Ace of Spoofing IV
You’ve invented a new spoofing attack.
Threat |
|
To trick an employee who works in the finance department, an attacker may send a message via SMS or a messaging service such as WhatsApp claiming to be a company executive or someone of importance, asking them to make an urgent bank transfer because they are offsite and it needs to be done immediately. Because of the urgency of the message and the status of the person being impersonated, the employee may feel compelled to make the transfer. These methods are often used to manipulate/social engineer the victim. This type of attack is known as smishing. |
|
CAPEC |
CAPEC-164: Mobile Phishing |
ASVS |
N/A |
CWE |
CWE does not currently cover social engineering in the... |