Skip to content
Every technique
T1566.004No distinct observable

Spearphishing Voice

Initial AccessLinux, macOS, Windows, Identity Provider

Where this stands

A reviewer read the telemetry and concluded there is nothing here to detect that a sibling technique does not already cover.

The brief has one analytic (AN0685), macOS-only, watching FaceTime/iMessage/SIP client logs for 'non-standard caller IDs or unusual metadata' via a bare service:unifiedlog sigmaLogsource with no eventIds and no field-level detail beyond that prose. Caller identity and call metadata live in unified-log message text, not in any structured field this corpus has an established, confident mapping for, so no field name here could be asserted as real per the authoring contract, and keying on the message text would be a keyword-only search Sigma cannot render. The analytic's other half — correlating the call with a subsequent RMM install or download — has no cross-event join Sigma can express, and the RMM-execution artefact by itself is already the published T1219 rule (remote support agent spawning a shell), which is not distinctive to a voice-phishing origin. […]

Covered instead by T1219.

What the technique is

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient. All forms of phishing are electronically delivered social engineering. In this scenario, adversaries are not directly sending malware to a victim vice relying on User Execution for delivery and execution. For example, victims may receive phishing messages that instruct them to call a phone number where they are directed to visit a malicious URL, download malware, or install adversary-accessible remote management tools (Remote Access Tools) onto their computer. Adversaries may also combine voice phishing with Multi-Factor Authentication Request Generation in order to trick users into divulging MFA credentials or accepting authentication prompts.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN0683

    Monitor call log records from corporate devices for unusual or unauthorized numbers, especially repeated calls to/from known malicious phone numbers. Correlate with subsequent system events (e.g., browser navigation, remote management tool execution).

  • AN0684

    Audit VoIP/SIP logs for suspicious outbound calls or call setup messages to unusual endpoints. Correlate with user activity such as browser execution or package installation following the call.

  • AN0685

    Monitor Facetime, iMessage, or SIP client logs for anomalous voice call attempts. Link to subsequent user execution events (downloads, RMM installs) triggered post-call.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.