NIST Site Search
Custom Search
[Official NIST.GOV TIME]
Product Research

Advertise on this site
Spear Phishing – Casting a Narrow Net
If you haven't heard of the term “Spear Phishing” you probably don't work for the Department of Defense (DoD). All DoD employees and contractors (Army, Navy, Air Force, Marines, etc.) are now required to complete spear phishing training. What is it and why should you care?No Longer Supported
Spear Phishing is simply as the title of this article indicates, it is the same as phishing but focused on a much smaller audience. A small net to catch just a few, or one, big fish. Often the attack is tailored to a particular individual, office or company. The bait is customized with information familiar, and specific, to the target. Often the attack takes on characteristics of a traditional con. The attacker uses information about you or your company to lower your guard and defeat any skepticism you may have that the email you just received is a scam. The information may be easily obtainable from the Internet, a phone book, or perhaps from a call to the office secretary. Social engineering is often a part of a good spear phishing attack. There is also some sort of bait to convince you that the message isn't just legitimate spam (because even if the sender of the email knows you that doesn't mean you want to open their email).

An attacker may use jargon used by the individual's business or line of work. They may express familiarity with other people within the company and mention them by name. Sometimes they'll reference procedures or forms used by the targets agency. Each of us may think we would never fall for this, but think of the people you work with. Given a personally addressed email that referenced a company specific product or service how many would open an attached file? Especially a MS Word or Excel file (both of which have had exploits recently that can be used to compromise a computer). Probably a large percentage of your coworkers would fall for this.

The goal of a spear phishing attack is often to obtain very specific information. It could be financial information, insider contract information, passwords, sensitive employee data, etc. (Studies show that a large percentage of users are still all too willing to give out their password to someone they don' know that claims to work for the IT department.) If they still fall for that they'll fall for most anything. (See References and Recommendations below)

Scenario 1:
Motivation: Wreak Havoc at a government office
Method: Combined social engineering / spear phishing attack
Details: Attacker finds an employee contact page on the Internet by searching Google for +“employee contacts” +site:gov. This turns up a number of web pages with contacts at various government offices. Attacker settles on a department at XYZ.GOV because not only do they list employee names and email addresses they also list the person's title (many offices still do this). The office also has a Homeland Security role so a successful attack would likely get lots of publicity. The attacker begins by calling a mid-level employee, John, in department YYY saying that he needed to open a trouble ticket for a virus on his computer. John has no idea why this person called his number but promptly gives the person the phone number of the IT Help Desk. Before he hangs up the attack asks John what antivirus he uses and whether he has had any problems before. Attacker then calls the help desk to open a ticket in John's name. While on the phone with the Help Desk the attacker makes friendly and gets this help desk person's name and email address. The attacker now spoofs an email from the Help Desk employee to a few select high level employees at department YYY with the addresses obtained from the web. The email from address is spoofed so that it apparently comes from the Help Desk employee. The email is very convincing as it contains a real name, real phone number for the help desk, even the help desk employee's personal telephone extension. The email also asks recipients to open the attached executable in order to install an antivirus security patch. Of course the attachment is actually a unique backdoor trojan and keylogger. The trojan will not be detectable by the departments antivirus and will install a rootkit that may never be found. After getting login information for the department head the hacker then logs in to several sensitive systems over the course of weeks and makes changes to existing data. The department head's computers are essentially owned by the hacker until they're replaced or completely rebuilt from the ground up.

Scenario 2: (currently being played out)
Motivation: Money
Method: Google harvest / spear phishing attack
Details: Attacker uses an off the shelf email address collection program to harvest email addresses of government employees. These programs are very simple to use and using spidering techniques can collect thousands of targeted email addresses per hour. Attacker uses these addresses to send phishing emails to government employees. The phishing message claims to be from Bank of America (BoA) asking people to update their BoA profile information. The message looks real, is addressed to “Dear Government Employee” and mentions their “government” BoA credit card. Over 1.2 million federal government employees have a BoA credit card and most are use to getting email messages asking them to update their information in some government system or another. Of course once they log in to the system from this email the phishers start running up charges against their government credit card. The Department of Defense specifically addresses this scam in it's spear phishing training that all DoD employees are required to take. But people are still being fooled.

