T1566.001 - Spearphishing Attachment - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
472
occurrences
First Seen
October 31, 2025
Last Seen
August 31, 2026

Related Threat Clusters

  • Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities

    Active exploitation of two critical vulnerabilities has been reported: CVE-2026-20230 in Cisco Unified CM and CVE-2026-20971 in Samsung KNOX. The Cisco flaw, a server-side request forgery (SSRF), poses an immediate…

    4 articles · Updated June 23, 2026
  • Lazarus Group Exploits Windows Zero-Day to Target Defense Sector

    The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…

    33 articles · Updated August 12, 2026
  • Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign

    Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…

    82 articles · Updated July 23, 2026
  • Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign

    Gamaredon, a Russian state-backed APT group, is actively exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy malware against Ukrainian government and military targets. The attack begins with a spearphishing…

    7 articles · Updated June 2, 2026
  • GhostShell Malware Targets Ukraine's UAV and Defense Supply Chain

    The GhostShell malware cluster is actively targeting Ukraine’s UAV operations and defense supply chain. Utilizing advanced techniques such as mTLS-authenticated implants and Telegram-based loaders, the attackers gain…

    2 articles · Updated June 25, 2026
  • Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations

    Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…

    19 articles · Updated June 8, 2026
  • Gamaredon APT Escalates Cyber Operations Against Ukraine in 2025

    The Gamaredon group, a Russian-aligned APT, has significantly upgraded its cyber capabilities in 2025, focusing on spear-phishing campaigns against Ukrainian targets. ESET Research reports that Gamaredon conducted 35…

    7 articles · Updated June 25, 2026
  • Armored Likho APT Targets Power Grids with BusySnake Stealer Malware

    A newly identified APT group, Armored Likho, is conducting a phishing campaign targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. The group employs a sophisticated infostealer…

    7 articles · Updated July 4, 2026
  • Kimsuky Expands AI Capabilities for Cyberattacks

    The North Korean hacking group Kimsuky has developed local AI tools to enhance its cyberattack capabilities, as reported by Genians Security Center on August 10, 2026. The group is utilizing large language models (LLMs)…

    49 articles · Updated August 10, 2026
  • APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign

    Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…

    100 articles · Updated April 7, 2026

Recent Intelligence Reports

  • Seqrite Uncovers China-Linked Cyber Espionage Campaign Targeting India's Tax Ecosystem — Itvoice.In · August 31, 2026
  • Diari d'Andorra • Aug 28, 2026 • 20:59 Alerta per una campanya de ciberatacs dirigida als hotels d’Andorra — www.diariandorra.ad · August 29, 2026
  • New campaign targets Cambodia with Spark RAT using BYOVD technique | brief — Scworld · August 28, 2026
  • Optery Highlights Emerging Social Engineering Threats in New Dispatch Issue — Tipranks · August 27, 2026
  • What Are Social Engineering Attacks — www.techtarget.com · August 27, 2026
  • BlueDelta Targets Defense and Diplomacy with HOOKEDGE — Recordedfuture · August 27, 2026
  • Dark Caracal Mobile Apt — www.lookout.com · August 26, 2026
  • CRPx0 - Threat Actor Profile — Kelacyber · August 26, 2026

CVSS v3.1 Breakdown