An organization's incident response team is dissecting a multi-channel cyber attack targeting a senior system administrator. The adversary first conducted open-source intelligence (OSINT) gathering on public code repositories to obtain personal details and active project names. Next, the attacker placed a direct voice call to the administrator's personal mobile phone impersonating an IT service desk director, claiming that emergency maintenance was required immediately to prevent critical domain service disruption. During the call, the administrator was instructed to follow a link sent via a cellular text message to enter their administrative single sign-on (SSO) credentials into a fake authentication portal. Which combination of social engineering attack vectors and primary principles of influence were executed by the adversary in this incident?
- Vishing and smishing leveraging authority and urgencyCevap
- BSpear phishing and whaling leveraging trust and social proof
- CPretexting and baiting leveraging consensus and scarcity
- DPharming and watering hole leveraging intimidation and consensus