Initial Access

Techniques include exploiting public-facing services such as web servers or remote-access portals; supply-chain compromise; but the most prevalent is through social engineering attacks such as phishing

Phishing Taxonomy

Taxonomy for phishing payloads based on real-world observations of adversary behaviour. He represents it as DELIVERY(CONTAINER(TRIGGER + PAYLOAD + DECOY)) where:

  • Delivery: delivery package to the victim
  • Container: container format used to package the files
  • Trigger: means to trigger payload execution
  • Payload: malicious code to execute
  • Decoy: file to display to the victim

Below is an example of how a campaign was able to distribute the Lumma Stealer malware