FORENSIA

ATT&CK · T1566.002 · sub-technique

Spearphishing Link

Tactics: initial-access

About

Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this case, the malicious emails contain links. Generally, the links will be accompanied by social engineering text and require the user to actively click or copy and paste a URL into a browser, leveraging User Execution. The visited website may compromise the web browser using an exploit, or the user will be prompted to download applications, documents, zip files, or even executables depending on the pretext for the email in the first place. Adversaries may also include links that are intended to interact directly with an email reader, including embedded images intended to exploit the end system directly. Additionally, adversaries may use seemingly benign links that abuse special characters to mimic legitimate websites (known as an "IDN homograph attack"). URLs may also be obfuscated by taking advantage of quirks in the URL schema, such as the acceptance of integer- or hexadecimal-based hostname formats and the automatic discarding of text before an “@” symbol: for example, `hxxp://google.com@1157586937`. Adversaries may also utilize links to perform consent phishing/spearphishing campaigns to Steal Application Access Tokens that grant immediate access to the victim environment. For example, a user may be lured into granting adversaries permissions/access via a malicious OAuth 2.0 request URL that when accepted by the user provide permissions/access for malicious applications. These stolen access tokens allow the adversary to perform various actions on behalf of the user via API calls. Similarly, malicious links may also target device-based authorization, such as OAuth 2.0 device authorization grant flow which is typically used to authenticate devices without UIs/browsers. Known as “device code phishing,” an adversary may send a link that directs the victim to a malicious authorization page where the user is tricked into entering a code/credentials that produces a device token.

Platforms: Identity Provider, Linux, macOS, Office Suite, SaaS, WindowsParent: T1566 PhishingMITRE ATT&CK ↗

Corpus indicators tagged with this technique

6,937 indicators in the corpus carry T1566.002.

IndicatorTypeFamilySevSrc
d6f479736ba55d3c4e895c4940d035cf772f3192fb8dc496f09a801aed16d970sha256phishing801
8111edf01ac6cb5c77e249d4e84fd92a85b5e89c2e2bef92fbe00b6f1cc2aa8esha256phishing801
7aa76237a7686583cc526b9d1a8486a52bd44a448d75ced51e1df4ba29ddb163sha256phishing802
d7d2f0ee187549f3f4a114d716be12521fbf62d6d26e2ac23d2a32d521d08fd8sha256phishing801
7900c2772680523cadc9fe4e07300d45500191ba64ff5b91573531b133840b14sha256phishing802
833008c03d40422192051584d829d730497108bef31751cceb0cc043dd96bbfbsha256phishing801
44a4ac119349f525d877728b53fe38453a516881d577679caf08ab69312a695fsha256phishing802
771a47120b935e218322046e838347d722d265b91f1afdef91194a5bec86a97asha256phishing802
e5e43b0830369c39fab45363486da4d21a98c5097ea262c9816997f11c73c1c4hashphishing802
adcd15f3d6b87f84d106ea426fa824fd20c9d64f6d199ce92580884290785f30sha256phishing801
62a879b0d1c1649cc72b2b6f61a8f6bd888625ce6e8a7aefe0a0461e4f27c525sha256phishing802
9758e76b601798a30d903bf05052a53df80451e5c156548ce9da828f608b6470sha256801
25b6fc4f9c54a28ba7bfc4dfeafb62c99b59ea6f0d17679219b876b321965095sha256phishing801
067ad6221b2224d5cdb64e51c5516132d820cf4d7edf9ec170643943e79c04b7sha256phishing801
23b37d2ebe683cec3b145b6f2234ee728b99228cf3774399fcfad9502daab9a9sha256phishing802
43d597783af656a35184021f5e20686896463a1712f9216e0217a2ca740e3935sha256phishing802
248ded4723e9f5da793e5e42d1ba7c2293dd704718f149b84b3b9b818a1f51dbsha256phishing802
669002654c264191d4660fbf757860d930175649735f81370b9f1af3658a304csha256phishing802
e4ccb2328c06710a7f0254cb6315e1b106396b0ff525f9cf3eada6e85d285c1csha256801
107b5aa3c4ef30b9b832e0a10b1efb1dcf433158bc6af8d890d66c0c9ed50d21sha256801
7b297f18ece81e87608e158288cc9c06cb9f4a8f1b2d2256aecf7bba8d7be2absha256phishing802
7b7981c99d59595fe15377df84695bb72ce0b85560a3935f930657b2d162e5efsha256phishing801
221a39856b37e3c682f62427f1e6b965b36a2405764689c914672770a01a1fa9sha256801
50ebf107d522326c9a9db8821fe3263aa5136964faaf5dd183657bbb52725f84sha256phishing802
5115277eabf2d22d49dcef1e155874387d8e783853bd86debf7ff58588aae35dsha256phishing802
5272917261d7091a59e00f9d09cd7eb1d3e111115a5b367f79a66d0d7c7b01f4sha256phishing802
22de84e8f29cba932cf65cf4dc1d333cb8b2e468204f97030712bee32691ac3bsha256phishing802
5ab41cf20315d2ea1385967d588159873a65ef5581a0b78de06c0d8617894194sha256phishing802
60972abf5425c191c81bae117f1dedaea13d39bc52f367d5dff9ad1aa4b9c5casha256phishing802
f0038a5f46720da5982b6984ceef10cf99359432e102b12a0b0657498d36f670sha256phishing801

Showing the top 30 by severity of 6,937.