Skip to content

Phishing

Risk Level

Phishing is a social engineering technique where attackers impersonate trusted entities to trick victims into revealing credentials, installing malware, or transferring funds. It remains the #1 initial access vector for most malware.

TypeVectorDescription
Email PhishingEmailBulk, generic; credential harvesting
Spear PhishingEmailTargeted; personalised; uses OSINT
WhalingEmailTargets executives; high-value
SmishingSMSText messages; urgency tactics
VishingVoicePhone calls; impersonation
QuishingQR CodeQR codes in email/physical
Clone PhishingEmailLegitimate email cloned, link replaced
Business Email Compromise (BEC)EmailInvoice fraud, payroll diversion
1. RECONNAISSANCE
└─ OSINT: LinkedIn, company website, breach data
2. CRAFTING
└─ Spoofed sender, urgent language, malicious link/attachment
3. DELIVERY
└─ Email gateway → inbox (bypass filters)
4. EXECUTION
└─ Click link → credential harvest / malware download
└─ Reply → BEC conversation
5. POST-EXPLOITATION
└─ Credential reuse, lateral movement, data theft
CampaignYearTargetMethod
Operation Aurora2009Google, AdobeSpear phish + 0-day
DNC Hack2016DNCSpear phish + credential theft
Colonial Pipeline2021Colonial PipelineVPN creds (phished?)
MGM Resorts2023MGMVishing + social engineering
  • FIDO2/WebAuthn — Phishing-resistant MFA
  • DMARC/DKIM/SPF — Email authentication
  • Email Security Gateway — ATP, sandboxing, URL rewriting
  • User Training — Quarterly sims; no punishment
  • Password Manager — Auto-fill only on legitimate domains
  • Report Button — “Report Phish” in email client
  • DMARC Policyp=reject for domains
TechniqueIDDescription
PhishingT1566All phishing types
Spearphishing AttachmentT1566.001Malicious attachment
Spearphishing LinkT1566.002Malicious link
Spearphishing via ServiceT1566.003Social media, SMS