A security analyst investigates an incident where an adversary registered a domain visually similar to an enterprise's external vendor portal (payro1l-service.com). The adversary hosted a trojanized software patch on the site and sent personalized emails directly to three payroll specialists, claiming an urgent compliance update was required to prevent processing delays. Which of the following social engineering attack vectors best describes the primary delivery tactic used against the payroll specialists?
- Spear phishing utilizing pretexting and typosquattingAnswer
- BA watering hole attack leveraging broad drive-by downloads
- CVishing combined with physical baiting techniques
- DWhaling aimed at executive-level operational disruption
Answer
Spear phishing utilizing pretexting and typosquatting is the primary vector because the adversary targeted specific employees with tailored emails, crafted an urgent compliance story, and hosted the malware on a deceptive domain.
The scenario describes a targeted attack against specific employees (payroll specialists) using customized communication, which characterizes spear phishing. The attacker fabricated an urgent compliance requirement scenario (pretexting) and directed targets to a visually deceptive lookalike domain (typosquatting).
Step-by-Step Solution
Key Concept
Identifying Spear Phishing, Pretexting, and Typosquatting Vectors