LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1598.003: Spearphishing Link

Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Establish Accounts or Compromise Accounts) and/or sending multiple, seemingly urgent messages.

All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, the malicious emails contain links generally accompanied by social engineering text to coax the user to actively click or copy and paste a URL into a browser.[1][2] The given website may be a clone of a legitimate site (such as an online or corporate login portal) or may closely resemble a legitimate site in appearance and have a URL containing elements from the real site. URLs may also be obfuscated by taking advantage of quirks in the URL schema, such as the acceptance of integer- or hexadecimal-based hostname formats and the automatic discarding of text before an “@” symbol: for example, `hxxp://google.com@1157586937`.[3]

Adversaries may also embed “tracking pixels,” "web bugs," or "web beacons" within phishing messages to verify the receipt of an email, while also potentially profiling and tracking victim information such as IP address.[4][5] These mechanisms often appear as small images (typically one pixel in size) or otherwise obfuscated objects and are typically delivered as HTML code containing a link to a remote server.[5][6]

Adversaries may also be able to spoof a complete website using what is known as a "browser-in-the-browser" (BitB) attack. By generating a fake browser popup window with an HTML-based address bar that appears to contain a legitimate URL (such as an authentication portal), they may be able to prompt users to enter their credentials while bypassing typical URL verification methods.[7][8]

Adversaries can use phishing kits such as `EvilProxy` and `Evilginx2` to perform adversary-in-the-middle phishing by proxying the connection between the victim and the legitimate website. On a successful login, the victim is redirected to the legitimate website, while the adversary captures their session cookie (i.e., Steal Web Session Cookie) in addition to their username and password. This may enable the adversary to then bypass MFA via Web Session Cookie.[9]

Adversaries may also send a malicious link in the form of Quick Response (QR) Codes (also known as “quishing”). These links may direct a victim to a credential phishing page.[10] By using a QR code, the URL may not be exposed in the email and may thus go undetected by most automated email security scans.[11] These QR codes may be scanned by or delivered directly to a user’s mobile device (i.e., Phishing), which may be less secure in several relevant ways.[11] For example, mobile users may not be able to notice minor differences between genuine and credential harvesting websites due to mobile’s smaller form factor.

From the fake website, information is gathered in web forms and sent to the adversary. Adversaries may also use information from previous reconnaissance efforts (ex: Search Open Websites/Domains or Search Victim-Owned Websites) to craft persuasive and believable lures.

EnterpriseT1598.003Sub-techniqueObject v1.7Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Spearphishing Link matters because it can turn a normal email, message, QR code, or fake login page into reconnaissance that harvests credentials, session cookies, or other actionable information before a visible intrusion occurs. For leaders, this is primarily an identity and access risk: the business impact depends less on malware execution and more on whether users, email controls, web controls, and identity monitoring can prevent or quickly validate credential exposure.

Executive priority

Treat this as a control-validation issue across email security, identity security, cloud/SaaS access, and incident response. Executives should ask whether the organization can prove: phishing links and QR-code lures are inspected, suspicious clicks are visible, credential submission events can be investigated, and suspected session-cookie theft can trigger rapid account containment. Because ATT&CK lists this as reconnaissance, response playbooks should not wait for endpoint malware before taking identity-focused action.

Technical view

This is ATT&CK T1598.003, a PRE-platform reconnaissance sub-technique under Phishing for Information. The official detection field is not provided, but ATT&CK relates DET0878, Detection of Spearphishing Link, and mitigations M1017 User Training and M1054 Software Configuration. SOC and IR teams should validate visibility across targeted messages, URLs, URL obfuscation patterns, fake login portals, tracking pixels/web beacons, browser-in-the-browser style credential prompts, QR-code links, and adversary-in-the-middle phishing frameworks such as evilginx2 where identity/session telemetry is available. Triage should focus on whether information was submitted, whether credentials or session cookies may have been exposed, and whether follow-on sign-ins align with the user’s normal behavior.

