官术网_书友最值得收藏!

Spear phishing

This is also related to a normal phishing attack, but it does not send out high volumes of emails in a random manner. Spear phishing is specifically targeted to obtain information from particular end users in an organization. Spear phishing is more strenuous since it requires the attackers to perform a number of background checks on targets in order to identify a victim that they can pursue. Attackers will then carefully craft an email that addresses something of interest to the target, coercing him or her to open it. Statistically, normal phishing has a 3% success rate, whereas spear phishing has a 70% success rate. It is also said that only 5% of people who open phishing emails click links or download any attachments, while almost half of all people who open spear phishing emails click on their links and download attachments.

A good example of a spear phishing attack would be one whereby attackers are targeting a staff member in the HR department. These are employees that have to be in constant contact with the world when seeking new talent. A spear phisher might craft an email accusing the department of corruption or nepotism, providing a link to a website where disgruntled—and fictional—potential employees have been complaining. HR staff members are not necessarily very knowledgeable about IT-related issues, and therefore might easily click on such links, and as a result get infected. From one single infection, malware can easily spread inside an organization by making its way through to the HR server, which almost every organization has.

主站蜘蛛池模板: 晋江市| 佳木斯市| 柞水县| 崇阳县| 安多县| 平昌县| 青神县| 彭山县| 宜城市| 西乌珠穆沁旗| 朝阳市| 美姑县| 瓦房店市| 增城市| 定西市| 谷城县| 凤山县| 永泰县| 安康市| 勃利县| 十堰市| 沙雅县| 湖口县| 盐边县| 时尚| 庆元县| 皮山县| 准格尔旗| 遂宁市| 宿州市| 夹江县| 东阿县| 济源市| 衡阳县| 普安县| 会泽县| 彭阳县| 贵南县| 岗巴县| 滨州市| 凉城县|