Spear phishing scams are only limited by the attackers imagination. People are just much too likely to be tricked by a phishing email if it contains targeted information familiar to them. We also make it far too easy for attackers by including targeting information on websites. Web pages with information such as a person's email address, job function, title, phone number, mailing address, department name, recent projects they've worked on, client names, etc. are gold mines for the attacker. Employee locators are rich with this type of information and contain lists of thousands of people.

We recently used a government agency employee locator to find an email address of someone in IT security at that office so that we could notify them of a critical vulnerability on their website that was reported to us. When we found an address that said something like we added that as one of the addresses notified. Turned out that address was actually a mailing list. Everyone that had anything to do with IT in that agency received the email! We know because we received hundreds of return receipts. Bad idea to publish that address, in fact mail from the outside shouldn't be allowed to reach such a group (this agency promptly came to the same conclusion). But such an address is perfect spear phishing. Not only does it reach a large targeted audience but the email address even tells you what its used for. Had this been a new unpublished exploit used by an attacker it could have brought that agency down for days and caused immeasurable harm.

  • Training – Though it may not seem as easy as installing a security appliance at the perimeter it is still one of the most effective steps against any social engineering attack. As mentioned above the Department of Defense has mandated it for all DoD employees. Even with all the money and technical know-how they can throw at the problem this was still one of the most important steps.
  • Block inbound message at the perimeter that contain a from address with your own domain (as applicable). Make sure mail from known sources originates from those sources. Eg; If you do a lot of business with a sister organization make sure email from that organization originates from known SMTP servers.
  • Use digital signatures where possible. This is being mandated within DoD and will soon be used throughout the federal government. If an important email is not signed ask the sender to resend it digitally signed. Yes, this can require a large PKI infrastructure but if you are implementing PKI for authentication, HSPD-12, DoD's Common Access Cards (CAC), etc. then by all means start using them within your organization to digitally sign your email. Its the best method for verifying the sender of an email.
  • Use encryption. If only the sender and yourself know the shared secret key then no one else will be able to impersonate one of you to the other. Of course symmetric key encryption (where the key is the same to both encrypt and decrypt a message) becomes very difficult to manage with a large number of people. But its certainly an option. Asymmetric encryption (public / private key) requires the same PKI infrastructure mentioned above or some sort of web of trust to certify the person is who they say they are (see the following description on how the product Pretty Good Privacy (PGP) works).
  • Double up on your current spam defenses. Often times phishing messages originate from compromised computers or botnets. Your anti-spam appliance may have already identified the source as a compromised or rogue SMTP server. Having multiple devices, or services, verifying incoming mail ups the odds of detection.
  • Make sure your users are using either IE7, Firefox 2.0, or Opera 9.1 as those web browsers include some built in protection against known phishing websites. Each of these browsers use technology to compare visited sites against databases of discovered phishing sites. None of these products will offer much protection against true spear phishing since the “narrow net” would probably involve a server that had not yet been discovered. But every layer of protection helps.

  • What is Spear Phishing by Microsoft
  • Spear Phishing by Wikipedia
  • What Is Spear Phishing from Definitions
  • DoD's Spear Phishing Awareness Training – Unclassified PowerPoint but hard to find if you're not part of one of the military Intranets. This link may not work for long so get it while you can, with a little modification it would be great training for any end-user.
  • DoD Information Assurance Awareness – by Defense Information Systems Agency (DISA). Excellent end-user training that can be used by anyone. Takes about 1.5 hours to complete and includes a short test at the end.
  • DoD Battles Spear Phishing – by Federal Computer Week. Real-life spear phishing examples of what the military faces daily. The same techniques can be used against anyone. The argument can be made that every organization or company has something they don't want falling in to the wrong hands.
  • AntiPhishing.Org – A good source of Anti-Phishing information, news, training, whitepapers, and statistics.

