75 - Phishing Techniques

Spear Phishing

Phishing aimed at a specific victim, constructed attack with higher chance of success

Whaling

Spear phishing directed at executives and high-profile individuals

BEC (Business Email Compromise)/ EAC (Email Account Compromise)

Such attacks are a specific form of phishing with financial motivation, the second most common form of attacks

Vishing

Phishing through call centers or bots that attempts to get the user to communicate sensitive data

Smishing

Phishing through SMS

Via Social

Spear phishing campaigns go through the information gathering phase in which the victim's social media presence is used to get information to use in attacking the victim

OSINT and SOCMINT, Maltego

  • OSINT: Open Source Intelligence
  • SOCMINT: Social Media Intelligence
  • Maltego: Interactive information mining tool, builds a graph of relationships of information