Detailedlikelihood: Highseverity: HighDraft
CAPEC-163Spear Phishing
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High
Description
An adversary targets a specific user or group with a Phishing (CAPEC-98) attack tailored to a category of users in order to have maximum relevance and deceptive capability. Spear Phishing is an enhanced version of the Phishing attack targeted to a specific user or group. The quality of the targeted email is usually enhanced by appearing to come from a known or trusted entity. If the email account of some trusted entity has been compromised the message may be digitally signed. The message will contain information specific to the targeted users that will enhance the probability that they will follow the URL to the compromised site. For example, the message may indicate knowledge of the targets employment, residence, interests, or other information that suggests familiarity. As soon as the user follows the instructions in the message, the attack proceeds as a standard Phishing attack.
Related weaknesses· 1
MITRE ATT&CK crosswalk· 7
T1534: Internal SpearfishingT1566.001: Phishing: Spearfishing AttachmentT1566.002: Phishing: Spearfishing LinkT1566.003: Phishing: Spearfishing via ServiceT1598.001: Phishing for Information: Spearfishing ServiceT1598.002: Phishing for Information: Spearfishing AttachmentT1598.003: Phishing for Information: Spearfishing Link
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | User Interface (UI) Misrepresentation of Critical Informationcwe-451 | 100% | live |
Related to7
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Spearphishing Servicet1598.001 | 100% | live |
| SubTechnique | Spearphishing Attachmentt1566.001 | 100% | live |
| Technique | Internal Spearphishingt1534 | 100% | live |
| SubTechnique | Spearphishing Linkt1566.002 | 100% | live |
| SubTechnique | Spearphishing via Servicet1566.003 | 100% | live |
| SubTechnique | Spearphishing Linkt1598.003 | 100% | live |
| SubTechnique | Spearphishing Attachmentt1598.002 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.