Share or Bookmark this Article Using:
No Longer Supported


Posted by on Wednesday 17 January 2007 - 22:05:35 | |printer friendly
Translate to: French German Italian Spanish Portuguese GTM_LAN_DUTCH Russian Chinese Arabic Korean English
Google Ads


»CVE-2009-5149 (na_model_862_gw_mono_firmware)
Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 ha ...
CloudBees Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation betwee ...
»CVE-2015-0856 (_sddm)
daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allo ...
»CVE-2015-5053 (gpu_driver)
The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 b ...
OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module ...
»CVE-2015-5256 (cordova)
Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly imple ...
»CVE-2015-5281 (enterprise_linux)
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, ...
OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, m ...
The Fingerprints pages in CloudBees Jenkins before 1.638 and LTS before 1.625.2 might allow remote a ...
CloudBees Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CS ...
XML external entity (XXE) vulnerability in the create-job CLI command in CloudBees Jenkins before 1. ...
CloudBees Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used ...
The sidepanel widgets in the CLI command overview and help pages in CloudBees Jenkins before 1.638 a ...
Directory traversal vulnerability in CloudBees Jenkins before 1.638 and LTS before 1.625.2 allows re ...
CloudBees Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens ...

Date published: 2015-11-26T05:50:00Z

»US-CERT Alerts Users to Holiday Phishing Scams and Malware Campaigns
Original release date: November 25, 2015 | Last revised: November 26, 2015 US-CERT reminds us ...
»Dell Computers Contain CA Root Certificate Vulnerability
Original release date: November 24, 2015 | Last revised: November 25, 2015 Dell personal comp ...
»VMware Releases Security Updates
Original release date: November 19, 2015 VMware has released security updates to address a vu ...
»IC3 Warns of Cyber Attacks Focused on Law Enforcement and Public Officials
Original release date: November 18, 2015 The Internet Crime Complaint Center (IC3) has issued ...
»Adobe Releases Security Updates for ColdFusion, LiveCycle Data Services, and Adobe Premiere Clip
Original release date: November 17, 2015 Adobe has released security updates to address multi ...
»Apache Commons Collections Java Library Vulnerability
Original release date: November 13, 2015 US-CERT is aware of a deserialization vulnerability ...
»Google Releases Security Updates for Chrome and Chrome OS
Original release date: November 11, 2015 Google has released security updates to address vuln ...
»Microsoft Releases November 2015 Security Bulletin
Original release date: November 10, 2015 Microsoft has released 12 updates to address vulnera ...
»Adobe Releases Security Updates for Flash Player
Original release date: November 10, 2015 Adobe has released security updates to address multi ...
»Symantec Releases Security Update
Original release date: November 09, 2015 | Last revised: November 10, 2015 Symantec has relea ...

Date published: not known

»Throwback Thursday: Legal attempts to reduce spam. A UK perspective
This Throwback Thursday, we turn the clock back to November 2003, when spam was such a hot topic tha ...
»Paper: 3ROS exploit framework kit — one more for the infection road
Aditya K. Sood and Rohit Bansal highlight a different side of an exploit kit. Exploit kits are a ser ...
»Throwback Thursday: What DDoS it all Mean?
This Throwback Thursday, we turn the clock back to March 2000, when DDoS attacks were a newly emergi ...
»The Internet of Bad Things, Observed
In his VB2015 keynote address, Ross Anderson described attacks against EMV cards. The VB2015 opening ...
»Throwback Thursday: Inside Sony's rootkit
This Throwback Thursday, we turn the clock back ten years, when the discovery of a rootkit ignited a ...
»Full house in VB's latest spam filter test
All participating full solutions earn VBSpam certification, while little delay is observed in spam f ...
»Paper: Shifu — the rise of a self-destructive banking trojan
Thorough analysis of this new kid on the malware block. Times are changing rapidly for banking troja ...
» 2015
Great research presented in a stimulating environment. I had heard many good stories about previous ...
»Throwback Thursday: Memetic Mass Mailers: Time to Classify Hoaxes as Malware?
This Throwback Thursday, we turn the clock back to July 2002, when virus hoaxes were wreaking havoc ...

