ID: SAT1018
- Initial Access
Traditionally, phishing attacks have been mostly email-based. While many organizations have been making use of SaaS-based instant messaging apps, these have been traditionally focused on internal communications, but this is changing rapidly.
Due to the ubiquity and effectiveness of instant messaging apps, communication with external parties has become more common. Instant messaging apps also lack many of the security controls around malicious links and attachments that have been common in email gateways for many years. This along with the immediacy and real-time nature of IM makes it a great vector for phishing attacks as users are less familiar with these apps as delivery vectors for phishing attacks.
- Slack Attack: A phisher's guide to initial access
- Slack Attack: A phisher's guide to persistence and lateral movement
- Jumpsec Advisory: IDOR in Microsoft Teams Allows for External Tenants to Introduce Malware
- TeamsPhisher
- Evilginx - MITM framework for phishing login credentials
- MITRE ATT&CK - Phishing: Spearphishing via Service
- Storm-0324 distributes malware using TeamsPhisher