FORENSIA

ATT&CK · T1566

Phishing

Tactics: initial-access

About

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms. Phishing may also involve social engineering techniques, such as posing as a trusted source, as well as evasive techniques such as removing or manipulating emails or metadata/headers from compromised accounts being abused to send messages (e.g., Email Hiding Rules). Another way to accomplish this is by Email Spoofing the identity of the sender, which can be used to fool both the human recipient as well as automated security tools, or by including the intended target as a party to an existing email thread that includes malicious files or links (i.e., "thread hijacking"). Victims may also receive phishing messages that instruct them to call a phone number where they are directed to visit a malicious URL, download malware, or install adversary-accessible remote management tools onto their computer (i.e., User Execution).

Platforms: Identity Provider, Linux, macOS, Office Suite, SaaS, WindowsMITRE ATT&CK ↗

Used by actors

8 known groups

Software

3 malware/tools implement this

HikitRoyalINC Ransomware

Corpus indicators tagged with this technique

1,680 indicators in the corpus carry T1566.

IndicatorTypeFamilySevSrc
07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841sha256phishing801
b0e292346b4ab3f83fadd8abcce7cfc5b9d50ef73ad141e8bc4a4689fee13504hashransomware802
69315b7a1c4bf5ee56cba1de29d1761ehashcryptojacking802
3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5sha256phishing801
3e7066e44132e64360a30974b6ea3671hash803
40b41979b317406f8abc601677a3b93aaf6ef8ab8ac188b8f383735e388f13b5hash803
50eda29bfbeeb8b0429718447725016ahashcryptojacking802
5d253cc263851ec68c0a988bf86afbb3e9f0b491hashcryptojacking802
e84b1e2c432b2394c403b524b8361ffa9923a022eb05215f1dc811bc167c3c5ehashcryptojacking802
c5a53c02d531c5e46f9cc2fc0afbb88dhashcryptojacking802
41f581f7d2c09ab0edfea850b9db506fhashcryptojacking802
a08d8e63b0cd3638fb40b8e6da546e26da69439597565827f9cec87915f78568sha256ransomware801
e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95sha256phishing801
b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173sha256phishing801
bd46890121106b43f0c01ab82629400chashcryptojacking802
579a82dde4425d95e20a22171be0a37702c833fdca6e5e04f69099a025863136hashcryptojacking802
ce62d1b6116f34f9ba815db1e2016d2ahashcryptojacking802
1fc5e6458316277fae8272cbe9f3dfc86b681635hashcryptojacking802
89930bd18e0f9c9c98dfb1662cb87aa98348e87164ab62b1f39e86ebf2ce24cbhashcryptojacking802
b5da6ffa5f85aa5016fbc02a3122361c85d21192c45df9544099d13e6ff84c36hashcryptojacking802
d42aecf76fb1531cd5b7139e669910b2fd82a90b7e11448128e226775bf5d42ehashcryptojacking802
b6a77b7892ef22d6afd91eb980a3f3d8hashcryptojacking802
a30a9779079dc897a15fed27f27f614fab77a20e953368808ba99ac6c6a3375bsha256phishing801
462af0a3a9094d44c30cc65544ec1171a62365cff09e67f5e87e061a3d604bd0hashcryptojacking802
3d1158884fb339b3328bd330fcc27598e1f1c94bcac39e75d1a272afa4deee1asha256ransomware801
a14bed1c46ba7406d5240e979251ccd394dfe3b5hashcryptojacking802
93b3d3925ccc201ab0f16017153a79ef05b8f5c2hashcryptojacking802
a37f6403fbf28fa0b48863287f4c5a5dhashcryptojacking802
670384fafb23140d96f2f8fe04a13fc8cc8e2a6e5e8c973e39b58d103c5fea92sha256phishing801
87480b151e465b73151220533c965f3a77046138f079ca3ceb961a7d5fee9a33hash801

Showing the top 30 by severity of 1,680.