An organization's security team identifies that several software developers received personalized email messages appearing to originate from their version control platform administrator. The messages claimed that due to a critical security compliance violation, their repository access would be suspended within 90 minutes unless they logged into a specified web portal to verify their identity. The link provided led to a counterfeit authentication portal hosted on a visually similar, typo-registered domain designed to harvest credentials. Which of the following social engineering attack vectors and influence principles were directly employed in this campaign? (Select TWO).
- Spear phishing aimed at specific corporate rolesCevap
- BWatering hole tactics compromising a shared developer site
- Urgency leveraged to bypass critical reasoningCevap
- DSmishing delivered over cellular SMS channels
Cevap
The attack utilized spear phishing targeted at software developers and leveraged the psychological principle of urgency by threatening imminent account suspension.
The scenario describes spear phishing because the attackers created customized, role-specific email lures targeting software developers. Additionally, the attackers leveraged urgency by establishing an immediate 90-minute deadline with severe consequences (loss of repository access) to prevent victims from stopping to verify the request.
Adım Adım Çözüm
Anahtar Kavram
Spear Phishing and Principles of Influence (Urgency)