Common attacks and their effectiveness Flashcards
What is phishing?
The use of digital communications to trick people into revealing sensitive data or deploying malicious software
What are the most common types of phishing?
Business Email Compromise (BEC), Spear Phishing, Whaling, Vishing, and smishing
What is business email compromise (BEC)?
When a threat actor sends an email message that seems to be from a known source to make a seemingly legitimate request for information, in order to obtain a financial advantage
What is Spear Phishing?
A malicious email attack that targets a specific user or group of users. The email seems to originate from a trusted source
What is whaling?
A form of spear phishing. Threat actors target company executives to gain access to sensitive data.
What is vishing?
A form of spear phishing. Threat actors target company executives to gain access to sensitive data
What is smishing?
The use of text messages to trick users, in order to obtain sensitive information or to impersonate a known source
What is malware?
A software designed to harm devices or networks. Malware is primarily used to obtain money, or sometimes an advantage that can be used against a person, an organization, or a territory
What are some of the most common types of malware attacks today?
Viruses, worms, ransomware, and spyware
What are viruses?
Malicious code written to interfere with computer operations and cause damage to data and software. When a user opens/downloads the malicious attachmetns, the virus hides itself in other files and when the infected file is open. The virus can now insert its own code to damage/destroy the system
What are worms?
Malware that can duplicate and spread itself across systems on its own. A worm does not need to be downloaded/opened, it self-replicates from an already infected computer to other devices on the same network
What is ransomware?
A malicious attack where threat actors encrypt an organization’s data and demand payment to restore access
What is spyware?
Malware that’s used to gather and sell information without consent.
What is social engineering?
A manipulation technique that exploits human error to gain private information, access, or valuables.
What are the most common types of social engineering?
Social media phishing, watering hole attack, USB baiting, and physical social engineering