If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1598/002 - Phishing for Information: Spea.

site address: attack.mitre.org/techniques/T1598/002 redirected to: attack.mitre.org/techniques/T1598/002

site title: Phishing for Information: Spearphishing Attachment, Sub-technique T1598.002 - Enterprise MITRE ATT&CK®

Our opinion (on Sunday 23 August 2026 20:20:09 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

phishing, for, information, spearphishing, attachment, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of,

Text of the page (most frequently used words):
and (18), the (16), spearphishing (16), retrieved (14), for (13), information (13), all (11), att (10), #techniques (9), with (9), 2020 (8), october (8), enterprise (7), 2024 (7), phishing (7), t1598 (7), that (6), messages (6), attachment (6), use (5), ics (5), mobile (5), none (5), data (5), january (5), june (5), sidewinder (5), 2021 (5), email (5), such (5), may (5), mitre (4), are (4), campaigns (4), detection (4), sub (4), december (4), sender (4), microsoft (4), threat (4), targeting (4), star (4), blizzard (4), apt (4), other (4), monitor (4), not (4), can (4), traffic (4), has (4), credentials (4), version (4), adversaries (4), domains (3), software (3), cti (3), mitigations (3), defenses (3), tactics (3), cyber (3), emails (3), using (3), russian (3), intelligence (3), targets (3), sidecopy (3), lures (3), network (3), flows (3), accounts (3), from (3), patterns (3), protocol (3), anomalous (3), description (3), name (3), social (3), engineering (3), user (3), attachments (3), websites (3), 002 (3), search (3), file (3), 2026 (2), corporation (2), policy (2), resources (2), reference (2), groups (2), components (2), analytics (2), strategies (2), assets (2), matrices (2), core (2), objects (2), security (2), spoofed (2), anti (2), spoofing (2), group (2), 2023 (2), ongoing (2), 2022 (2), september (2), analysis (2), victims (2), infrastructure (2), 2018 (2), march (2), activity (2), html (2), smuggling (2), 2025 (2), links (2), when (2), processes (2), normally (2), have (2), suspicious (2), filtering (2), based (2), dkim (2), spf (2), detect (2), associated (2), command (2), line (2), analytic (2), mechanisms (2), domain (2), enable (2), sent (2), establish (2), sending (2), credential (2), malicious (2), harvesting (2), collect (2), efforts (2), used (2), dragonfly (2), reconnaissance (2), technique (2), open (2), cases (2), reason (2), frequently (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, terms, contact, reset, filters, australian, centre, 2012, mitigating, framework, november, protection, eop, shields, coldriver, expands, its, western, officials, include, malware, increases, sophistication, evasion, attacks, february, cisa, fsb, actor, continues, worldwide, spear, august, disrupting, seaborgium, operations, cyble, futuristic, rewterz, april, campaign, hegel, global, perspective, team, connecting, payloads, cert, alert, ta18, 074a, government, energy, critical, sectors, matt, kiely, july, smuggler, gambit, uncovering, adversary, middle, tradecraft, ryan, hanson, 2016, phishery, ducklin, serious, without, phishers, bring, along, their, own, web, pages, references, uncommon, utilizing, communication, never, been, seen, before, numerous, receiving, single, unusual, unknown, header, help, analyze, packet, inspection, follow, expected, standards, extraneous, packets, belong, established, gratuitous, syntax, structure, consider, correlation, process, monitoring, execution, arguments, anomalies, files, initiate, connections, respective, an1997, det0865, strategy, users, trained, identify, attempts, training, m1017, authentication, filter, validity, checks, integrity, enabling, these, within, organization, through, policies, dmarc, recipients, intra, org, cross, perform, similar, message, validation, configuration, m1054, mitigation, rapport, eventually, containing, stealing, sites, g1033, mails, lead, g0121, crafted, generic, spam, g1008, office, g0035, procedure, examples, live, permalink, last, modified, created, philip, winther, robert, simmons, malwareutkonos, sebastian, salla, mcafee, contributors, pre, platforms, tactic, also, previous, craft, persuasive, believable, victim, owned, forms, electronically, delivered, targeted, specific, individual, company, industry, this, scenario, attach, some, they, rely, upon, recipient, populating, then, returning, text, usually, tries, give, plausible, why, should, filled, request, business, associate, leverage, harvest, via, fake, login, portals, send, elicit, sensitive, during, attempt, trick, into, divulging, actionable, involves, posing, source, multiple, seemingly, urgent, compromise, voice, 004, link, 003, service, 001, home, join, mclean, hotel, location, details, found, register, here, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, about, get, started, detections,


