If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1566 - Phishing, Technique T1566 - En.

site address: attack.mitre.org/techniques/T1566 redirected to: attack.mitre.org/techniques/T1566

site title: Phishing, Technique T1566 - Enterprise MITRE ATT&CK®

Our opinion (on Thursday 20 August 2026 20:07:05 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

phishing, procedure, examples, mitigations, detection, strategy, references, sub, techniques,

Text of the page (most frequently used words):
#phishing (30), and (25), retrieved (25), the (16), email (16), 2023 (13), all (11), 2024 (11), march (11), malicious (11), att (10), used (10), has (10), t1566 (10), techniques (9), may (9), access (9), spearphishing (9), 2026 (8), detection (8), messages (8), can (8), are (7), enterprise (7), emails (7), threat (7), ransomware (7), february (7), campaigns (6), royal (6), inc (6), attachments (6), through (6), activity (6), for (6), victims (6), initial (6), ics (5), mobile (5), none (5), software (5), october (5), spoofing (5), april (5), september (5), that (5), where (5), suspicious (5), execution (5), network (5), such (5), systems (5), gain (5), mitre (4), use (4), 2020 (4), with (4), via (4), platforms (4), urls (4), anomalous (4), file (4), attempts (4), from (4), links (4), social (4), version (4), cti (3), data (3), mitigations (3), defenses (3), sub (3), core (3), cyber (3), security (3), using (3), sender (3), november (3), microsoft (3), anti (3), handala (3), intelligence (3), domain (3), org (3), sea (3), turtle (3), hijacking (3), 2025 (3), actors (3), january (3), group (3), ransom (3), axiom (3), 2014 (3), thread (3), services (3), spread (3), spam (3), delivered (3), saas (3), based (3), office (3), files (3), description (3), name (3), engineering (3), well (3), void (3), manticore (3), spear (3), victim (3), also (3), tools (3), adversaries (3), send (3), targeted (3), corporation (2), policy (2), domains (2), resources (2), reference (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), objects (2), december (2), linked (2), support (2), seizure (2), 2019 (2), service (2), cisa (2), cybereason (2), research (2), 2022 (2), operations (2), what (2), june (2), web (2), luna (2), moth (2), campaign (2), remote (2), management (2), itkin (2), liora (2), link (2), after (2), login (2), delivery (2), containing (2), embedded (2), processes (2), correlating (2), logs (2), process (2), outbound (2), connections (2), mail (2), unusual (2), creation (2), users (2), metadata (2), message (2), strategy (2), analytic (2), identify (2), user (2), mechanisms (2), perform (2), attachment (2), etc (2), intrusion (2), prevention (2), insecure (2), been (2), including (2), call (2), number (2), muddywater (2), kimsuky (2), hikit (2), conducted (2), gold (2), southfield (2), applejeus (2), identity (2), 004 (2), 003 (2), 002 (2), 001 (2), malware (2), adversary (2), party (2), more (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, terms, contact, reset, filters, australian, centre, 2012, mitigating, spoofed, framework, protection, eop, domaintools, investigations, mois, influence, ecosystem, assessment, doj, fbi, case, 00683, cda, affidavit, warrant, matter, names, justicehomeland, karmabelow80, hack, redwatned, cisco, talos, dns, abuses, trust, internet, stopransomware, iacono, green, deep, dive, global, soc, teams, rumble, analysis, naumaan, around, world, days, state, sponsored, try, clickfix, mandiant, apt43, north, korean, uses, cybercrime, fund, espionage, staying, ahead, age, sentinelone, socradar, dark, profile, counter, unit, team, revil, sodinokibi, august, novetta, operation, smn, actor, report, esler, lee, williams, spotlight, 2016, michael, barni, barnhart, dtex, anonymous, smes, exposing, dprk, syndicate, hidden, workforce, kristopher, russo, callback, protecting, against, monitoring, oren, biderman, tomer, lahiyani, noam, lifshitz, ori, porag, behind, recent, false, subscription, scams, brian, krebs, phishes, prey, your, curiosity, double, bounced, attacks, proofpoint, vicky, ray, rob, downs, examining, vba, initiated, infostealer, oauth, applications, abuse, cloud, references, chat, collaboration, contain, detect, clicks, uploads, token, misuse, an0193, targeting, idps, often, manifest, invitations, fake, sso, prompts, correlates, flows, mfa, bypass, geographic, patterns, following, an0192, documents, macros, spawn, relies, application, child, an0191, app, saved, disk, immediately, executed, safari, preview, launching, correlate, unifiedlogs, events, subsequent, an0190, monitor, payload, clients, thunderbird, mutt, result, focus, correlation, between, writes, an0189, inbound, followed, new, document, behavior, involves, received, an0188, across, det0070, trained, training, m1017, authentication, filter, validity, checks, spf, integrity, dkim, enabling, these, within, organization, policies, dmarc, enable, recipients, intra, cross, similar, filtering, validation, configuration, m1054, determine, certain, websites, types, scr, exe, pif, cpl, necessary, business, consider, blocking, cannot, monitored, poses, significant, risk, restrict, content, m1021, designed, scan, remove, block, m1031, audits, scans, permissions, configurations, potential, weaknesses, audit, m1047, virus, automatically, quarantine, antivirus, antimalware, m1049, mitigation, emailed, threatening, vector, g1055, g1041, back, lured, into, calling, provided, s1073, sent, targets, address, microsoftonlines, com, g0069, g0094, have, s1139, g1032, s0009, malspam, machines, g0115, initially, compromise, g0001, distribute, payloads, g1049, procedure, examples, live, permalink, last, modified, created, liran, ravich, cardinalops, ohad, zaidenberg, ohad_mz, philip, winther, scott, cook, capital, one, contributors, provider, linux, suite, windows, macos, tactic, receive, instruct, them, phone, they, directed, visit, url, download, install, accessible, onto, their, computer, typically, execute, code, third, like, media, involve, posing, trusted, source, evasive, removing, manipulating, headers, compromised, accounts, being, abused, another, way, accomplish, this, which, fool, both, human, recipient, automated, intended, target, existing, includes, hiding, rules, forms, electronically, known, specific, individual, company, industry, will, generally, conduct, non, mass, voice, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, about, get, started, detections, technique,