Date published: not known
Main Menu
· Home
Current Security News
US-CERT Current Activity

» US-CERT Alerts Users to Holiday Phishing Scams and Malware Campaigns
[25 Nov 2015 11:21am]

» Dell Computers Contain CA Root Certificate Vulnerability
[24 Nov 2015 04:56pm]

» VMware Releases Security Updates
[19 Nov 2015 02:03pm]

» IC3 Warns of Cyber Attacks Focused on Law Enforcement and Public Officials
[18 Nov 2015 07:25pm]

» Adobe Releases Security Updates for ColdFusion, LiveCycle Data Services, and Adobe Premiere Clip
[17 Nov 2015 04:46pm]

» Apache Commons Collections Java Library Vulnerability
[13 Nov 2015 01:16pm]

» Google Releases Security Updates for Chrome and Chrome OS
[11 Nov 2015 09:47am]

» Microsoft Releases November 2015 Security Bulletin
[10 Nov 2015 05:17pm]

» Adobe Releases Security Updates for Flash Player
[10 Nov 2015 04:35pm]

» Symantec Releases Security Update
[09 Nov 2015 04:47pm]

US-CERT Alerts

» TA15-314A: Compromised Web Servers and Web Shells - Threat Awareness and Guidance
[10 Nov 2015 06:12pm]

» TA15-286A: Dridex P2P Malware
[13 Oct 2015 05:23am]

» TA15-240A: Controlling Outbound DNS Access
[28 Aug 2015 11:31am]

» TA15-213A: Recent Email Phishing Campaigns – Mitigation and Response Recommendations
[01 Aug 2015 04:01pm]

» TA15-195A: Adobe Flash and Microsoft Windows Vulnerabilities
[14 Jul 2015 05:13pm]

» TA15-120A: Securing End-to-End Communications
[29 Apr 2015 10:00pm]

» TA15-119A: Top 30 Targeted High Risk Vulnerabilities
[28 Apr 2015 10:00pm]

» TA15-105A: Simda Botnet
[15 Apr 2015 06:51am]

» TA15-103A: DNS Zone Transfer AXFR Requests May Leak Domain Information
[13 Apr 2015 01:36pm]

» TA15-098A: AAEH
[08 Apr 2015 10:00pm]

Computerworld Security

» Older Dell devices also affected by dangerous eDellRoot certificate
[26 Nov 2015 08:44am]

» Lenovo patches serious flaws in PC system update tool
[25 Nov 2015 11:19am]

» Microsoft's November Windows 10 update messed up some users' privacy settings
[24 Nov 2015 06:21pm]

» Hilton says malware targeted its credit card system
[24 Nov 2015 05:43pm]

» Dell Danger! “Superfish 2.0” blunder: It gets worse
[24 Nov 2015 03:25pm]

» A second dangerous Dell root certificate discovered
[24 Nov 2015 01:03pm]

» What CSOs should do in their first days
[24 Nov 2015 10:38am]

» What you need to know about Dell's root certificate security debacle
[24 Nov 2015 08:39am]

» U.S. is still tiptoeing toward EMV credit cards
[24 Nov 2015 06:29am]

» Infosec jobs: Use keywords to boost your LinkedIn ranking
[24 Nov 2015 05:15am]

» Dell security error widens as researchers dig deeper
[24 Nov 2015 04:42am]

» Dell installs self-signed root certificate on laptops, endangers users' privacy
[23 Nov 2015 03:52pm]

» Adware program Vonteera blocks security products with simple Windows UAC trick
[23 Nov 2015 01:09pm]

» IDG Contributor Network: Attempting to make the sharing economy safer with Onfido
[23 Nov 2015 09:00am]

» United Airlines waits 6 months to patch critical flaw submitted to bug bounty program
[23 Nov 2015 06:10am]

Microsoft Security Advisories

» 3108638 - Update for Windows Hyper-V to Address CPU Weakness - Version: 1.0
[10 Nov 2015 12:00am]

» 2755801 - Update for Vulnerabilities in Adobe Flash Player in Internet Explorer and Microsoft Edge - Version: 50.0
[10 Nov 2015 12:00am]

» 3042058 - Update to Default Cipher Suite Priority Order - Version: 1.1
[13 Oct 2015 01:00am]

» 2960358 - Update for Disabling RC4 in .NET TLS - Version: 2.0
[13 Oct 2015 01:00am]

» 3097966 - Inadvertently Disclosed Digital Certificates Could Allow Spoofing - Version: 2.0
[13 Oct 2015 01:00am]

» 3083992 - Update to Improve AppLocker Publisher Rule Enforcement - Version: 1.0
[08 Sep 2015 01:00am]