Likely telemetry

  • Email gateway and mailbox logs, including sender, recipient, headers, authentication results, embedded links, HTML content, image loads, and attachments or QR-code images
  • URL rewriting, detonation, safe-link, proxy, secure web gateway, DNS, and browser history records showing link visits or blocked navigation
  • Identity provider and SaaS sign-in logs, including new device, new location, impossible or unusual travel, MFA events, session creation, and token/session activity
  • Web server or remote image request evidence where tracking pixels or web beacons are suspected
  • User-reported phishing submissions and help desk records tied to targeted messages

Detection direction

  • Do not rely only on attachment or malware alerts; this behavior may only collect information and may not execute code.
  • Validate detection for URL obfuscation techniques described by ATT&CK, including misleading text before an @ symbol and integer- or hexadecimal-based hostnames.
  • Tune email and web detections for cloned login portals, lookalike URLs, urgent social-engineering language, remote image loads, and QR-code links while accounting for benign marketing trackers and legitimate business links.
  • Correlate message receipt, link click, credential-entry suspicion, and subsequent identity-provider activity; the decisive evidence is often in identity and SaaS logs rather than endpoint telemetry.
  • Review whether mobile-device interactions create blind spots, especially when QR codes move the user from corporate email tooling to a less-monitored browser or device.

Mitigation priorities

  • Prioritize user training that specifically covers targeted credential-harvesting links, fake login portals, QR-code phishing, browser-in-the-browser prompts, and reporting suspicious messages.
  • Harden software and service configuration for email, browser, SaaS, and identity platforms, including anti-spoofing and phishing-resistant settings where available.
  • Ensure account containment procedures can rapidly reset credentials, revoke sessions, and review MFA/session activity when a user may have submitted credentials or exposed a session cookie.
  • Test controls with safe simulations that measure reporting, email inspection, URL analysis, QR-code handling, and identity-response workflows rather than only attachment-based phishing.
  • Maintain audit evidence showing training coverage, configuration reviews, phishing-report handling, and incident response decisions for suspected credential exposure.
Additional notes and limits

The ATT&CK object emphasizes information gathering through spearphishing links, including fake portals, URL obfuscation, tracking pixels, browser-in-the-browser deception, adversary-in-the-middle phishing kits, and QR-code phishing. Relationship context includes DET0878 for detection, M1017 and M1054 for mitigation, T1598 as the parent technique, and multiple associated groups and software, including evilginx2. Use those relationships as prioritization context, not proof of current activity in any environment.

MITRE does not provide official detection text for this object in the supplied fields. This take therefore identifies evidence classes and validation questions rather than guaranteed analytics. Actual coverage depends on the organization’s email stack, web controls, identity provider logging, SaaS visibility, mobile telemetry, retention, and phishing-report workflow.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Spearphishing Link

Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Establish Accounts or Compromise Accounts) and/or sending multiple, seemingly urgent messages.

All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, the malicious emails contain links generally accompanied by social engineering text to coax the user to actively click or copy and paste a URL into a browser.[1][2] The given website may be a clone of a legitimate site (such as an online or corporate login portal) or may closely resemble a legitimate site in appearance and have a URL containing elements from the real site. URLs may also be obfuscated by taking advantage of quirks in the URL schema, such as the acceptance of integer- or hexadecimal-based hostname formats and the automatic discarding of text before an “@” symbol: for example, `hxxp://google.com@1157586937`.[3]

Adversaries may also embed “tracking pixels,” "web bugs," or "web beacons" within phishing messages to verify the receipt of an email, while also potentially profiling and tracking victim information such as IP address.[4][5] These mechanisms often appear as small images (typically one pixel in size) or otherwise obfuscated objects and are typically delivered as HTML code containing a link to a remote server.[5][6]

Adversaries may also be able to spoof a complete website using what is known as a "browser-in-the-browser" (BitB) attack. By generating a fake browser popup window with an HTML-based address bar that appears to contain a legitimate URL (such as an authentication portal), they may be able to prompt users to enter their credentials while bypassing typical URL verification methods.[7][8]

