T1566 Phishing — ATT&CK Technique
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms. Phishing may also involve social engineering techniques, such as posing as a trusted source, as well as evasive techniques such as removing or manipulating emails or metadata/headers from compromised accounts being abused to send messages (e.g., Email Hiding Rules). Another way to accomplish this is by Email Spoofing the identity of the sender, which can be used to fool both the human recipient as well as automated security tools, or by including the intended target as a party to an existing email thread that includes malicious files or links (i.e., "thread hijacking"). Victims may also receive phishing messages that instruct them to call a phone number where they are directed to visit a malicious URL, download malware, or install adversary-accessible remote management tools onto their computer (i.e., User Execution).
Detection coverage (30)
- CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum critical
- Suspicious Execution via macOS Script Editor medium
- CVE-2021-31979 CVE-2021-33771 Exploits critical
- WebDAV Temporary Local File Creation medium
- Potential Malicious Usage of CloudTrail System Manager high
- Okta FastPass Phishing Detection high
- Download From Suspicious TLD - Blacklist low
- Download From Suspicious TLD - Whitelist low
- Suspicious External WebDAV Execution high
- Potential Initial Access via DLL Search Order Hijacking medium
- HTML Help HH.EXE Suspicious Child Process high
- Suspicious HH.EXE Execution high
- Suspicious Microsoft OneNote Child Process high
- Phishing Pattern ISO in Archive high
- Gdrive suspicious file sharing
- Gsuite suspicious calendar invite
- Windows InProcServer32 New Outlook Form
- Windows Phishing Outlook Drop Dll In FORM Dir
- Zscaler Behavior Analysis Threat Blocked
- Zscaler CryptoMiner Downloaded Threat Blocked
- Zscaler Legal Liability Threat Blocked
- Zscaler Potentially Abused File Download
- Zscaler Adware Activities Threat Blocked
- Zscaler Employment Search Web Activity
- Zscaler Malware Activity Threat Blocked
- Zscaler Privacy Risk Destinations Threat Blocked
- Zscaler Exploit Threat Blocked
- Zscaler Phishing Activity Threat Blocked
- Zscaler Scam Destinations Threat Blocked
- Zscaler Virus Download threat blocked