Technical

How to Get Away with Phishing - Part 0

Phishing

Everyone’s favorite subject

It’s hard to go through cybersecurity articles without seeing yet another article about phishing - another post raising awareness, another cautionary tale, another guide on the top 10 telltale signs of a phishing email.

Surely, surely everyone knows all about phishing by now, right?

So, instead of another fear mongering article telling people to be “vigilant”, we’ll show the attackers some love, and tell you all about how to phish (and get away with it).

Welcome to phishing school

Everyone is welcome at the school of phishing - whether you’re a cybersecurity enthusiast, seasoned professional, or just a curious passerby, we’ll have something for you. The concept of phishing might seem simple, but there are many techniques and intricacies behind each attack that makes the difference between a small-time scammer and a high-rolling cybercriminal.

We’ll take a deep dive into the anatomy of a phishing campaign, breaking it down step-by-step to give you some practical insights for conducting your perfect phishing campaign. Each post in this series will dissect different parts of a phish, and go through the tactics and strategies that veteran phishers use.

Spear phishing - Let’s try to catch some big fish

Now I’m sure everyone has heard about phishing, and probably encountered your fair share of phishing emails. An estranged grandparent leaving you a windfall inheritance, a pending delivery from your local post office, a prince from foreign lands who needs your help, an ecommerce company giving you a sweet refund, and so on.

They’re cute, for sure. But these are for small fish. Here, we want to catch some big fish - Corporations and C-suite are the ones we’re after. For those, we need some specialized bait. And to craft good bait, you must first know your target.

Research your target

A good phishing campaign starts with research. The more you know about your targets, the more convincing your phishing attempts will be, and the more likely you will get a bite.

Luckily for you, most of the the information you need is available in the palm of your hand - you only need to know how to look.

The art of doing this is called Open-Source Intelligence, or OSINT.

OSINT for profit

When targeting a company, there are 2 main areas you should look into: people, and environment.

1. Understand the people

Companies are made of people (yes, even your annoying coworkers), and understanding those people makes it easier to fool them. It also helps to identify key individuals who can help give you the keys to the kingdom.

Here are some tools that can help you on your “research”:

2. Understanding the environment

Tools:

Next time

Now that you have done the research, it’s time to put that knowledge to use in crafting convincing bait to lure in your target. We’ll cover how to do that in the next installment of our series.