T1566

Phishing

Adversaries send phishing messages to gain access to victim systems. Phishing can be targeted (spearphishing) or sent to large numbers of recipients.

ATT&CK / Initial Access

In the 2020 SolarWinds attack, initial access was achieved through a supply chain compromise, but many APT groups like APT29 extensively use spearphishing with malicious attachments or links.

Defense strategies

  • Email filtering and anti-phishing tools
  • User awareness training
  • Multi-factor authentication
  • Sandboxing email attachments
  • Link protection and URL rewriting

Detection methods

  • Monitor for suspicious email patterns
  • Analyze attachment behavior in sandbox
  • Track clicks on external links
  • Correlate with threat intelligence feeds

T1566 on MITRE ATT&CK ↗