Adversaries can use phishing kits such as `EvilProxy` and `Evilginx2` to perform adversary-in-the-middle phishing by proxying the connection between the victim and the legitimate website. On a successful login, the victim is redirected to the legitimate website, while the adversary captures their session cookie (i.e., Steal Web Session Cookie) in addition to their username and password. This may enable the adversary to then bypass MFA via Web Session Cookie.[9]

Adversaries may also send a malicious link in the form of Quick Response (QR) Codes (also known as “quishing”). These links may direct a victim to a credential phishing page.[10] By using a QR code, the URL may not be exposed in the email and may thus go undetected by most automated email security scans.[11] These QR codes may be scanned by or delivered directly to a user’s mobile device (i.e., Phishing), which may be less secure in several relevant ways.[11] For example, mobile users may not be able to notice minor differences between genuine and credential harvesting websites due to mobile’s smaller form factor.

From the fake website, information is gathered in web forms and sent to the adversary. Adversaries may also use information from previous reconnaissance efforts (ex: Search Open Websites/Domains or Search Victim-Owned Websites) to craft persuasive and believable lures.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1598Phishing for InformationThis object subtechnique of Phishing for Information.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0121: Sidewinder

Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.[1][2][3]

GroupEnterprise

G1015: Scattered Spider

Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. [1] [2] The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. [2] Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. [3] [4] [5] Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. [6]

GroupEnterprise

G0129: Mustang Panda

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam. [1][2][3][4][5][6][7][8][9][10][11][12][13]

GroupEnterprise

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

GroupEnterprise

G0122: Silent Librarian

Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies worldwide since at least 2013. Members of Silent Librarian are known to have been affiliated with the Iran-based Mabna Institute which has conducted cyber intrusions at the behest of the government of Iran, specifically the Islamic Revolutionary Guard Corps (IRGC).[1][2][3]

GroupEnterprise

G0128: ZIRCONIUM

ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.[1][2]

GroupEnterprise

G0050: APT32

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]

GroupEnterprise

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

GroupEnterprise

G0059: Magic Hound

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.[1][2][3][4][5]

GroupEnterprise

G0007: APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

GroupEnterprise

G1033: Star Blizzard

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.[1][2][3][4]

GroupEnterprise

G1036: Moonstone Sleet

Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.[1]

ToolEnterprise

S0677: AADInternals

AADInternals is a PowerShell-based framework for administering, enumerating, and exploiting Azure Active Directory. The tool is publicly available on GitHub.[1][2]

WindowsOffice SuiteIdentity Provider
MalwareEnterprise

S0649: SMOKEDHAM

SMOKEDHAM is a Powershell-based .NET backdoor that was first reported in May 2021; it has been used by at least one ransomware-as-a-service affiliate.[1][2]

Windows
ToolEnterprise

S9003: evilginx2

evilginx2 is an open-source adversary-in-the-middle (AiTM) attack framework based on the open-source nginx web server. evilginx2 can be used as a reverse proxy between victims and legitimate web services to intercept and capture credentials, authentication tokens, and session cookies.[1][2][3]

IaaSIdentity ProviderOffice Suite
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.7
Created
Modified
Raw hash
d8ec3cc9a46ec491...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.7Current bundled8ec3cc9a46e…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    TrendMictro Phishing

    Babon, P. (2020, September 3). Tricky 'Forms' of Phishing. Retrieved October 20, 2020.

    Open source URL
  2. [2]
    PCMag FakeLogin

    Kan, M. (2019, October 24). Hackers Try to Phish United Nations Staffers With Fake Login Pages. Retrieved October 20, 2020.

    Open source URL
  3. [3]
    Mandiant URL Obfuscation 2023

    Nick Simonian. (2023, May 22). Don't @ Me: URL Obfuscation Through Schema Abuse. Retrieved August 4, 2023.

    Open source URL
  4. [4]
    NIST Web Bug

    NIST Information Technology Laboratory. (n.d.). web bug. Retrieved March 22, 2023.

