ZeroFox Intelligence Brief - Social Engineering Series: Non-Email Phishing
|by Alpha Team

ZeroFox Intelligence Brief - Social Engineering Series: Non-Email Phishing
Product Serial: B-2024-02-22a
TLP:CLEAR
ZeroFox's Social Engineering Series breaks down aspects of the threat into digestible reports and outlines defensive actions that can be taken by individuals and organizations. Part Two of this series is a deep dive into the non-email, alternative communication methods that threat actors leverage to conduct phishing attacks.
Standing Intelligence Requirements
Social Engineering, Phishing
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Numerous different communication methods are used in phishing attacks, enabling threat actors to conduct highly-bespoke campaigns targeting specific individuals, organizations, industries, or regions.
- Threat actors leverage voice phishing, SMS phishing (aka smishing), QR Code phishing and USB phishing as alternative delivery methods to email phishing. Each of these offers the attacker unique opportunities, strengths and weaknesses.
- The methods adopted by threat actors conducting phishing attacks will continue to evolve alongside the communication channels used by individuals and organizations and will adapt in response to increased public awareness of contemporary threats, modern security protocols, and the fundamental ways that people interact with technology.
Tags: tlp:clear, phishing & fraud