T1566.002 Phishing Link is an initial access technique in MITRE ATT&CK where attackers send phishing emails containing malicious hyperlinks that direct users to credential harvesting pages or malware payloads, enabling remote access or execution.
Overview
T1566.002 Phishing Link is an initial access technique in MITRE ATT&CK where attackers send phishing emails containing malicious hyperlinks that direct users to credential harvesting pages or malware payloads, enabling remote access or execution. It remains a common and effective vector due to its wide reach and potential to bypass some defenses, making it a persistent threat to organizations and critical infrastructure.
Related Threat Clusters
-
Hackers Collaborate with Organized Crime to Steal Cargo Shipments
Cybercriminals are infiltrating trucking and freight companies to steal cargo shipments before they reach stores. Research from Proofpoint indicates that these hackers are using remote monitoring and management tools to…
11 articles · Updated November 4, 2025 -
Hackers Collaborate with Organized Crime to Steal Cargo Shipments
Cybercriminals are partnering with organized crime groups to hijack cargo shipments from trucking and freight companies. Utilizing remote monitoring and management tools, these hackers are able to infiltrate logistics…
18 articles · Updated December 1, 2025
Recent Intelligence Reports
- Hackers Weaponize Remote Tools to Hijack Cargo Freight — Darkreading · November 3, 2025