    Open source URL
  5. [5]
    Ryte Wiki

    Ryte Wiki. (n.d.). Retrieved November 17, 2024.

    Open source URL
  6. [6]
    IAPP

    IAPP. (n.d.). Retrieved March 5, 2024.

    Open source URL
  7. [7]
    ZScaler BitB 2020

    ZScaler. (2020, February 11). Fake Sites Stealing Steam Credentials. Retrieved March 8, 2023.

    Open source URL
  8. [8]
    Mr. D0x BitB 2022

    mr.d0x. (2022, March 15). Browser In The Browser (BITB) Attack. Retrieved March 8, 2023.

    Open source URL
  9. [9]
    Proofpoint Human Factor

    Proofpoint. (n.d.). The Human Factor 2023: Analyzing the cyber attack chain. Retrieved July 20, 2023.

    Open source URL
  10. [10]
    QR-campaign-energy-firm

    Jonathan Greig. (2023, August 16). Phishing campaign used QR codes to target large energy company. Retrieved November 27, 2023.

    Open source URL
  11. [11]
    qr-phish-agriculture

    Tim Bedard and Tyler Johnson. (2023, October 4). QR Code Scams & Phishing. Retrieved November 27, 2023.

    Open source URL
  12. [12]
    ATT Sidewinder January 2021

    Hegel, T. (2021, January 13). A Global Perspective of the SideWinder APT. Retrieved January 27, 2021.

    Open source URL
  13. [13]
    Check Point Scattered Spider JUL 2025

    Check Point Team. (2025, July 7). Exposing Scattered Spider: New Indicators Highlight Growing Threat to Enterprises and Aviation. Retrieved October 13, 2025.

    Open source URL
  14. [14]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  15. [15]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  16. [16]
    DOJ Iran Indictments March 2018

    DOJ. (2018, March 23). U.S. v. Rafatnejad et al . Retrieved February 3, 2021.

    Open source URL
  17. [17]
    Phish Labs Silent Librarian

    Hassold, Crane. (2018, March 26). Silent Librarian: More to the Story of the Iranian Mabna Institute Indictment. Retrieved February 3, 2021.

    Open source URL
  18. [18]
    Secureworks COBALT DICKENS August 2018

    Counter Threat Unit Research Team. (2018, August 24). Back to School: COBALT DICKENS Targets Universities. Retrieved February 3, 2021.

    Open source URL
  19. [19]
    Proofpoint TA407 September 2019

    Proofpoint Threat Insight Team. (2019, September 5). Threat Actor Profile: TA407, the Silent Librarian. Retrieved February 3, 2021.

    Open source URL
  20. [20]
    Secureworks COBALT DICKENS September 2019

    Counter Threat Unit Research Team. (2019, September 11). COBALT DICKENS Goes Back to School…Again. Retrieved February 3, 2021.

    Open source URL
  21. [21]
    Malwarebytes Silent Librarian October 2020

    Malwarebytes Threat Intelligence Team. (2020, October 14). Silent Librarian APT right on schedule for 20/21 academic year. Retrieved February 3, 2021.

    Open source URL
  22. [22]
    AADInternals Documentation

    Dr. Nestori Syynimaa. (2018, October 25). AADInternals. Retrieved February 18, 2022.

    Open source URL
  23. [23]
    Microsoft Targeting Elections September 2020

    Burt, T. (2020, September 10). New cyberattacks targeting U.S. elections. Retrieved March 24, 2021.

    Open source URL
  24. [24]
    Volexity Ocean Lotus November 2020

    Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020.

    Open source URL
  25. [25]
    VirusBulletin Kimsuky October 2019

    Kim, J. et al. (2019, October). KIMSUKY GROUP: TRACKING THE KING OF THE SPEAR PHISHING. Retrieved November 2, 2020.

    Open source URL
  26. [26]
    Malwarebytes Kimsuky June 2021

    Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.