Text of the page (random words):
phishing technique t1566 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise phishing phishing sub techniques 4 id name t1566 001 spearphishing attachment t1566 002 spearphishing link t1566 003 spearphishing via service t1566 004 spearphishing voice adversaries may send phishing messages to gain access to victim systems all forms of phishing are electronically delivered social engineering phishing can be targeted known as spearphishing in spearphishing a specific individual company or industry will be targeted by the adversary more generally adversaries can conduct non targeted phishing such as in mass malware spam campaigns adversaries may send victims emails containing malicious attachments or links typically to execute malicious code on victim systems phishing may also be conducted via third party services like social media platforms phishing may also involve social engineering techniques such as posing as a trusted source as well as evasive techniques such as removing or manipulating emails or metadata headers from compromised accounts being abused to send messages e g email hiding rules 1 2 another way to accomplish this is by email spoofing 3 the identity of the sender which can be used to fool both the human recipient as well as automated security tools 4 or by including the intended target as a party to an existing email thread that includes malicious files or links i e thread hijacking 5 victims may also receive phishing messages that instruct them to call a phone number where they are directed to visit a malicious url download malware 6 7 or install adversary accessible remote management tools onto their computer i e user execution 8 id t1566 sub techniques t1566 001 t1566 002 t1566 003 t1566 004 ⓘ tactic initial access ⓘ platforms identity provider linux office suite saas windows macos contributors liora itkin liran ravich cardinalops ohad zaidenberg ohad_mz philip winther scott cook capital one version 2 7 created 02 march 2020 last modified 12 may 2026 version permalink live version procedure examples id name description g1049 applejeus applejeus has used spearphishing emails to distribute malicious payloads 9 g0001 axiom axiom has used spear phishing to initially compromise victims 10 11 g0115 gold southfield gold southfield has conducted malicious spam malspam campaigns to gain access to victim s machines 12 s0009 hikit hikit has been spread through spear phishing 11 g1032 inc ransom inc ransom has used phishing to gain initial access 13 14 s1139 inc ransomware inc ransomware campaigns have used spearphishing emails for initial access 14 g0094 kimsuky kimsuky has used spearphishing to gain initial access and intelligence 15 16 g0069 muddywater muddywater has sent phishing emails to targets from the email address support microsoftonlines com 17 s1073 royal royal has been spread through the use of phishing campaigns including call back phishing where victims are lured into calling a number provided through email 18 19 20 g1041 sea turtle sea turtle used spear phishing to gain initial access to victims 21 g1055 void manticore void manticore has emailed victims threatening messages 22 void manticore has used phishing as an initial access vector 23 mitigations id mitigation description m1049 antivirus antimalware anti virus can automatically quarantine suspicious files m1047 audit perform audits or scans of systems permissions insecure software insecure configurations etc to identify potential weaknesses m1031 network intrusion prevention network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity m1021 restrict web based content determine if certain websites or attachment types ex scr exe pif cpl etc that can be used for phishing are necessary for business operations and consider blocking access if activity cannot be monitored well or if it poses a significant risk m1054 software configuration use anti spoofing and email authentication mechanisms to filter messages based on validity checks of the sender domain using spf and integrity of messages using dkim enabling these mechanisms within an organization through policies such as dmarc may enable recipients intra org and cross domain to perform similar message filtering and validation 24 25 m1017 user training users can be trained to identify social engineering techniques and phishing emails detection strategy id name analytic id analytic description det0070 detection strategy for phishing across platforms an0188 unusual inbound email activity where attachments or embedded urls are delivered to users followed by execution of new processes or suspicious document behavior detection involves correlating email metadata file creation and network activity after a phishing message is received an0189 monitor for malicious payload delivery through phishing where attachments or urls in email clients e g thunderbird mutt result in unusual file creation or outbound network connections focus on correlation between mail logs file writes and execution activity an0190 detection of phishing through anomalous mail app activity such as attachments saved to disk and immediately executed or safari preview launching urls and files linked from email messages correlate unifiedlogs events with subsequent process execution an0191 phishing via office documents containing embedded macros or links that spawn processes detection relies on correlating office application logs with suspicious child process execution and outbound network connections an0192 phishing attempts targeting idps often manifest as anomalous login attempts from suspicious email invitations or fake sso prompts detection correlates login flows mfa bypass attempts and anomalous geographic patterns following phishing email delivery an0193 phishing delivered via saas services chat collaboration platforms where messages contain malicious urls or attachments detect anomalous link clicks suspicious file uploads or token misuse after saas based phishing attempts references microsoft 2023 september 22 malicious oauth applications abuse cloud email services to spread spam retrieved march 13 2023 vicky ray and rob downs 2014 october 29 examining a vba initiated infostealer campaign retrieved march 13 2023 proofpoint n d what is email spoofing retrieved february 24 2023 itkin liora 2022 september 1 double bounced attacks with email spoofing retrieved february 24 2023 brian krebs 2024 march 28 thread hijacking phishes that prey on your curiosity retrieved september 27 2024 oren biderman tomer lahiyani noam lifshitz ori porag n d luna moth the threat actors behind recent false subscription scams retrieved february 2 2023 cisa n d protecting against malicious use of remote monitoring and management software retrieved february 2 2023 kristopher russo n d luna moth callback phishing campaign retrieved february 2 2023 michael barni barnhart dtex and anonymous smes 2025 may 14 exposing dprk s cyber syndicate and hidden it workforce retrieved september 3 2025 esler j lee m and williams c 2014 october 14 threat spotlight group 72 retrieved january 14 2016 novetta n d operation smn axiom threat actor group report retrieved november 12 2014 counter threat unit research team 2019 september 24 revil sodinokibi ransomware retrieved august 4 2020 socradar 2024 january 24 dark web profile inc ransom retrieved june 5 2024 sentinelone n d what is inc ransomware retrieved june 5 2024 microsoft threat intelligence 2024 february 14 staying ahead of threat actors in the age of ai retrieved march 11 2024 mandiant 2024 march 14 apt43 north korean group uses cybercrime to fund espionage operations retrieved may 3 2024 naumaan s et al 2025 april 17 around the world in 90 days state sponsored actors try clickfix retrieved january 21 2026 cybereason global soc and cybereason security research teams 2022 december 14 royal rumble analysis of royal ransomware retrieved march 30 2023 iacono l and green s 2023 february 13 royal ransomware deep dive retrieved march 30 2023 cisa 2023 march 2 stopransomware royal ransomware retrieved march 31 2023 cisco talos 2019 april 17 sea turtle dns hijacking abuses trust in core internet service retrieved november 20 2024 doj fbi 2026 march 19 case 1 26 mj 00683 cda affidavit in support of seizure warrant in the matter of the seizure of domain names justicehomeland org karmabelow80 org handala hack to and handala redwatned to retrieved april 20 2026 domaintools investigations 2026 april 6 handala mois linked cyber influence ecosystem threat intelligence assessment retrieved april 20 2026 microsoft 2020 october 13 anti spoofing protection in eop retrieved october 19 2020 australian cyber security centre 2012 december mitigating spoofed emails using sender policy framework retrieved november 17 2024 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 72 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-72


