46
Groups Using This
1
Tactics
6
Platforms
20
Prevalence Rank
Description

Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this case, the malicious emails contain links. Generally, the links will be accompanied by social engineering text and require the user to actively click or copy and paste a URL into a browser, leveraging User Execution. The visited website may compromise the web browser using an exploit, or the user will be prompted to download applications, documents, zip files, or even executables depending on the pretext for the email in the first place. Adversaries may also include links that are intended to interact directly with an email reader, including embedded images intended to exploit the end system directly. Additionally, adversaries may use seemingly benign links that abuse special characters to mimic legitimate websites (known as an "IDN homograph attack"). URLs may also be obfuscated by taking advantage of quirks in the URL schema, such as the acceptance of integer- or hexadecimal-based hostname formats and the automatic discarding of text before an “@” symbol: for example, `hxxp://google.com@1157586937`. Adversaries may also utilize links to perform consent phishing/spearphishing campaigns to Steal Application Access Tokens that grant immediate access to the victim environment. For example, a user may be lured into granting adversaries permissions/access via a malicious OAuth 2.0 request URL that when accepted by the user provide permissions/access for malicious applications. These stolen access tokens allow the adversary to perform various actions on behalf of the user via API calls. Similarly, malicious links may also target device-based authorization, such as OAuth 2.0 device authorization grant flow which is typically used to authenticate devices without UIs/browsers. Known as “device code phishing,” an adversary may send a link that directs the victim to a malicious authorization page where the user is tricked into entering a code/credentials that produces a device token.

View MITRE record ↗

Platforms
Identity ProviderLinuxmacOSOffice SuiteSaaSWindows
Groups Using T1566.002 (46)
G0094
Kimsuky
🇷🇺 Russia130 techniques19 software
G0032
Lazarus Group
🇰🇵 North Korea93 techniques26 software
G0129
Mustang Panda
🇷🇺 Russia85 techniques23 software
G0034
Sandworm Team
🇷🇺 Russia79 techniques27 software
G0050
APT32
🇻🇳 Vietnam78 techniques15 software
G0059
Magic Hound
🇮🇷 Iran78 techniques13 software
G0049
OilRig
🇮🇷 Iran76 techniques30 software
G0069
MuddyWater
🇮🇷 Iran68 techniques21 software
G0010
Turla
🇷🇺 Russia68 techniques30 software
G0046
FIN7
67 techniques19 software
G0016
APT29
🇷🇺 Russia66 techniques49 software
G0102
Wizard Spider
🇷🇺 Russia64 techniques22 software
G0087
APT39
🇮🇷 Iran53 techniques11 software
G0065
Leviathan
🇨🇳 China50 techniques17 software
G1006
Earth Lusca
🇨🇳 China44 techniques9 software
G0022
APT3
🇨🇳 China44 techniques6 software
G1054
MirrorFace
🇨🇳 China43 techniques16 software
G0040
Patchwork
🇨🇳 China41 techniques8 software
G1039
RedCurl
🇷🇺 Russia41 techniques0 software
G0099
APT-C-36
38 techniques9 software
G0061
FIN8
36 techniques11 software
G0080
Cobalt Group
34 techniques6 software
G0092
TA505
34 techniques16 software
G1044
APT42
🇮🇷 Iran32 techniques2 software
G1046
Storm-1811
31 techniques7 software
G0064
APT33
🇮🇷 Iran31 techniques16 software
G0121
Sidewinder
🇨🇳 China30 techniques1 software
G0128
ZIRCONIUM
🇨🇳 China29 techniques0 software
G1014
LuminousMoth
🇨🇳 China28 techniques2 software
G1018
TA2541
28 techniques9 software
G0090
WIRTE
26 techniques8 software
G0006
APT1
🇨🇳 China23 techniques17 software
G0140
LazyScripter
20 techniques7 software
G0112
Windshift
19 techniques1 software
G0142
Confucius
19 techniques1 software
G0021
Molerats
16 techniques6 software
G1011
EXOTIC LILY
15 techniques2 software
G0098
BlackTech
🇨🇳 China14 techniques6 software
G0134
Transparent Tribe
🇵🇰 Pakistan14 techniques5 software
G0085
FIN4
12 techniques0 software
G1020
Mustard Tempest
12 techniques2 software
G0120
Evilnum
11 techniques3 software
G0095
Machete
🇷🇺 Russia11 techniques1 software
G0066
Elderwood
🇨🇳 China9 techniques9 software
G0103
Mofang
🇨🇳 China6 techniques2 software
G1037
TA577
6 techniques3 software
↑