    Open source URL
  27. [27]
    KISA Operation Muzabi

    KISA. (2021). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 8, 2024.

    Open source URL
  28. [28]
    Proofpoint TA427 April 2024

    Lesnewich, G. et al. (2024, April 16). From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering. Retrieved May 3, 2024.

    Open source URL
  29. [29]
    EnkiWhiteHat_KimsukyDOCSWAP_Dec2025

    EnkiWhiteHat. (2025, December 16). Kimsuky Distributing Malicious Mobile App via QR Code. Retrieved January 8, 2026.

    Open source URL
  30. [30]
    FBI_KimsukyQR_Jan2026

    FBI. (2026, January 8). FBI Flash AC-000001-MW North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities. Retrieved April 18, 2026.

    Open source URL
  31. [31]
    Certfa Charming Kitten January 2021

    Certfa Labs. (2021, January 8). Charming Kitten’s Christmas Gift. Retrieved May 3, 2021.

    Open source URL
  32. [32]
    ClearSky Kittens Back 3 August 2020

    ClearSky Research Team. (2020, August 1). The Kittens Are Back in Town 3 - Charming Kitten Campaign Evolved and Deploying Spear-Phishing link by WhatsApp. Retrieved April 21, 2021.

    Open source URL
  33. [33]
    Proofpoint TA453 March 2021

    Miller, J. et al. (2021, March 30). BadBlood: TA453 Targets US and Israeli Medical Research Personnel in Credential Phishing Campaigns. Retrieved May 4, 2021.

    Open source URL
  34. [34]
    Proofpoint TA453 July2021

    Miller, J. et al. (2021, July 13). Operation SpoofedScholars: A Conversation with TA453. Retrieved August 18, 2021.

    Open source URL
  35. [35]
    Google Iran Threats October 2021

    Bash, A. (2021, October 14). Countering threats from Iran. Retrieved January 4, 2023.

    Open source URL
  36. [36]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  37. [37]
    FireEye Shining A Light on DARKSIDE May 2021

    FireEye. (2021, May 11). Shining a Light on DARKSIDE Ransomware Operations. Retrieved September 22, 2021.

    Open source URL
  38. [38]
    Google TAG Ukraine Threat Landscape March 2022

    Huntley, S. (2022, March 7). An update on the threat landscape. Retrieved March 16, 2022.

    Open source URL
  39. [39]
    DOJ GRU Indictment Jul 2018

    Mueller, R. (2018, July 13). Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al. Retrieved November 17, 2024.

    Open source URL
  40. [40]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  41. [41]
    US District Court Indictment GRU Oct 2018

    Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020.

    Open source URL
  42. [42]
    Secureworks IRON TWILIGHT Active Measures March 2017

    Secureworks CTU. (2017, March 30). IRON TWILIGHT Supports Active Measures. Retrieved February 28, 2022.

    Open source URL
  43. [43]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  44. [44]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  45. [45]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  46. [46]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  47. [47]
    Microsoft Moonstone Sleet 2024

    Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.

    Open source URL
  48. [48]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  49. [49]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  50. [50]
    Breakdev Evilginx 2.3 JAN 2019

    Gretzky, K. (2019, January 18). Evilginx 2.3 - Phisherman's Dream. Retrieved January 27, 2026.

    Open source URL
  51. [51]
    Breakdev Evilginx 3.3 APR 2024

    Gretzky, K. (2024, April 2). Evilginx 3.3 - Go & Phish. Retrieved January 27, 2026.

    Open source URL
  52. [52]
    Sophos Evilginx MAR 2025

    Everts, M. (2025, March 28). Stealing user credentials with evilginx. Retrieved January 27, 2026.

    Open source URL
  53. [53]
    Volexity Patchwork June 2018

    Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.

    Open source URL
  54. [54]
    Microsoft Anti Spoofing

    Microsoft. (2020, October 13). Anti-spoofing protection in EOP. Retrieved October 19, 2020.

