Attack Techniques · 2.1

🎣 Phishing & Spear Phishing

The most common attack — a fake message asking you to act⏱ ~3 min

Phishing

Attackers send deceptive emails, messages, or links to websites that appear legitimate, aiming to trick recipients into clicking and revealing sensitive information such as passwords, credit card numbers, or personal data. Phishing is sent in bulk — the same message to thousands of people, betting that some percentage will fall for it.

Spear Phishing

Spear phishing is the targeted version. Instead of a generic blast, the attacker customizes the message using specific information about the target — their name, job title, recent projects, even a colleague's name — making it far more convincing.

Phishing
  • Mass-sent to thousands or millions
  • Generic content ('Dear Customer')
  • Lower success rate per message
  • Cast a wide net for any victim
Spear Phishing
  • Targeted at a specific person or small group
  • Personalized with real details (name, role, project)
  • Much higher success rate
  • Used for high-value targets: executives, finance, IT admins

Whaling — Spear Phishing the C-Suite

★ FactWhen the target is a senior executive (CEO, CFO), it's called 'whaling.' These attacks often impersonate a board member, auditor, or legal counsel, and request large wire transfers or sensitive financial data. Whaling attacks have cost individual companies tens of millions of dollars in a single incident.

How to Spot a Phishing Email

From:PayPal Support <security@paypa1-alerts.ru>Subject:⚠ URGENT: Account suspended in 24 hours!!Dear Valued Customer,We detected unusal activity. You must verifiy youraccount imediately or it will be permanently locked.VERIFY NOWlink → http://paypal-secure-verify.xyz/loginPayPal Security Team1. fake domain — "paypa1", .ru2. urgency + threats3. generic greeting4. spelling mistakes5. pushy button…6. …to a shady URL
Anatomy of a phishing email — six red flags in one message
  • Mismatched sender address — display name says 'PayPal Support' but the email is from a random domain
  • Generic or slightly-off greeting — 'Dear Valued Customer' instead of your actual name
  • Urgency or threats — 'Act now or your account will be closed'
  • Suspicious links — hover over the link (don't click) to see the real destination URL before trusting it
  • Unexpected attachments — especially .zip, .exe, .scr, or macro-enabled Office files (.docm, .xlsm)
  • Poor grammar or formatting — though AI-generated phishing has made this less reliable as a signal
  • Requests for credentials or payment — legitimate companies rarely ask you to 'verify your password' by email
💡 TipHover over any link before clicking to preview the actual URL in your browser or email client's status bar. A link displaying 'paypal.com' might actually point to 'paypal-secure-verify.ru'. Always check the actual destination, not just the link text.
🧠Quick Checkfirst try = +5 XP

What makes spear phishing more dangerous than regular phishing?

0 XP🔥 0 days