Text of the page (random words):
phishing for information spearphishing attachment sub technique t1598 002 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise phishing for information spearphishing attachment phishing for information spearphishing attachment other sub techniques of phishing for information 4 id name t1598 001 spearphishing service t1598 002 spearphishing attachment t1598 003 spearphishing link t1598 004 spearphishing voice adversaries may send spearphishing messages with a malicious attachment to elicit sensitive information that can be used during targeting spearphishing for information is an attempt to trick targets into divulging information frequently credentials or other actionable information spearphishing for information frequently involves social engineering techniques such as posing as a source with a reason to collect information ex establish accounts or compromise accounts and or sending multiple seemingly urgent messages all forms of spearphishing are electronically delivered social engineering targeted at a specific individual company or industry in this scenario adversaries attach a file to the spearphishing email in some cases they may rely upon the recipient populating information then returning the file 1 2 the text of the spearphishing email usually tries to give a plausible reason why the file should be filled in such as a request for information from a business associate in other cases adversaries may leverage techniques such as html smuggling to harvest user credentials via fake login portals 3 adversaries may also use information from previous reconnaissance efforts ex search open websites domains or search victim owned websites to craft persuasive and believable lures id t1598 002 sub technique of t1598 ⓘ tactic reconnaissance ⓘ platforms pre contributors philip winther robert simmons malwareutkonos sebastian salla mcafee version 1 2 created 02 october 2020 last modified 24 october 2025 version permalink live version procedure examples id name description g0035 dragonfly dragonfly has used spearphishing with microsoft office attachments to enable harvesting of user credentials 4 g1008 sidecopy sidecopy has crafted generic lures for spam campaigns to collect emails and credentials for targeting efforts 5 g0121 sidewinder sidewinder has sent e mails with malicious attachments that lead victims to credential harvesting websites 6 7 8 g1033 star blizzard star blizzard has sent emails to establish rapport with targets eventually sending messages with attachments containing links to credential stealing sites 9 10 11 12 mitigations id mitigation description m1054 software configuration use anti spoofing and email authentication mechanisms to filter messages based on validity checks of the sender domain using spf and integrity of messages using dkim enabling these mechanisms within an organization through policies such as dmarc may enable recipients intra org and cross domain to perform similar message filtering and validation 13 14 m1017 user training users can be trained to identify social engineering techniques and spearphishing attempts detection strategy id name analytic id analytic description det0865 detection of spearphishing attachment an1997 monitor network data for uncommon data flows processes utilizing the network that do not normally have network communication or have never been seen before are suspicious monitor for suspicious email activity such as numerous accounts receiving messages from a single unusual unknown sender filtering based on dkim spf or header analysis can help detect when the email sender is spoofed 13 14 monitor and analyze traffic patterns and packet inspection associated to protocol s that do not follow the expected protocol standards and traffic flows e g extraneous packets that do not belong to established flows gratuitous or anomalous traffic patterns anomalous syntax or structure consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns e g monitor anomalies in use of files that do not normally initiate connections for respective protocol s references ducklin p 2020 october 2 serious security phishing without links when phishers bring along their own web pages retrieved october 20 2020 ryan hanson 2016 september 24 phishery retrieved october 23 2020 matt kiely 2024 july 5 smuggler s gambit uncovering html smuggling adversary in the middle tradecraft retrieved march 18 2025 us cert 2018 march 16 alert ta18 074a russian government cyber activity targeting energy and other critical infrastructure sectors retrieved june 6 2018 threat intelligence team 2021 december 2 sidecopy apt connecting lures victims payloads to infrastructure retrieved june 13 2022 hegel t 2021 january 13 a global perspective of the sidewinder apt retrieved january 27 2021 rewterz 2020 april 20 sidewinder apt group campaign analysis retrieved january 29 2021 cyble 2020 september 26 sidewinder apt targets with futuristic tactics and techniques retrieved january 29 2021 microsoft threat intelligence 2022 august 15 disrupting seaborgium s ongoing phishing operations retrieved june 13 2024 cisa et al 2023 december 7 russian fsb cyber actor star blizzard continues worldwide spear phishing campaigns retrieved june 13 2024 microsoft threat intelligence 2023 december 7 star blizzard increases sophistication and evasion in ongoing attacks retrieved february 13 2024 shields w 2024 january 18 russian threat group coldriver expands its targeting of western officials to include the use of malware retrieved june 13 2024 microsoft 2020 october 13 anti spoofing protection in eop retrieved october 19 2020 australian cyber security centre 2012 december mitigating spoofed emails using sender policy framework retrieved november 17 2024 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 59 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-59


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1598/002
X-GitHub-Request-Id 7156:34F8D5:993495:A0518B:6A8B55F8
x-github-edge-region uksouth
Accept-Ranges bytes
Age 0
Date Sun, 23 Aug 2026 20:20:09 GMT
Via 1.1 varnish
X-Served-By cache-lcy-egml8630095-LCY
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787516409.230965,VS0,VE83
Vary Accept-Encoding
X-Fastly-Request-ID 6dcb8915f05c9b32a213150d2f24fc01819e04c4
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1598/002/
access-control-allow-origin *
expires Sun, 23 Aug 2026 20:30:09 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id A95E:779F0:53077DE:53B7A54:6A8B55F9
x-github-edge-region fra
accept-ranges bytes
age 0
date Sun, 23 Aug 2026 20:20:09 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290051-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787516409.342659,VS0,VE107
vary Accept-Encoding
x-fastly-request-id 1ef03da1b00f15f127857ee3891dfe70a14a1ab4
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:21 GMT
access-control-allow-origin *
etag W/ 6a75ea95-e43f
expires Sun, 23 Aug 2026 20:30:09 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id D8F8:9FC9E:53277A1:53D7B6C:6A8B55F9
x-github-edge-region fra
accept-ranges bytes
date Sun, 23 Aug 2026 20:20:09 GMT
via 1.1 varnish
age 0
x-served-by cache-rtm-ehrd2290051-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787516409.458034,VS0,VE109
vary Accept-Encoding
x-fastly-request-id 0109b85f5ff6568765636215fdff5a2c9f7a81ea
content-length 9858

Meta Tags

title="Phishing for Information: Spearphishing Attachment, Sub-technique T1598.002 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size9858
load time (s)0.618698
redirect count2
speed download15951
server IP 185.199.111.153
* all occurrences of the string "http://" have been changed to "htt???/"