    Open source URL
  55. [55]
    ACSC Email Spoofing

    Australian Cyber Security Centre. (2012, December). Mitigating Spoofed Emails Using Sender Policy Framework. Retrieved November 17, 2024.

    Open source URL
  56. [56]
    ACSC Email Spoofing

    Australian Cyber Security Centre. (2012, December). Mitigating Spoofed Emails Using Sender Policy Framework. Retrieved November 17, 2024.

    Open source URL
  57. [57]
    ACSC Email Spoofing

    Australian Cyber Security Centre. (2012, December). Mitigating Spoofed Emails Using Sender Policy Framework. Retrieved November 17, 2024.

    Open source URL
  58. [58]
    IAPP

    IAPP. (n.d.). Retrieved March 5, 2024.

    Open source URL
  59. [59]
    IAPP

    IAPP. (n.d.). Retrieved March 5, 2024.

    Open source URL
  60. [60]
    Mandiant URL Obfuscation 2023

    Nick Simonian. (2023, May 22). Don't @ Me: URL Obfuscation Through Schema Abuse. Retrieved August 4, 2023.

    Open source URL
  61. [61]
    Mandiant URL Obfuscation 2023

    Nick Simonian. (2023, May 22). Don't @ Me: URL Obfuscation Through Schema Abuse. Retrieved August 4, 2023.

    Open source URL
  62. [62]
    Microsoft Anti Spoofing

    Microsoft. (2020, October 13). Anti-spoofing protection in EOP. Retrieved October 19, 2020.

    Open source URL
  63. [63]
    Microsoft Anti Spoofing

    Microsoft. (2020, October 13). Anti-spoofing protection in EOP. Retrieved October 19, 2020.

    Open source URL
  64. [64]
    Mr. D0x BitB 2022

    mr.d0x. (2022, March 15). Browser In The Browser (BITB) Attack. Retrieved March 8, 2023.

    Open source URL
  65. [65]
    Mr. D0x BitB 2022

    mr.d0x. (2022, March 15). Browser In The Browser (BITB) Attack. Retrieved March 8, 2023.

    Open source URL
  66. [66]
    NIST Web Bug

    NIST Information Technology Laboratory. (n.d.). web bug. Retrieved March 22, 2023.

    Open source URL
  67. [67]
    NIST Web Bug

    NIST Information Technology Laboratory. (n.d.). web bug. Retrieved March 22, 2023.

    Open source URL
  68. [68]
    PCMag FakeLogin

    Kan, M. (2019, October 24). Hackers Try to Phish United Nations Staffers With Fake Login Pages. Retrieved October 20, 2020.

    Open source URL
  69. [69]
    PCMag FakeLogin

    Kan, M. (2019, October 24). Hackers Try to Phish United Nations Staffers With Fake Login Pages. Retrieved October 20, 2020.

    Open source URL
  70. [70]
    Proofpoint Human Factor

    Proofpoint. (n.d.). The Human Factor 2023: Analyzing the cyber attack chain. Retrieved July 20, 2023.

    Open source URL
  71. [71]
    Proofpoint Human Factor

    Proofpoint. (n.d.). The Human Factor 2023: Analyzing the cyber attack chain. Retrieved July 20, 2023.

    Open source URL
  72. [72]
    QR-campaign-energy-firm

    Jonathan Greig. (2023, August 16). Phishing campaign used QR codes to target large energy company. Retrieved November 27, 2023.

    Open source URL
  73. [73]
    QR-campaign-energy-firm

    Jonathan Greig. (2023, August 16). Phishing campaign used QR codes to target large energy company. Retrieved November 27, 2023.

    Open source URL
  74. [74]
    Ryte Wiki

    Ryte Wiki. (n.d.). Retrieved November 17, 2024.

    Open source URL
  75. [75]
    Ryte Wiki

    Ryte Wiki. (n.d.). Retrieved November 17, 2024.

    Open source URL
  76. [76]
    TrendMictro Phishing

    Babon, P. (2020, September 3). Tricky 'Forms' of Phishing. Retrieved October 20, 2020.

