TACTIC: INITIAL ACCESS
Spearphishing Link (T1566.002): real cases
MITRE Definition ↗ Adversaries send spearphishing emails containing malicious hyperlinks to lure users into downloading payloads or entering credentials.
Key Facts
Technique ID
T1566.002
Initial Access
Mapped Cases
5
Primary sources
Related Laws
0
Criminal statutes
- ATT&CK Technique Identifier: T1566.002.
- Tactical Phase: Initial Access.
- Substantiated in 5 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)
fugitive 2018-06-08
Primary Source Evidence Excerpt: Complaint ¶ 55
"Spearphishing emails were sent to bank officials at Bangladesh Bank directing them to fake SWIFT messaging updates."
U.S. District Court for the Central District of California
View full case dossier →
U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)
sentenced 2017-02-28
Primary Source Evidence Excerpt: Indictment ¶ 22, Page 12
"Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials."
U.S. District Court for the Northern District of California
View full case dossier →
U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)
sentenced 2016-10-05
Primary Source Evidence Excerpt: Trial Transcript Day 4, Page 61
"Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials."
U.S. District Court for the Northern District of California
View full case dossier →
U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)
fugitive 2018-07-13
Primary Source Evidence Excerpt: Indictment ¶ 21, Page 8
"Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains."
U.S. District Court for the District of Columbia
View full case dossier →
U.S. v. Brett Johnson (ShadowCrew Cybercrime Syndicate)
sentenced 2004-10-26
Primary Source Evidence Excerpt: Indictment ¶ 11, Page 6
"Johnson established early phishing operations that cloned PayPal and eBay authentication web pages to steal account credentials."
U.S. District Court for the District of New Jersey
View full case dossier →