A network administrator discovers that multiple employees in the legal department received text messages on their corporate mobile devices containing a link to reset their domain credentials due to a mandatory security update. The link directs users to a fraudulent web page whose URL replaces the letter 'o' with the digit '0' in the company's official domain name to harvest login details. Which of the following social engineering attack vectors did the threat actor combine to execute this attack?
- Smishing and typosquattingAnswer
- BSpear phishing and watering hole
- CVishing and pretexting
- DBaiting and pharming
Answer
Smishing and typosquatting
The correct answer combines smishing (using SMS text messages as the initial attack vector) and typosquatting (registering a fake domain with a subtle visual misspelling such as replacing 'o' with '0').
Step-by-Step Solution
Key Concept
Classification of Social Engineering Delivery Mechanisms and Domain Spoofing Techniques
Estimated Time:1m 30s