T1566, Spearphishing, is a MITRE ATT&CK technique in which attackers target specific individuals or organizations with crafted emails containing links or attachments to steal credentials or deploy malware.
Overview
T1566, Spearphishing, is a MITRE ATT&CK technique in which attackers target specific individuals or organizations with crafted emails containing links or attachments to steal credentials or deploy malware. It remains a primary initial access vector across ransomware, espionage, and APT campaigns, with evolving variants such as quishing (QR code-based phishing) that exploit messaging channels beyond traditional attachments.
Related Threat Clusters
-
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
9 articles · Updated November 14, 2025 -
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
The Russian state-backed hacking group Sandworm has intensified its operations against Ukrainian organizations by deploying data-wiping malware. This campaign targets critical sectors, including the grain industry, and…
6 articles · Updated November 7, 2025 -
Iran-aligned APT-C-07 Uses Infy, Foudre, and Tonnerre Malware for Cyber Espionage
The Prince of Persia APT, also known as APT-C-07, has been active since 2007 and is linked to Iranian cyber-espionage efforts. This group employs various malware families, including Infy, Foudre, and Tonnerre, to target…
1 article · Updated January 16, 2026 -
Sandworm Hackers Target Ukraine's Grain Sector with Data-Wiping Malware
The Russian state-backed hacker group Sandworm has launched a campaign using data-wiping malware against Ukrainian organizations, particularly focusing on the grain sector. This attack aims to disrupt critical…
9 articles · Updated November 8, 2025 -
APT Hackers Target Indian Government with GOGITTER and GITSHELLPAD Malware
In September 2025, advanced persistent threat actors from Pakistan launched coordinated cyberattacks against Indian government organizations using the GOGITTER tool and GITSHELLPAD malware. This campaign, known as…
3 articles · Updated January 27, 2026 -
Data Recovery from INC Ransomware Due to Operational Security Lapse
An operational security failure by the INC ransomware gang allowed researchers to recover data stolen from twelve U.S. organizations. Cyber Centaurs, a digital forensics firm, discovered the gang's cloud storage…
5 articles · Updated January 23, 2026 -
APT24 Uses BadAudio Malware in Ongoing Espionage Campaign
APT24, a China-linked hacking group, has been utilizing a previously undocumented malware named BadAudio in a three-year espionage campaign. This malware has been delivered through various methods, including…
6 articles · Updated November 20, 2025 -
Kimsuky APT Group Targets Institutions with Quishing Attacks
The FBI has issued a warning regarding the North Korea-linked APT group Kimsuky, which is conducting quishing attacks targeting governments, think tanks, and academic institutions. These attacks involve spear-phishing…
2 articles · Updated January 10, 2026 -
Cybersecurity Challenges in Higher Education Institutions
Higher education institutions are facing significant cybersecurity threats, including ransomware, phishing, and data breaches. These challenges are exacerbated by the shift to digital learning and insufficient budgets,…
159 articles · Updated January 30, 2026 -
Threat Actor Conducts Large-Scale Exploit Testing Before Ransomware Deployment
Between December 25–28, 2025, a threat actor executed a scanning campaign targeting internet-facing systems, testing over 240 different exploits. This operation, linked to CTG Server Limited, aimed to identify and…
3 articles · Updated January 9, 2026
Recent Intelligence Reports
- Cybersecurity Threats to Universities and Colleges — Timeshighereducation · January 30, 2026
- Cyber's New Reality: AI, Deepfakes, And Double Extortion (Podcast) — Mondaq · January 28, 2026
- Pakistan-Linked APT Deploys GOGITTER, GITSHELLPAD In Strikes On Indian Government — Cyberpress · January 27, 2026
- Cyber's New Reality: AI, Deepfakes, and Double Extortion — Goodwinlaw · January 26, 2026
- Infostealer Trove: 149 Million Logins Exposed in Open Database Nightmare — Webpronews · January 25, 2026
- Canadian Securities Regulators Warn Registrants About New Impersonation Scam — Mondovisione · January 25, 2026
- Database Containing 149M Stolen Passwords From Gmail, Instagram, More Exposes ... — Au.Pcmag · January 24, 2026
- Nearly 150 Million Online Accounts Exposed In Massive Data Leak - Evrim Ağacı — Evrimagaci · January 24, 2026