T1566.002Spearphishing Link
T1566.002 — Spearphishing Link is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 43 detection use cases covering it and 135 threat-intel articles citing it.
Initial Access
43Use cases
135Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1566 · Phishing
Use cases covering this technique (43)
Phishing-link click correlated to endpoint execution User clicked through a Safe Links warning page Click on URL whose host doesn't match the sender domain [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Azure AD Device Code Authentication O365 Email Reported By Admin Found Malicious O365 Email Reported By User Found Malicious O365 Threat Intelligence Suspicious Email Delivered O365 ZAP Activity Detection Process Creating LNK file in Suspicious Location Windows Defender ASR Audit Events Windows Defender ASR Block Events Windows Defender ASR Rules Stacking [LLM] Raviral.com Sniper Dz kit endpoints accessed (k_fac.php / track.js) [LLM] Phishing email click landing on Sniper Dz infrastructure (URL/click correlation) [LLM] Brand-impersonating phishing pages on abused free-hosting platforms (Sniper Dz pattern) [LLM] phpBB password-reset Host header injection (CVE-2026-29199 exploitation) [LLM] Outlook preview-pane Type Confusion exploit chain (Outlook → Word → LOLBin) [LLM] ChatGPT Plus payment-update phishing emails (display-name + subject lure) [LLM] Phishing redirect chain via awstrack.me / Rebrandly into AI-themed landing path [LLM] World Cup 2026 themed lookalike / typosquat domain resolution by corporate hosts [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry [LLM] UTA0355 device-code phishing: deviceCode auth flow with cross-IP token redemption [LLM] Mail-borne click to fake FIFA World Cup 2026 phishing domain [LLM] Hoppscotch device-login open redirect token theft via localhost.* / sslip.io bypass [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP [LLM] gofile.io archive download by browser followed by extracted-EXE execution within 30 minutes [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP [LLM] User-targeted SvelteSpill exploit URL delivered or clicked (CVE-2026-27118) [LLM] Phishing email impersonating npm support from typosquatted npmjs.help domain [LLM] Aikido npm phishing: direct outbound connection to RackGenius C2 (163.123.236.118) [LLM] Aikido npm phishing: DNS / web request to siemens-energy.icu or siemensergy.icu typosquats [LLM] Aikido campaign: jsDelivr CDN fetch of weaponised flockiali/opresc/prndn/oprnm/operni npm package [LLM] Aikido npm phishing: user clicked phishing URL hosting /DIVzTaSF credential capture [LLM] Aikido npm phishing: inbound email containing jsDelivr link to flockiali/opresc/prndn/oprnm/operni [LLM] DNS / outbound connection to npnjs[.]com phishing infrastructure [LLM] ESET-impersonating typosquat domain contact (InedibleOchotense / Kalambur delivery) [LLM] DreamJob trojanized PDF/installer execution from job-lure decoy folder [LLM] Connection to Beamglea phishing credential-harvesting domains [LLM] Inbound phishing email from npmjs.help maintainer-takeover domain [LLM] Browser/HTTPS traffic to npmjs.help credential-harvesting page [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit)Articles citing this technique (135)
crit ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities art-37
high Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility art-74
crit Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models art-87
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-130
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-220
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-429
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-537
crit ESET Threat Report H2 2025 art-647
high Defense in Depth art-1278