Initial Access
Techniques include exploiting public-facing services such as web servers or remote-access portals; supply-chain compromise; but the most prevalent is through social engineering attacks such as phishing
Phishing Taxonomy
Taxonomy for phishing payloads based on real-world observations of adversary behaviour. He represents it as DELIVERY(CONTAINER(TRIGGER + PAYLOAD + DECOY)) where:
Delivery: delivery package to the victimContainer: container format used to package the filesTrigger: means to trigger payload executionPayload: malicious code to executeDecoy: file to display to the victim
Below is an example of how a campaign was able to distribute the Lumma Stealer malware
