📖 What is Spear Phishing?
Spear Phishing is a targeted form of phishing where the attacker researches a specific individual or organization to make the fraudulent message highly personalized. This increased relevance makes the attack more convincing and significantly increases the likelihood of the victim falling for the scam.
"The key difference between phishing and spear phishing is the 'target.' Phishing is a wide net; spear phishing is a sniper rifle."
📚 Certification: CompTIA PenTest+ (PT0-002)
🔑 What are the Key Concepts of Spear Phishing?
- ▸ OSINT integration involves using public sources like LinkedIn or company blogs to gather personal details that make the lure more believable.
- ▸ Psychological triggers such as urgency, authority, or fear are leveraged to manipulate the specific target into taking a desired action.
- ▸ Payload delivery often involves tailored malicious attachments or links that appear relevant to the victim's specific job function or interests.
- ▸ Whaling is a specialized form of spear phishing that specifically targets high-ranking executives, such as CEOs or CFOs, for high-value gains.
- ▸ The success rate is significantly higher than bulk phishing due to the perceived legitimacy and personalization of the communication.
🎯 How does Spear Phishing appear on the PT0-002 Exam?
You may be asked to identify the specific attack type when a scenario describes an attacker researching a HR manager's recent conference attendance to craft a fake follow-up email.
A scenario might describe a penetration test objective to gain initial access to a corporate network; you must select the most effective social engineering method for a specific high-value target.
Expect questions where you must distinguish between phishing, spear phishing, and whaling based on the target's role and the level of personalization used.
❓ Frequently Asked Questions
How is spear phishing different from whaling in a testing context?
Spear phishing targets any specific individual or small group. Whaling is a subset of spear phishing that exclusively targets 'big fish' like C-level executives for high-value data or funds.
What is the relationship between OSINT and spear phishing?
OSINT is the prerequisite. An attacker uses Open Source Intelligence to gather the specific details needed to make a spear phishing email look authentic and trustworthy to the victim.