Attack Techniques · 2.4
🐟 Angler Phishing & Social Media Attacks
Where the attack happens isn't your inbox anymore — it's your feed⏱ ~2 min
Angler phishing mainly targets social media users and often takes advantage of popular or trending topics to create deceptive messages, making them appear relevant and trustworthy. The name comes from the attacker 'fishing' for victims who are already engaged and emotionally invested in a topic.
Common Angler Phishing Patterns
- •Fake customer support accounts — a customer complains publicly about a company (e.g., an airline) and an attacker creates a lookalike support account that replies first, directing the victim to a phishing link
- •Trending hashtag hijacking — attackers post malicious links using trending hashtags to maximize visibility and apparent legitimacy
- •Fake giveaways and contests — 'Like and share to win an iPhone' posts that harvest personal data or drive traffic to malicious sites
- •Romance scams — long-term relationship building on dating apps or social media, eventually leading to requests for money
- •Quizzes and personality apps — seemingly harmless apps that request broad account permissions or harvest data used for further targeting
💡 TipAlways verify customer support accounts directly through the company's official, verified channel — never click on a 'support' account that replies to your complaint unprompted. Check for verification badges, but remember badges themselves have also been spoofed or purchased fraudulently on some platforms.
OSINT — How Attackers Build Their Target Profile
Open-Source Intelligence (OSINT) is the practice of gathering publicly available information to build a profile of a target. Attackers use it constantly before launching spear phishing, pretexting, or vishing attacks.
| Source | What an Attacker Learns |
|---|---|
| Job title, manager's name, recent promotions, company org structure | |
| Company website / press releases | Recent acquisitions, new vendors, executive travel schedules |
| Social media (Instagram, Facebook) | Pet names, family member names, vacation dates (when you're away) |
| Data breach dumps | Old passwords (often reused), security question answers |
| Job postings | Internal software/tools used (helps craft a believable IT pretext) |
🔒 SecurityReview your own social media privacy settings and think about what a stranger could learn about you in five minutes of searching. Limiting public details about your employer, role, daily routine, and family members directly reduces how convincing a targeted attack against you can be.
🧠Quick Checkfirst try = +5 XP
You tweet a complaint at an airline and a 'support' account replies with a link. What's the risk?
🎮 Practice what you learned
⭐ 0 XP🔥 0 days