ZeroFox Intelligence Brief - Social Engineering Series: Email Phishing
|by Alpha Team

ZeroFox Intelligence Brief - Social Engineering Series: Email Phishing
Product Serial: B-2024-02-22a
TLP:CLEAR
ZeroFox's Social Engineering Series breaks down aspects of the threat into digestible reports and outlines defensive actions that can be taken by individuals and organizations. Part One of this series explores email-based phishing, the opportunities it offers threat actors, how it is used to capitalize upon and enable successful social engineering techniques, and what steps can be taken to increase vigilance and reduce the threat.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Social engineering allows threat actors to take advantage of fundamental human attributes that are seen as weak aspects of a network's attack surface and prone to manipulation, exposing cognitive biases and emotional triggers in the attacker’s favor.
- Phishing is almost certainly the most commonly-employed method of social engineering. Successful attacks facilitate data theft or the deployment of malicious software via unauthorized network access.
- Techniques, tactics, and procedures (TTPs) vary significantly over time and between attacks, though the vast majority of phishing attacks leverage a form of pretexting and ultimately rely on the victim’s active participation.
- Email phishing is almost certainly the most commonly-leveraged method of communication observed in phishing attacks. Email phishing offers the attacker a number of advantages, such as the ability to use attachments to deliver malicious payloads.
Tags: us/canada, tlp:clear, phishing & fraud