Install any skill in seconds. Free to start, no credit card required.
Get Started Free →After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within th...
.claude/skills/cyberstrikeus-t1534-internal-spearphishing/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-02 | ✗→✓ | ▲ Improved | 28% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -22% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 53% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 11% | 0% |
| case-11 | ✗→✓ | ▲ Improved | -66% | 0% |
After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization. Internal spearphishing is multi-staged campaign where a legitimate account is initially compromised either by controlling the user's device or by compromising the account credentials of the user. Adversaries may then attempt to take advantage of the trusted internal account to increase the likelihood of tricking more victims into falling for phish attempts, often incorporating Impersonation.
For example, adversaries may leverage Spearphishing Attachment or Spearphishing Link as part of internal spearphishing to deliver a payload or redirect to an external site to capture credentials through Input Capture on sites that mimic login interfaces.
Adversaries may also leverage internal chat apps, such as Microsoft Teams, to spread malicious content or engage users in attempts to capture sensitive information and/or credentials.
Platforms: Windows, macOS, Linux, SaaS, Office Suite
> Note: No Atomic Red Team tests available for this technique. See Atomic Red Team GitHub for updates.
No specific mitigations documented for this technique.
| Finding | Severity | Impact | | ------------------------------------------- | -------- | ---------------- | | Internal Spearphishing technique applicable | High | Lateral Movement |
| CWE ID | Title | | ------- | ----------------------- | | CWE-284 | Improper Access Control |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 37,562 | 69,871 | +86% | 1 | 1 | 0% | 4,966 | 6,095 | +23% | 0 | 0 | — |
case-02 | fail→pass | 28,026 | 24,789 | -12% | 1 | 1 | 0% | 3,608 | 4,614 | +28% | 0 | 0 | — |
case-03 | pass→pass | 15,460 | 14,259 | -8% | 1 | 1 | 0% | 1,702 | 2,276 | +34% | 0 | 0 | — |
case-04 | pass→pass | 22,124 | 19,575 | -12% | 1 | 1 | 0% | 2,306 | 2,909 | +26% | 0 | 0 | — |
case-05 | fail→pass | 16,733 | 7,717 | -54% | 1 | 1 | 0% | 1,649 | 1,279 | -22% | 0 | 0 | — |
case-06 | fail→pass | 18,985 | 19,824 | +4% | 1 | 1 | 0% | 2,013 | 3,072 | +53% | 0 | 0 | — |
case-07 | pass→pass | 21,995 | 11,071 | -50% | 1 | 1 | 0% | 2,357 | 1,634 | -31% | 0 | 0 | — |
case-08 | pass→pass | 8,439 | 4,290 | -49% | 1 | 1 | 0% | 501 | 1,140 | +128% | 0 | 0 | — |
case-09 | fail→pass | 16,445 | 6,249 | -62% | 1 | 1 | 0% | 1,566 | 1,735 | +11% | 0 | 0 | — |
case-10 | fail→fail | 16,342 | 18,928 | +16% | 1 | 1 | 0% | 1,489 | 3,373 | +127% | 0 | 0 | — |
case-11 | fail→pass | 17,093 | 8,178 | -52% | 1 | 1 | 0% | 2,952 | 999 | -66% | 0 | 0 | — |
case-12 | fail→fail | 12,037 | 8,640 | -28% | 1 | 1 | 0% | 886 | 1,118 | +26% | 0 | 0 | — |
case-13 | pass→pass | 8,071 | 3,346 | -59% | 1 | 1 | 0% | 497 | 899 | +81% | 0 | 0 | — |
case-14 | pass→pass | 23,184 | 4,109 | -82% | 1 | 1 | 0% | 3,085 | 1,372 | -56% | 0 | 0 | — |
case-15 | fail→pass | 10,778 | 3,978 | -63% | 1 | 1 | 0% | 1,774 | 1,232 | -31% | 0 | 0 | — |
case-16 | fail→pass | 23,711 | 8,064 | -66% | 1 | 1 | 0% | 2,859 | 1,294 | -55% | 0 | 0 | — |
case-17 | pass→pass | 10,923 | 8,093 | -26% | 1 | 1 | 0% | 850 | 1,081 | +27% | 0 | 0 | — |
case-18 | pass→pass | 11,106 | 7,957 | -28% | 1 | 1 | 0% | 916 | 1,212 | +32% | 0 | 0 | — |
case-19 | pass→pass | 19,153 | 16,292 | -15% | 1 | 1 | 0% | 2,011 | 2,355 | +17% | 0 | 0 | — |
case-20 | fail→pass | 12,636 | 7,625 | -40% | 1 | 1 | 0% | 1,358 | 2,066 | +52% | 0 | 0 | — |
case-21 | fail→fail | 4,301 | 5,455 | +27% | 1 | 1 | 0% | 763 | 1,683 | +121% | 0 | 0 | — |
case-22 | fail→fail | 16,965 | 17,719 | +4% | 1 | 1 | 0% | 3,031 | 2,836 | -6% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +36 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.