    Open source URL
  77. [77]
    TrendMictro Phishing

    Babon, P. (2020, September 3). Tricky 'Forms' of Phishing. Retrieved October 20, 2020.

    Open source URL
  78. [78]
    ZScaler BitB 2020

    ZScaler. (2020, February 11). Fake Sites Stealing Steam Credentials. Retrieved March 8, 2023.

    Open source URL
  79. [79]
    ZScaler BitB 2020

    ZScaler. (2020, February 11). Fake Sites Stealing Steam Credentials. Retrieved March 8, 2023.

    Open source URL
  80. [80]
    mitre-attackT1598.003
    Open source URL
  81. [81]
    mitre-attackT1598.003
    Open source URL
  82. [82]
    mitre-attackT1598.003
    Open source URL
  83. [83]
    qr-phish-agriculture

    Tim Bedard and Tyler Johnson. (2023, October 4). QR Code Scams & Phishing. Retrieved November 27, 2023.

    Open source URL
  84. [84]
    qr-phish-agriculture

    Tim Bedard and Tyler Johnson. (2023, October 4). QR Code Scams & Phishing. Retrieved November 27, 2023.

    Open source URL
  85. [85]
    ATT Sidewinder January 2021

    Hegel, T. (2021, January 13). A Global Perspective of the SideWinder APT. Retrieved January 27, 2021.

    Open source URL
  86. [86]
    Check Point Scattered Spider JUL 2025

    Check Point Team. (2025, July 7). Exposing Scattered Spider: New Indicators Highlight Growing Threat to Enterprises and Aviation. Retrieved October 13, 2025.

    Open source URL
  87. [87]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  88. [88]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  89. [89]
    DOJ Iran Indictments March 2018

    DOJ. (2018, March 23). U.S. v. Rafatnejad et al . Retrieved February 3, 2021.

    Open source URL
  90. [90]
    Malwarebytes Silent Librarian October 2020

    Malwarebytes Threat Intelligence Team. (2020, October 14). Silent Librarian APT right on schedule for 20/21 academic year. Retrieved February 3, 2021.

    Open source URL
  91. [91]
    Phish Labs Silent Librarian

    Hassold, Crane. (2018, March 26). Silent Librarian: More to the Story of the Iranian Mabna Institute Indictment. Retrieved February 3, 2021.

    Open source URL
  92. [92]
    Proofpoint TA407 September 2019

    Proofpoint Threat Insight Team. (2019, September 5). Threat Actor Profile: TA407, the Silent Librarian. Retrieved February 3, 2021.

    Open source URL
  93. [93]
    Secureworks COBALT DICKENS August 2018

    Counter Threat Unit Research Team. (2018, August 24). Back to School: COBALT DICKENS Targets Universities. Retrieved February 3, 2021.

    Open source URL
  94. [94]
    Secureworks COBALT DICKENS September 2019

    Counter Threat Unit Research Team. (2019, September 11). COBALT DICKENS Goes Back to School…Again. Retrieved February 3, 2021.

    Open source URL
  95. [95]
    AADInternals Documentation

    Dr. Nestori Syynimaa. (2018, October 25). AADInternals. Retrieved February 18, 2022.

    Open source URL
  96. [96]
    Microsoft Targeting Elections September 2020

    Burt, T. (2020, September 10). New cyberattacks targeting U.S. elections. Retrieved March 24, 2021.

    Open source URL
  97. [97]
    Volexity Ocean Lotus November 2020

    Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020.

    Open source URL
  98. [98]
    EnkiWhiteHat_KimsukyDOCSWAP_Dec2025

    EnkiWhiteHat. (2025, December 16). Kimsuky Distributing Malicious Mobile App via QR Code. Retrieved January 8, 2026.

    Open source URL
  99. [99]
    FBI_KimsukyQR_Jan2026

    FBI. (2026, January 8). FBI Flash AC-000001-MW North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities. Retrieved April 18, 2026.

