TACTIC: INITIAL ACCESS

Spearphishing Link (T1566.002): real cases

MITRE Definition ↗
Adversaries send spearphishing emails containing malicious hyperlinks to lure users into downloading payloads or entering credentials.

Key Facts

Technique ID
T1566.002
Initial Access
Mapped Cases
5
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1566.002.
  • Tactical Phase: Initial Access.
  • Substantiated in 5 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Complaint ¶ 55
"Spearphishing emails were sent to bank officials at Bangladesh Bank directing them to fake SWIFT messaging updates."
U.S. District Court for the Central District of California View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 22, Page 12
"Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials."
U.S. District Court for the Northern District of California View full case dossier →
Primary Source Evidence Excerpt: Trial Transcript Day 4, Page 61
"Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials."
U.S. District Court for the Northern District of California View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 21, Page 8
"Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains."
U.S. District Court for the District of Columbia View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 11, Page 6
"Johnson established early phishing operations that cloned PayPal and eBay authentication web pages to steal account credentials."
U.S. District Court for the District of New Jersey View full case dossier →