Delivery technique · MITRE ATT&CK T1566.001, T1566.002
Email phishing
Mass email that impersonates a trusted sender to get a click, a download, or a reply.
How it works
- Attackers send lookalike messages from spoofed or lookalike domains.
- A link leads to a fake login page or a malicious attachment.
- Stolen credentials or malware give the attacker a foothold.
Defenses
- Enforce DMARC on your own domains.
- Use phishing-resistant MFA so stolen passwords are not enough.
- Report suspicious mail with one click and act on the reports.
Reference: MITRE ATT&CK T1566 Phishing
Scams that use it
- Crypto wallet drainer
- Fake airdrop or giveaway
- Tax agency and benefits impersonation
- Fake FBI or IC3 contact
- Fake regulator recovery scam
- Fake refund and over-refund scam
- Package delivery text scam
- Fake law firm and asset recovery scam
- Fake refund of a previous scam
- Marketplace fake payment and overpayment
- Charity and disaster relief scam
- Advance fee and 419 scam
- Lottery, sweepstakes, and prize scam
- Fake check and overpayment scam
- Fake recruiter and hiring scam
- Reshipping and money mule job scam
- CEO fraud (executive impersonation)
- Vendor invoice and payment redirection
- Payroll diversion
- Callback phishing (fake subscription renewal)
- Developer-targeted lures (fake job tests and malicious packages)
- "I recorded you" email sextortion
Cases
2019-12 · US · Sentenced · $122M stolen
Evaldas Rimasauskas sentenced for fake invoice fraud on Google and Facebook, 2019