1200KM / simulation
T1566.002 Spearphishing Link — Attack Simulation
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve…
Technique description
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Paste and run technique
Procedure bc177ef9-6a12-4ebc-a2ec-d41e19c2791d; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT1 · G0006
- Turla · G0010
- APT29 · G0016
- Molerats · G0021
- APT3 · G0022
- Lazarus Group · G0032
- Sandworm Team · G0034
- Patchwork · G0040
- FIN7 · G0046
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- FIN8 · G0061
- APT33 · G0064
- Leviathan · G0065
- Elderwood · G0066
- MuddyWater · G0069
- Cobalt Group · G0080
- FIN4 · G0085
- APT39 · G0087
- WIRTE · G0090
- TA505 · G0092
- Kimsuky · G0094
- Machete · G0095
- BlackTech · G0098
- APT-C-36 · G0099
- Wizard Spider · G0102
- Mofang · G0103
- Windshift · G0112
- Evilnum · G0120
- Sidewinder · G0121
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- Transparent Tribe · G0134
- LazyScripter · G0140
- Confucius · G0142
- Earth Lusca · G1006
- EXOTIC LILY · G1011
- LuminousMoth · G1014
- TA2541 · G1018
- Mustard Tempest · G1020
- TA577 · G1037
- RedCurl · G1039
- APT42 · G1044
- Storm-1811 · G1046
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.