T1566.002Spearphishing Link
T1566.002 — Spearphishing Link is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 40 detection use cases covering it and 186 threat-intel articles citing it.
Initial Access
40Use cases
186Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1566 · Phishing
Use cases covering this technique (40)
Phishing-link click correlated to endpoint execution User clicked through a Safe Links warning page Click on URL whose host doesn't match the sender domain [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Azure AD Device Code Authentication O365 Email Reported By Admin Found Malicious O365 Email Reported By User Found Malicious O365 Threat Intelligence Suspicious Email Delivered O365 ZAP Activity Detection Process Creating LNK file in Suspicious Location Windows Defender ASR Audit Events Windows Defender ASR Block Events Windows Defender ASR Rules Stacking [LLM] SafePal breach phishing wave: impersonation email with firmware-update / seed-phrase lure [LLM] Endpoint traffic to SafePal phishing site safepal.support / lookalike domains [LLM] RecruitTrap recruitment lure via abused PeopleForce (reply.peopleforce.io) ATS relay [LLM] Browser navigation to BitB Calendly-lookalike phishing host (rare .cfd/.work TLD) [LLM] JWR phishing-kit landing: victim beacon + ws-worker.js load in web proxy telemetry [LLM] First-seen browser egress to abused cloud-PaaS phishing domains (workers.dev / pages.dev / vercel.app / github.io / netlify.app / dweb.link) [LLM] Safe Links click resolving through a cloud-PaaS redirect chain into AitM phishing [LLM] Endpoint connections to Storm-2945 CaptiveCrunch AiTM doppelganger infrastructure [LLM] ClickFix execution reaching CaptiveCrunch infrastructure or dropping svchost32 [LLM] Successful Entra ID device-code authentication (ARToken/EvilTokens PhaaS MFA bypass) [LLM] Inbound phishing email or URL referencing npm look-alike domain npmjs.help [LLM] Endpoint DNS resolution or web connection to npm phishing domain npmjs.help [LLM] mshta.exe HTA downloader reaching UAT-11795 staging domains (ClickFix) [LLM] npm maintainer credential-phish lookalike domain npmjs.help (chalk/debug ATO) [LLM] EvilTokens device-code token polling from attacker infra (python-requests UA / C2 IPs) [LLM] EvilTokens device-code lure email (Acrobat/DocuSign decoy, 'Verify to view') [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry [LLM] Mail-borne click to fake FIFA World Cup 2026 phishing domain [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP [LLM] gofile.io archive download by browser followed by extracted-EXE execution within 30 minutes [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP [LLM] Phishing email impersonating npm support from typosquatted npmjs.help domain [LLM] Connection to Beamglea phishing credential-harvesting domains [LLM] Inbound phishing email from npmjs.help maintainer-takeover domain [LLM] Browser/HTTPS traffic to npmjs.help credential-harvesting page [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit)Articles citing this technique (186)
crit Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware art-28
crit Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner art-38
high Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware art-40
high Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers art-44
crit APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit art-48
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories art-51
high Curiouser and Curiouser art-52
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55
high OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning art-69
high DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt art-82
crit A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices art-85
crit Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo art-86
crit Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers art-88
high Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets art-90
crit The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications art-96
crit Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS art-101
crit Begun, the Patch Wars have art-253
crit ESET Threat Report H1 2026 art-312
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-408
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-448
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-468
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-592
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-673
crit ESET Threat Report H2 2025 art-762
high Defense in Depth art-1415
high Ethical hacking techniques art-1721
high Ethical Hacking: Top Tools art-1725
crit API Security Guide art-1774
high Securing the web (forward) art-1826
high Cybersecurity Hygiene 101 art-1847
crit Secure Python URL validation art-1960
high Snyk joins OpenSSF: Tackling open source supply chain security with a developer-first approach art-3089
crit XSS Attacks: The Next Wave art-3664