Adversaries send phishing messages to gain access to victim systems. Phishing can be targeted (spearphishing) or sent to large numbers of recipients.
In the 2020 SolarWinds attack, initial access was achieved through a supply chain compromise, but many APT groups like APT29 extensively use spearphishing with malicious attachments or links.