Posts

Showing posts with the label Social Engineering

Phishing Simulation Programs: Design, Metrics, and What Not to Do

A phishing simulation sends controlled, harmless lookalike messages to your own staff and measures what happens. Gophish is the common open-source platform for running them, but the platform is the easy part. Program design is what determines whether a simulation improves security or quietly damages the relationship between the security team and everyone else. How a simulation works The mechanics are the same as real phishing, minus the payload. You define a target group, compose a message, host a landing page on a domain you control, and send. Each recipient gets a uniquely tracked link, so the platform can record who opened the message, who clicked, who submitted data on the landing page, and who reported it. The landing page is where the training happens. Rather than a fake login that harvests credentials, a well-built simulation lands the user on a short page explaining what just happened and pointing out the specific cues in the message they missed. Delivery requires preparat...

Credential Harvesting Pages: How Social Engineering Attacks Are Built

Social engineering toolkits automate the mechanics of an attack that is fundamentally about people. Understanding what they automate is useful to defenders because each automated stage is a stage you can break, and the controls that break them are different at each step. The credential harvesting page The most common attack in the category is also the simplest. An attacker clones a login page — the real one, fetched and saved so the HTML, CSS, and images match exactly — and hosts it on a domain of their own. A victim who reaches it and enters credentials hands them straight to the attacker, who then forwards the browser to the genuine site so the user sees a normal login and suspects nothing. Nothing about the page is exploited. It is a copy, and the deception is entirely in the domain name and the context that got the victim there. That is why the technical countermeasures aim at the domain and at what the credentials are worth once stolen, rather than at the page. Loo...

Pharming: Redirecting Users Without a Click, and How to Prevent It

Phishing persuades a user to click a link to a malicious site. Pharming sends them there when they type the correct address themselves. The user does everything right — no link clicked, no attachment opened, the real domain typed by hand — and still arrives at the attacker's server. That is what makes it worth understanding separately. The methods, roughly in order of how common they are Router and gateway compromise is the leading route in practice. Home and small office routers are reachable from the internet with default credentials and unpatched firmware more often than anyone would like. An attacker who gains access changes the DHCP-assigned DNS server to one they control, and every device on that network resolves names through the attacker — no malware on any endpoint, and a factory reset of a laptop fixes nothing. Hosts file modification is the simplest. Every operating system consults a local file mapping names to addresses before querying DNS, so malware...

Brand Impersonation: Lookalike Domains, Typosquatting and Takedowns

Brand impersonation uses an organization's name, logo and visual identity to make an attack credible. The victims are usually the brand's customers or its own employees, and the organization being impersonated often learns about it last — from a customer complaint rather than from any control it operates. The forms it takes Lookalike domains are the foundation of most of it. Typosquatting registers common misspellings. Character substitution swaps visually similar characters, and internationalized domain names allow characters from other scripts that render almost identically to Latin ones — a homograph attack that is genuinely hard to spot in an address bar. Combosquatting appends a plausible word, producing something like a support or login variant of the real name, which looks legitimate precisely because organizations do register domains like that. Alternative top-level domains take the exact brand name under a different suffix. Cloned websites follow: the real si...

Pretexting: How Attackers Build a Believable Story to Get What They Want

Pretexting is inventing a scenario — a role, a reason, a context — that makes a request seem legitimate. It is the foundation underneath most social engineering rather than a separate technique. A phishing email works because it comes with a pretext; remove the story and it is just a link nobody clicks. What makes a pretext work The lever is specificity. Anyone can claim to be from IT. Someone who names your actual ticketing system, your actual IT manager, and the actual maintenance window scheduled for this weekend is not obviously lying, and checking would feel insulting. That detail comes from reconnaissance. Staff directories, job postings, press releases, social media, conference talks, and document metadata supply names, titles, reporting lines, vendor relationships, and technology in use. The material is public and individually harmless; assembled, it is a script. Authority does most of the remaining work. A request that appears to come from an executive, an audi...

