An enterprise security analyst investigates an incident where several corporate accounts were compromised. The investigation reveals that employees received text messages on their mobile devices directing them to a fake login site to verify credentials. Additionally, the attacker placed phone calls to affected staff while pretending to be internal IT personnel to convince them to approve multi-factor authentication (MFA) push notifications. Which of the following social engineering attack vectors were directly executed in this campaign? (Select TWO.)
- SmishingAnswer
- VishingAnswer
- CWatering hole attack
- DTyposquatting
Answer
The threat actor utilized smishing (SMS-based phishing) and vishing (voice-based phishing) during the attack.
The scenario describes two specific delivery mediums: text messages (SMS) used to send malicious links, which defines smishing; and voice phone calls used to manipulate employees into approving MFA push notifications, which defines vishing.
Step-by-Step Solution
Key Concept
Social Engineering Attack Vectors (Smishing vs. Vishing)