered O365 ZAP Activity Detection Detect Outlook exe writing a zip file Windows CAB File on Disk Windows Defender ASR Audit Events Windows Defender ASR Block Events Windows Defender ASR Rules Stacking Windows ISO LNK File Creation Windows Office Product Dropped Cab or Inf File Windows Office Product Dropped Uncommon File Windows Office Product Loaded MSHTML Module Windows Office Product Loading Taskschd DLL Windows Office Product Loading VBE7 DLL Windows Office Product Spawned Child Process For Download Windows Office Product Spawned Control Windows Office Product Spawned MSDT Windows Office Product Spawned Rundll32 With No DLL Windows Office Product Spawned Uncommon Process Windows Phishing PDF File Executes URL Link Windows Phishing Recent ISO Exec Registry Windows Spearphishing Attachment Onenote Spawn Mshta Windows Universal Data Link File Creation Windows Spearphishing Attachment Connect To None MS Office Domain MSHTML Module Load in Office Product Office Application Drop Executable Office Application Spawn Regsvr32 process Office Application Spawn rundll32 process Office Document Creating Schedule Task Office Document Executing Macro Code Office Document Spawned Child Process To Download Office Product Spawn CMD Process Office Product Spawning BITSAdmin Office Product Spawning CertUtil Office Product Spawning MSHTA Office Product Spawning Rundll32 with no DLL Office Product Spawning Windows Script Host Office Product Spawning Wmic Office Product Writing cab or inf Office Spawning Control Windows Office Product Spawning MSDT Winword Spawning Cmd Winword Spawning PowerShell Winword Spawning Windows Script Host [LLM] Quishing delivery: inbound email with QR-code image/PDF attachment and no scannable body URL [LLM] QR-code PDF phishing attachment resolving to workers.dev / pamconj M365 harvesting page (UAT-11764) [LLM] Inbound HTML-attachment lure exploiting Zimbra XSS (CVE-2025-66376) [LLM] Mailcow quarantine XSS via EICAR + HTML in attachment filename (GHSA-2xjc-rg88-jvpp) [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP [LLM] Inbound email with HTML attachment linking to unpkg.com Beamglea packageArticles citing this technique (101)
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories art-51
high Curiouser and Curiouser art-52
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55
crit Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS art-101
crit Begun, the Patch Wars have art-253
crit ESET Threat Report H1 2026 art-312
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-448
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-673
crit ESET Threat Report H2 2025 art-762
crit CISA KEV: CVE-2024-38226 — Microsoft Publisher Protection Mechanism Failure Vulnerability art-1253
high Defense in Depth art-1415
high Ethical hacking techniques art-1721
high Ethical Hacking: Top Tools art-1725
crit API Security Guide art-1774
high Securing the web (forward) art-1826
high Cybersecurity Hygiene 101 art-1847
crit Secure Python URL validation art-1960
high Securing PHP containers art-2105
crit XSS Attacks: The Next Wave art-3664