Smishing Explained: SMS Phishing for the Security+ Exam

Smishing is phishing delivered by SMS. It gets its own term on the Security+ syllabus because the channel changes the defensive picture, not because the social engineering differs. Why SMS works for attackers No gateway. Email passes through filtering that scans links, checks sender reputation and validates SPF, DKIM and DMARC. SMS arrives directly on the device with none of that. Higher trust and urgency. People treat texts as more personal and more immediate than email, and read them within minutes. That compresses the time available for second thoughts, which is exactly what social engineering depends on. Small screen. The address bar truncates, so a deceptive domain is harder to spot. Link previews are limited or absent. Shortened links are normal. Character limits made short links routine in SMS, so a message with an opaque link raises no suspicion at all. Personal devices. The phone is often outside corporate management, without endpoint protection or web filtering. S...

Vishing Explained: Voice Phishing and MFA Bypass for Security+

Vishing — voice phishing — is social engineering conducted over the phone. An attacker calls, establishes a plausible identity, manufactures urgency, and talks the victim into handing over credentials, approving an MFA prompt, or making a payment. A phishing email gives the target time to think. A phone call does not, and that is the entire point. Email phishing can be reread, forwarded to IT, and checked against the sender's real address. A live call moves at the attacker's pace, exploits politeness, and leaves no artifact to examine. That is why vishing succeeds against people who would never click a suspicious link — and why it has become the preferred route past MFA. The Techniques Caller ID spoofing. Trivially easy, and it underpins nearly every campaign. The display can read your bank's real number, your own company's help desk, or a government agency. Caller ID is not authentication and never was — worth saying plainly, because most people treat it as ...

Quishing Explained: QR Code Phishing for the Security+ Exam

Quishing is phishing delivered through a QR code. It earned its own term because the QR code changes the defensive picture in ways a URL does not, and SY0-701 lists it alongside vishing and smishing. Why a QR code is different Four properties, and each one weakens a control that normally works. The destination is unreadable. A human cannot tell where a QR code points. Every piece of advice about hovering over a link and checking the domain is inapplicable — there is nothing to inspect. It defeats link scanning. Email security gateways extract and analyse URLs. A QR code arrives as an image, so unless the gateway decodes images there is no URL to scan. This is the main reason attackers adopted it, and the main reason it works. It moves the victim to a phone. The scan usually happens on a personal mobile device, outside corporate filtering, often without endpoint protection, and with a small screen that truncates the address bar so a deceptive domain is even harder to spot. It w...

URL Shorteners and Link Analysis Explained for the Security+ Exam

A shortened URL hides its destination behind a redirect. That is useful for sharing and it is a problem for security, because the advice everyone gives — check the link before you click — becomes impossible to follow. Why shorteners are a security problem The destination is invisible. A short link gives no indication of where it goes. Domain reputation, spelling and the path are all hidden. Reputation is inherited. The shortener's domain is well known and widely allowed, so the link inherits trust the actual destination has not earned. Blocking the shortener wholesale breaks a great deal of legitimate traffic. The destination can change. Many services let the owner edit the target after the fact. A link that passed inspection when the email was delivered can point somewhere else by the time the user clicks — which defeats scan-at-delivery entirely. Chained redirects. Several shorteners in sequence frustrate automated analysis and add hops that filters may not follow. Trac...

Obfuscated Links Explained: Spotting Phishing URLs for the Security+ Exam

Obfuscated links are URLs deliberately disguised so the recipient cannot tell where they actually lead. They are a core phishing technique, and they work because people have been trained to "check the link before clicking" without being taught what part of a link actually matters. Everything in a URL before the final domain can be faked. The only part that decides where you go is the registrable domain immediately left of the first single slash. How Links Get Disguised Mismatched display text. In HTML email, the visible text and the destination are separate. A link reading www.yourbank.com can point anywhere at all. This is the simplest technique and still the most effective. Subdomain deception. yourbank.com.secure-login.ru is a subdomain of secure-login.ru , not of yourbank.com. Readers scanning left to right see the familiar name first and stop reading. Read a domain from the right, not the left. Typosquatting and homoglyphs. arnazon.com with rn in place...