Attack Techniques · 2.4

🐟 Angler Phishing & Social Media Attacks

Where the attack happens isn't your inbox anymore — it's your feed⏱ ~2 min

Angler phishing mainly targets social media users and often takes advantage of popular or trending topics to create deceptive messages, making them appear relevant and trustworthy. The name comes from the attacker 'fishing' for victims who are already engaged and emotionally invested in a topic.

Common Angler Phishing Patterns

  • Fake customer support accounts — a customer complains publicly about a company (e.g., an airline) and an attacker creates a lookalike support account that replies first, directing the victim to a phishing link
  • Trending hashtag hijacking — attackers post malicious links using trending hashtags to maximize visibility and apparent legitimacy
  • Fake giveaways and contests — 'Like and share to win an iPhone' posts that harvest personal data or drive traffic to malicious sites
  • Romance scams — long-term relationship building on dating apps or social media, eventually leading to requests for money
  • Quizzes and personality apps — seemingly harmless apps that request broad account permissions or harvest data used for further targeting
💡 TipAlways verify customer support accounts directly through the company's official, verified channel — never click on a 'support' account that replies to your complaint unprompted. Check for verification badges, but remember badges themselves have also been spoofed or purchased fraudulently on some platforms.

OSINT — How Attackers Build Their Target Profile

Open-Source Intelligence (OSINT) is the practice of gathering publicly available information to build a profile of a target. Attackers use it constantly before launching spear phishing, pretexting, or vishing attacks.

SourceWhat an Attacker Learns
LinkedInJob title, manager's name, recent promotions, company org structure
Company website / press releasesRecent acquisitions, new vendors, executive travel schedules
Social media (Instagram, Facebook)Pet names, family member names, vacation dates (when you're away)
Data breach dumpsOld passwords (often reused), security question answers
Job postingsInternal software/tools used (helps craft a believable IT pretext)
🔒 SecurityReview your own social media privacy settings and think about what a stranger could learn about you in five minutes of searching. Limiting public details about your employer, role, daily routine, and family members directly reduces how convincing a targeted attack against you can be.
🧠Quick Checkfirst try = +5 XP

You tweet a complaint at an airline and a 'support' account replies with a link. What's the risk?

0 XP🔥 0 days