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
x-origin-cache HIT
Location htt????/attack.mitre.org/techniques/T1566
X-GitHub-Request-Id 5DAA:CEB0D:B25793:B34187:6A875E69
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Thu, 20 Aug 2026 20:07:05 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290048-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787256425.118212,VS0,VE113
Vary Accept-Encoding
X-Fastly-Request-ID 563d335c6f54fbabac5aa6d4c5502c2b3492a930
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1566/
access-control-allow-origin *
expires Thu, 20 Aug 2026 20:17:05 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id A450:3DADB9:B0CCC9:B1B63E:6A875E69
x-github-edge-region fra
accept-ranges bytes
age 0
date Thu, 20 Aug 2026 20:07:05 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290055-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787256425.257732,VS0,VE110
vary Accept-Encoding
x-fastly-request-id 59d1ca17b66eab8b0485908c0115f838f2bb6336
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:18 GMT
access-control-allow-origin *
etag W/ 6a75ea92-1288f
expires Thu, 20 Aug 2026 19:16:40 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 0D2C:CEB0D:859DA7:864E7A:6A875040
x-github-edge-region fra
accept-ranges bytes
age 0
date Thu, 20 Aug 2026 20:07:05 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290055-RTM
x-cache HIT
x-cache-hits 0
x-timer S1787256425.376253,VS0,VE111
vary Accept-Encoding
x-fastly-request-id 63d5227f2c8ba71ac979f4706602907a9b4f7369
content-length 12564

Meta Tags

title="Phishing, Technique T1566 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size12564
load time (s)0.652624
redirect count2
speed download19269
server IP 185.199.109.153
* all occurrences of the string "http://" have been changed to "htt???/"