Phishing
Introduction
Section titled “Introduction”Phishing is a social engineering technique where attackers impersonate trusted entities to trick victims into revealing credentials, installing malware, or transferring funds. It remains the #1 initial access vector for most malware.
| Type | Vector | Description |
|---|---|---|
| Email Phishing | Bulk, generic; credential harvesting | |
| Spear Phishing | Targeted; personalised; uses OSINT | |
| Whaling | Targets executives; high-value | |
| Smishing | SMS | Text messages; urgency tactics |
| Vishing | Voice | Phone calls; impersonation |
| Quishing | QR Code | QR codes in email/physical |
| Clone Phishing | Legitimate email cloned, link replaced | |
| Business Email Compromise (BEC) | Invoice fraud, payroll diversion |
Attack Flow
Section titled “Attack Flow”1. RECONNAISSANCE └─ OSINT: LinkedIn, company website, breach data
2. CRAFTING └─ Spoofed sender, urgent language, malicious link/attachment
3. DELIVERY └─ Email gateway → inbox (bypass filters)
4. EXECUTION └─ Click link → credential harvest / malware download └─ Reply → BEC conversation
5. POST-EXPLOITATION └─ Credential reuse, lateral movement, data theftNotable Campaigns
Section titled “Notable Campaigns”| Campaign | Year | Target | Method |
|---|---|---|---|
| Operation Aurora | 2009 | Google, Adobe | Spear phish + 0-day |
| DNC Hack | 2016 | DNC | Spear phish + credential theft |
| Colonial Pipeline | 2021 | Colonial Pipeline | VPN creds (phished?) |
| MGM Resorts | 2023 | MGM | Vishing + social engineering |
Prevention
Section titled “Prevention”- ✅ FIDO2/WebAuthn — Phishing-resistant MFA
- ✅ DMARC/DKIM/SPF — Email authentication
- ✅ Email Security Gateway — ATP, sandboxing, URL rewriting
- ✅ User Training — Quarterly sims; no punishment
- ✅ Password Manager — Auto-fill only on legitimate domains
- ✅ Report Button — “Report Phish” in email client
- ✅ DMARC Policy —
p=rejectfor domains
MITRE ATT&CK
Section titled “MITRE ATT&CK”| Technique | ID | Description |
|---|---|---|
| Phishing | T1566 | All phishing types |
| Spearphishing Attachment | T1566.001 | Malicious attachment |
| Spearphishing Link | T1566.002 | Malicious link |
| Spearphishing via Service | T1566.003 | Social media, SMS |
Related
Section titled “Related”- Trojan Horse — Delivery via phishing
- Ransomware — Phishing delivery
- BEC — Business email compromise
- User Awareness — Training