Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Initial Access/ T1566.002

T1566.002Spearphishing Link

T1566.002 — Spearphishing Link is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 44 detection use cases covering it and 180 threat-intel articles citing it.

Initial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
44Use cases
180Articles
0Sub-techniques
1Tactic

Use cases covering this technique (44)

Phishing-link click correlated to endpoint execution Internal delivery · alerting DSP User clicked through a Safe Links warning page Internal delivery · alerting DS Click on URL whose host doesn't match the sender domain Internal delivery · hunting DS [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD Azure AD Device Code Authentication ESCU actions · alerting P O365 Email Reported By Admin Found Malicious ESCU actions · alerting P O365 Email Reported By User Found Malicious ESCU actions · alerting P O365 Threat Intelligence Suspicious Email Delivered ESCU actions · hunting P O365 ZAP Activity Detection ESCU actions · hunting P Process Creating LNK file in Suspicious Location ESCU actions · hunting P Windows Defender ASR Audit Events ESCU actions · hunting P Windows Defender ASR Block Events ESCU actions · hunting P Windows Defender ASR Rules Stacking ESCU actions · hunting P [LLM] DNS / web resolution of F6 counterfeit Russian-company domains Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised M365 mailbox fan-out of QR-code PDF phishing (UAT-11764) Bespoke delivery · alerting DSP [LLM] ARToken/EvilTokens device-code phishing: contact with pamconj C2 and Cloudflare Workers lures Bespoke delivery · alerting DSΣPDDCS [LLM] Operation BlueDash fake Teams/Zoom update payload-host infrastructure contact Bespoke delivery · alerting DSΣPDDCS [LLM] InsureTrap malvertising: Google Ads referrer landing on free-hosting insurance phish Bespoke delivery · hunting DSΣP [LLM] BlueNoroff typosquatted Zoom/Teams infrastructure network contact Bespoke delivery · alerting DSΣPDDCS [LLM] ChatGPT AgentForger CSRF link: Agent Builder URL with initial_assistant_prompt param Bespoke delivery · alerting DSΣP [LLM] Inbound phishing email or URL referencing npm look-alike domain npmjs.help Bespoke delivery · alerting DSP [LLM] Endpoint DNS resolution or web connection to npm phishing domain npmjs.help Bespoke delivery · alerting DSΣPDDCS [LLM] mshta.exe HTA downloader reaching UAT-11795 staging domains (ClickFix) Bespoke delivery · alerting DSΣPDDCS [LLM] npm maintainer credential-phish lookalike domain npmjs.help (chalk/debug ATO) Bespoke delivery · alerting DSΣPDDCS [LLM] Entra ID Device Authorization Grant (device code) authentication flow sign-in Bespoke exploit · alerting DSΣPDD [LLM] Law-firm / order-confirmation lure delivering device-code phish via cacoo.com and allianceinvestigators.com Bespoke delivery · hunting DS [LLM] ARToken/EvilTokens PhaaS infrastructure contact (pamconj.com panel + Cloudflare Worker lure) Bespoke delivery · alerting DSΣPDDCS [LLM] Montana Empire phishing-kit ZIP + companion APK by SHA256 on endpoints Bespoke delivery · hunting DSΣPCS [LLM] Montana Empire kit PHP components staged on web infrastructure Bespoke install · hunting DSΣPDDCS [LLM] EvilTokens device-code token polling from attacker infra (python-requests UA / C2 IPs) Bespoke delivery · hunting DSΣPDD [LLM] EvilTokens device-code lure email (Acrobat/DocuSign decoy, 'Verify to view') Bespoke delivery · alerting DSP [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry Bespoke delivery · hunting DSΣPDDCS [LLM] Mail-borne click to fake FIFA World Cup 2026 phishing domain Bespoke delivery · alerting DSΣPDDCS [LLM] Hoppscotch device-login open redirect token theft via localhost.* / sslip.io bypass Bespoke exploit · alerting DSΣPDDCS [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP Bespoke delivery · alerting DS [LLM] gofile.io archive download by browser followed by extracted-EXE execution within 30 minutes Bespoke install · alerting DS [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP Bespoke delivery · hunting DSΣPDD [LLM] Phishing email impersonating npm support from typosquatted npmjs.help domain Bespoke delivery · alerting DSΣP [LLM] ESET-impersonating typosquat domain contact (InedibleOchotense / Kalambur delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] Connection to Beamglea phishing credential-harvesting domains Bespoke actions · alerting DSΣPDDCS [LLM] Inbound phishing email from npmjs.help maintainer-takeover domain Bespoke delivery · alerting DSΣPDD [LLM] Browser/HTTPS traffic to npmjs.help credential-harvesting page Bespoke delivery · alerting DSΣPDDCS [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit) Bespoke delivery · alerting DSΣPDDCS

Articles citing this technique (180)