» 3057154 - Update to Harden Use of DES Encryption - Version: 1.0
[14 Jul 2015 01:00am]

» 3074162 - Vulnerability in Microsoft Malicious Software Removal Tool Could Allow Elevation of Privilege - Version: 1.0
[14 Jul 2015 01:00am]

» 2962393 - Update for Vulnerability in Juniper Networks Windows In-Box Junos Pulse Client - Version: 2.0
[09 Jun 2015 01:00am]

» 3062591 - Local Administrator Password Solution (LAPS) Now Available - Version: 1.0
[01 May 2015 01:00am]

» 3045755 - Update to Improve PKU2U Authentication - Version: 1.0
[14 Apr 2015 01:00am]

» 3009008 - Vulnerability in SSL 3.0 Could Allow Information Disclosure - Version: 3.0
[14 Apr 2015 01:00am]

» 3050995 - Improperly Issued Digital Certificates Could Allow Spoofing - Version: 2.0
[26 Mar 2015 01:00am]

» 3046310 - Improperly Issued Digital Certificates Could Allow Spoofing - Version: 2.0
[19 Mar 2015 01:00am]

» 3046015 - Vulnerability in Schannel Could Allow Security Feature Bypass - Version: 2.0
[10 Mar 2015 01:00am]

WIRED » Security

» A $10 Tool Can Guess (And Steal) Your Next Credit Card Number
[24 Nov 2015 01:20pm]

» Medical Devices That Are Vulnerable to Life-Threatening Hacks
[24 Nov 2015 05:00am]

» The Doctor on a Quest to Save Our Medical Devices From Hackers
[24 Nov 2015 05:00am]

» Security News This Week: The Manhattan DA Wants Backdoors for Smartphones
[21 Nov 2015 05:00am]

» How to Baffle Web Trackers by Obfuscating Your Movements Online
[21 Nov 2015 03:05am]

» Nice Try, Quantico, But That’s Not How Hacking Works
[20 Nov 2015 10:00am]

» Security Manual Reveals the OPSEC Advice ISIS Gives Recruits
[19 Nov 2015 02:45pm]

» Carnegie Mellon Denies FBI Paid for Tor-Breaking Research
[18 Nov 2015 01:13pm]

» Here’s a Spy Firm’s Price List for Secret Hacker Techniques
[18 Nov 2015 05:26am]

» Department of Defense Head Ashton Carter Enlists Silicon Valley to Transform the Military
[18 Nov 2015 03:00am]

Network World Security

» Older Dell devices also affected by dangerous eDellRoot certificate
[26 Nov 2015 08:44am]

» Millions of embedded devices use the same hard-coded SSH and TLS private keys
[26 Nov 2015 07:56am]

» Microsoft beefs up security products to block adware
[25 Nov 2015 07:50pm]

» Dridex spam campaigns target the US, UK and France
[25 Nov 2015 07:27pm]

» REVIEW: Best VPN routers for small business
[16 Nov 2015 04:00am]

» 6 super-defenses against super-user attacks
[09 Nov 2015 04:00am]

» Review: Stop insider attacks with these 6 powerful tools
[09 Nov 2015 04:00am]

» Ring's Ring: Automating the Doorbell
[07 Nov 2015 11:19am]

» Tor Messenger: Anonymous instant messaging beta released
[30 Oct 2015 10:28pm]

» New endpoint security tools target zero-day attacks
[27 Oct 2015 04:00am]

» Review: Carbon Black and Cylance: The new face of endpoint security
[27 Oct 2015 04:00am]

» REVIEW: Threat Intelligence could turn the tide against cybercriminals
[14 Sep 2015 04:38am]

» Review: How to protect top-secret data
[31 Aug 2015 04:09am]

» Millions of embedded devices use the same hard-coded SSH and TLS private keys
[26 Nov 2015 07:56am]

» Microsoft beefs up security products to block adware
[25 Nov 2015 07:50pm]


More IT Security
News Feeds
More Sponsors

Advertise on this site
RSS Feeds
Our news can be syndicated by using these rss feeds.
Symantec News is in no way connected to the U.S. government site

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues. -
Hosted by BlueHost. We've never had a better hosting company.