T1566.002 - Phishing Link - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 3, 2025
Last Seen
November 3, 2025

T1566.002 Phishing Link is an initial access technique in MITRE ATT&CK where attackers send phishing emails containing malicious hyperlinks that direct users to credential harvesting pages or malware payloads, enabling remote access or execution.

Overview

T1566.002 Phishing Link is an initial access technique in MITRE ATT&CK where attackers send phishing emails containing malicious hyperlinks that direct users to credential harvesting pages or malware payloads, enabling remote access or execution. It remains a common and effective vector due to its wide reach and potential to bypass some defenses, making it a persistent threat to organizations and critical infrastructure.

Related Threat Clusters

  • Hackers Collaborate with Organized Crime to Steal Cargo Shipments

    Cybercriminals are infiltrating trucking and freight companies to steal cargo shipments before they reach stores. Research from Proofpoint indicates that these hackers are using remote monitoring and management tools to…

    11 articles · Updated November 4, 2025
  • Hackers Collaborate with Organized Crime to Steal Cargo Shipments

    Cybercriminals are partnering with organized crime groups to hijack cargo shipments from trucking and freight companies. Utilizing remote monitoring and management tools, these hackers are able to infiltrate logistics…

    18 articles · Updated December 1, 2025

Recent Intelligence Reports

  • Hackers Weaponize Remote Tools to Hijack Cargo Freight — Darkreading · November 3, 2025

CVSS v3.1 Breakdown