📖 What is Spear Phishing?
Spear Phishing is a targeted form of phishing where an attacker sends a personalized message to a specific individual or small group. By using gathered intelligence about the target, the attacker increases the likelihood that the victim will trust the message and reveal sensitive data.
"Contrast this with "phishing" (broad/generic). If the attacker knows the target's name or job title, it's "spear" phishing."
📚 Certification: CompTIA Security+ Certification Exam (SY0-701)
🔑 What are the Key Concepts of Spear Phishing?
- ▸ Attackers perform reconnaissance using OSINT, gathering data from social media and company websites to make the message appear authentic and trustworthy.
- ▸ Personalization is the defining characteristic, utilizing specific names, job titles, or internal project details to bypass the victim's natural suspicion.
- ▸ These attacks leverage social engineering tactics, such as urgency or authority, tailored specifically to the victim's professional role or personal interests.
- ▸ The primary goal is often credential theft or malware delivery, using highly convincing lures like targeted invoices or internal company memos.
🎯 How does Spear Phishing appear on the SY0-701 Exam?
A scenario might describe an HR manager receiving an email that references a specific employee's name and a recent internal policy change. You will be asked to identify this as spear phishing.
You may be asked to distinguish between a generic phishing campaign sent to thousands of users and a targeted attack aimed at the accounting department to steal financial data.
Expect questions where you must identify the reconnaissance phase of an attack, specifically when an attacker uses LinkedIn to find the names of IT administrators to craft a convincing lure.
❓ Frequently Asked Questions
What is the difference between spear phishing and whaling?
While both are targeted, spear phishing can target any specific individual or group. Whaling is a specialized subset of spear phishing that exclusively targets high-profile executives, such as the CEO or CFO.
Can spear phishing be conducted through channels other than email?
Yes. While email is most common, spear phishing can occur via SMS (smishing) or voice calls (vishing), provided the attacker uses personalized information to target a specific individual.