Detailedlikelihood: Highseverity: HighDraft

CAPEC-163Spear Phishing

Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High

Description

An adversary targets a specific user or group with a Phishing (CAPEC-98) attack tailored to a category of users in order to have maximum relevance and deceptive capability. Spear Phishing is an enhanced version of the Phishing attack targeted to a specific user or group. The quality of the targeted email is usually enhanced by appearing to come from a known or trusted entity. If the email account of some trusted entity has been compromised the message may be digitally signed. The message will contain information specific to the targeted users that will enhance the probability that they will follow the URL to the compromised site. For example, the message may indicate knowledge of the targets employment, residence, interests, or other information that suggests familiarity. As soon as the user follows the instructions in the message, the attack proceeds as a standard Phishing attack.

Related weaknesses· 1

CWE-451

MITRE ATT&CK crosswalk· 7

T1534: Internal SpearfishingT1566.001: Phishing: Spearfishing AttachmentT1566.002: Phishing: Spearfishing LinkT1566.003: Phishing: Spearfishing via ServiceT1598.001: Phishing for Information: Spearfishing ServiceT1598.002: Phishing for Information: Spearfishing AttachmentT1598.003: Phishing for Information: Spearfishing Link

Related attack patterns· 1

CAPEC-98 (ChildOf)

Exploits1

TypeTargetConfidenceTier
WeaknessUser Interface (UI) Misrepresentation of Critical Informationcwe-451100%live

Related to7

TypeTargetConfidenceTier
SubTechniqueSpearphishing Servicet1598.001100%live
SubTechniqueSpearphishing Attachmentt1566.001100%live
TechniqueInternal Spearphishingt1534100%live
SubTechniqueSpearphishing Linkt1566.002100%live
SubTechniqueSpearphishing via Servicet1566.003100%live
SubTechniqueSpearphishing Linkt1598.003100%live
SubTechniqueSpearphishing Attachmentt1598.002100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Phishing
CAPEC
Mobile Phishing
Sub-technique
Spearphishing Attachment
Sub-technique
Spearphishing Service
Sub-technique
Spearphishing Link
Sub-technique
Spearphishing via Service
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.