Spear phishing

We have already come across phishing a couple of times in this book. The difference between phishing and spear phishing is that a phishing attempt is normally indiscriminate and floods the phishing emails to many people hoping that a few will fall for the trap. For example, the Nigerian Prince email is a phishing attack but not quite spear phishing. A spear phishing attack is where the malicious emails are specifically targeted at some people. It is analogous to the common spear, which isolates and attacks an individual rather than a crowd of people. In SET, the spear phishing attack is the first option as can be seen from the following screenshot:

SET Terminal

When we choose the spear phishing attack, we are led into another ...

Get Learn Social Engineering now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.