Question

Difficulty: HardSocial Engineering Attacks and Vectors

A security analyst investigates an incident where an adversary registered a domain visually similar to an enterprise's external vendor portal (payro1l-service.com). The adversary hosted a trojanized software patch on the site and sent personalized emails directly to three payroll specialists, claiming an urgent compliance update was required to prevent processing delays. Which of the following social engineering attack vectors best describes the primary delivery tactic used against the payroll specialists?

  1. Spear phishing utilizing pretexting and typosquattingAnswer
  2. B
    A watering hole attack leveraging broad drive-by downloads
  3. C
    Vishing combined with physical baiting techniques
  4. D
    Whaling aimed at executive-level operational disruption

Answer

Spear phishing utilizing pretexting and typosquatting is the primary vector because the adversary targeted specific employees with tailored emails, crafted an urgent compliance story, and hosted the malware on a deceptive domain.
The scenario describes a targeted attack against specific employees (payroll specialists) using customized communication, which characterizes spear phishing. The attacker fabricated an urgent compliance requirement scenario (pretexting) and directed targets to a visually deceptive lookalike domain (typosquatting).

Step-by-Step Solution

1
Analyze the delivery method and target specificity in the scenario.
The adversary targeted specific payroll specialists using customized emails, which defines spear phishing.
General phishing broadcasts messages broadly, whereas targeting specific individuals based on their roles is spear phishing.
2
Evaluate the psychological influence technique and domain setup.
The adversary created a fake story about mandatory compliance updates (pretexting) and hosted it on a lookalike domain (typosquatting).
Pretexting establishes a fabricated scenario to manipulate targets into taking action, while typosquatting tricks users via deceptive URL spellings.
3
Differentiate from alternative social engineering vectors.
Watering hole, vishing/baiting, and whaling do not match the targeted email medium, technical setup, or audience profile described.
Watering hole attacks compromise third-party sites passively, vishing uses voice calls, baiting uses physical media, and whaling targets C-suite executives.

Key Concept

Identifying Spear Phishing, Pretexting, and Typosquatting Vectors
Rate this question