    Open source URL
  100. [100]
    KISA Operation Muzabi

    KISA. (2021). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 8, 2024.

    Open source URL
  101. [101]
    Malwarebytes Kimsuky June 2021

    Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.

    Open source URL
  102. [102]
    Proofpoint TA427 April 2024

    Lesnewich, G. et al. (2024, April 16). From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering. Retrieved May 3, 2024.

    Open source URL
  103. [103]
    VirusBulletin Kimsuky October 2019

    Kim, J. et al. (2019, October). KIMSUKY GROUP: TRACKING THE KING OF THE SPEAR PHISHING. Retrieved November 2, 2020.

    Open source URL
  104. [104]
    Certfa Charming Kitten January 2021

    Certfa Labs. (2021, January 8). Charming Kitten’s Christmas Gift. Retrieved May 3, 2021.

    Open source URL
  105. [105]
    ClearSky Kittens Back 3 August 2020

    ClearSky Research Team. (2020, August 1). The Kittens Are Back in Town 3 - Charming Kitten Campaign Evolved and Deploying Spear-Phishing link by WhatsApp. Retrieved April 21, 2021.

    Open source URL
  106. [106]
    Google Iran Threats October 2021

    Bash, A. (2021, October 14). Countering threats from Iran. Retrieved January 4, 2023.

    Open source URL
  107. [107]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  108. [108]
    Proofpoint TA453 July2021

    Miller, J. et al. (2021, July 13). Operation SpoofedScholars: A Conversation with TA453. Retrieved August 18, 2021.

    Open source URL
  109. [109]
    Proofpoint TA453 March 2021

    Miller, J. et al. (2021, March 30). BadBlood: TA453 Targets US and Israeli Medical Research Personnel in Credential Phishing Campaigns. Retrieved May 4, 2021.

    Open source URL
  110. [110]
    FireEye Shining A Light on DARKSIDE May 2021

    FireEye. (2021, May 11). Shining a Light on DARKSIDE Ransomware Operations. Retrieved September 22, 2021.

    Open source URL
  111. [111]
    DOJ GRU Indictment Jul 2018

    Mueller, R. (2018, July 13). Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al. Retrieved November 17, 2024.

    Open source URL
  112. [112]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  113. [113]
    Google TAG Ukraine Threat Landscape March 2022

    Huntley, S. (2022, March 7). An update on the threat landscape. Retrieved March 16, 2022.

    Open source URL
  114. [114]
    Secureworks IRON TWILIGHT Active Measures March 2017

    Secureworks CTU. (2017, March 30). IRON TWILIGHT Supports Active Measures. Retrieved February 28, 2022.

    Open source URL
  115. [115]
    US District Court Indictment GRU Oct 2018

    Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020.

    Open source URL
  116. [116]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  117. [117]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  118. [118]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  119. [119]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  120. [120]
    Microsoft Moonstone Sleet 2024

    Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.

    Open source URL
  121. [121]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  122. [122]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  123. [123]
    Breakdev Evilginx 2.3 JAN 2019

    Gretzky, K. (2019, January 18). Evilginx 2.3 - Phisherman's Dream. Retrieved January 27, 2026.

    Open source URL
  124. [124]
    Breakdev Evilginx 3.3 APR 2024

    Gretzky, K. (2024, April 2). Evilginx 3.3 - Go & Phish. Retrieved January 27, 2026.

    Open source URL
  125. [125]
    Sophos Evilginx MAR 2025

    Everts, M. (2025, March 28). Stealing user credentials with evilginx. Retrieved January 27, 2026.

    Open source URL
  126. [126]
    Volexity Patchwork June 2018

    Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.

    Open source URL
  127. [127]
    ACSC Email Spoofing

    Australian Cyber Security Centre. (2012, December). Mitigating Spoofed Emails Using Sender Policy Framework. Retrieved November 17, 2024.

    Open source URL
  128. [128]
    Microsoft Anti Spoofing

    Microsoft. (2020, October 13). Anti-spoofing protection in EOP. Retrieved October 19, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.