T1566.002Spearphishing Link
T1566.002 — Spearphishing Link is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 44 detection use cases covering it and 180 threat-intel articles citing it.
Initial Access
44Use cases
180Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1566 · Phishing
Use cases covering this technique (44)
Phishing-link click correlated to endpoint execution User clicked through a Safe Links warning page Click on URL whose host doesn't match the sender domain [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Azure AD Device Code Authentication O365 Email Reported By Admin Found Malicious O365 Email Reported By User Found Malicious O365 Threat Intelligence Suspicious Email Delivered O365 ZAP Activity Detection Process Creating LNK file in Suspicious Location Windows Defender ASR Audit Events Windows Defender ASR Block Events Windows Defender ASR Rules Stacking [LLM] DNS / web resolution of F6 counterfeit Russian-company domains [LLM] Compromised M365 mailbox fan-out of QR-code PDF phishing (UAT-11764) [LLM] ARToken/EvilTokens device-code phishing: contact with pamconj C2 and Cloudflare Workers lures [LLM] Operation BlueDash fake Teams/Zoom update payload-host infrastructure contact [LLM] InsureTrap malvertising: Google Ads referrer landing on free-hosting insurance phish [LLM] BlueNoroff typosquatted Zoom/Teams infrastructure network contact [LLM] ChatGPT AgentForger CSRF link: Agent Builder URL with initial_assistant_prompt param [LLM] Inbound phishing email or URL referencing npm look-alike domain npmjs.help [LLM] Endpoint DNS resolution or web connection to npm phishing domain npmjs.help [LLM] mshta.exe HTA downloader reaching UAT-11795 staging domains (ClickFix) [LLM] npm maintainer credential-phish lookalike domain npmjs.help (chalk/debug ATO) [LLM] Entra ID Device Authorization Grant (device code) authentication flow sign-in [LLM] Law-firm / order-confirmation lure delivering device-code phish via cacoo.com and allianceinvestigators.com [LLM] ARToken/EvilTokens PhaaS infrastructure contact (pamconj.com panel + Cloudflare Worker lure) [LLM] Montana Empire phishing-kit ZIP + companion APK by SHA256 on endpoints [LLM] Montana Empire kit PHP components staged on web infrastructure [LLM] EvilTokens device-code token polling from attacker infra (python-requests UA / C2 IPs) [LLM] EvilTokens device-code lure email (Acrobat/DocuSign decoy, 'Verify to view') [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry [LLM] Mail-borne click to fake FIFA World Cup 2026 phishing domain [LLM] Hoppscotch device-login open redirect token theft via localhost.* / sslip.io bypass [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP [LLM] gofile.io archive download by browser followed by extracted-EXE execution within 30 minutes [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP [LLM] Phishing email impersonating npm support from typosquatted npmjs.help domain [LLM] ESET-impersonating typosquat domain contact (InedibleOchotense / Kalambur delivery) [LLM] Connection to Beamglea phishing credential-harvesting domains [LLM] Inbound phishing email from npmjs.help maintainer-takeover domain [LLM] Browser/HTTPS traffic to npmjs.help credential-harvesting page [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit)Articles citing this technique (180)
crit Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads art-06
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97
crit Begun, the Patch Wars have art-150
crit Winning 54% of the time art-214
crit ESET Threat Report H1 2026 art-221
crit When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website art-246
high Catan and Mouse art-261
high The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration art-312
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-362
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-402
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-422
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-551
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
crit ESET Threat Report H2 2025 art-732
high Defense in Depth art-1391
high Ethical hacking techniques art-1698
high Ethical Hacking: Top Tools art-1702
crit API Security Guide art-1751
high Securing the web (forward) art-1803
high Cybersecurity Hygiene 101 art-1824
crit Secure Python URL validation art-1937
high Snyk joins OpenSSF: Tackling open source supply chain security with a developer-first approach art-3066
crit XSS Attacks: The Next Wave art-3641