Phishing attacks are becoming frighteningly sophisticated: Hackers are taking extreme measures to trick their victims, including impersonating real people and creating fake social media accounts. In order to gain access to confidential usernames and passwords, hackers send malicious phishing links that unsuspecting people can click on.
See also: Phishing scam: Australian sentenced to two years in prison

The National Cyber Security Centre (NCSC) – part of the British intelligence agency GCHQ – has sounded the alarm about phishing attacks, which are targeting individuals and organisations across many industries.
The ultimate goal of phishing attacks is to trick victims into clicking on malicious links, leading them to fake login pages. Here, the victim will provide their credentials – giving hackers access not only to that account but also to other potential targets, which they can exploit for financial gain or personal information.
See also: Google ads phishing attack targets Bitwarden users
Cybercriminals are known to disguise malicious links in popular cloud software and collaboration tools, such as OneDrive and Google Drive. In one case, the perpetrators went so far as to set up a Zoom call with their victim, sending a suspicious URL through the chat line during the call. To further add an air of authenticity, they use multiple accounts for this phishing thread – all under their control!
To launch spear-phishing attacks, attackers first conduct extensive research and preparation. To uncover as much information about victims as possible, malicious actors leverage publicly available profiles on social media and other platforms. This includes both professional details about job roles and personal contacts in the real world.
It is quite common for attackers to create fake social media and networking profiles in the name of real people, as this makes their tactics even more convincing. Some approaches are also crafted to appear to be related to legitimate events, while they are completely fabricated.
According to the NCSC, international cybercriminals from Russia and Iran have launched campaigns to trick innocent victims with phishing attacks. Although Russian and Iranian attackers use different tactics, there is one thing they both share: targeting personal email accounts as part of their dangerous schemes. No matter how convincing or attractive the lures may seem, it is important to remember not to fall for suspicious emails or attachments!
It appears that this method is used to bypass cybersecurity protocols of corporate accounts and networks, however commercial email addresses have also been identified as targets.

One of the most important strategies attackers use in phishing campaigns is their patient approach. Instead of quickly asking targets to click on a dangerous link or open an infected attachment, they try to gradually build trust over time . This slow and steady approach helps them significantly increase chances of success .
This process usually begins with a seemingly innocent initial email message, which is carefully crafted to be as engaging and interesting as possible for recipient . Thanks to meticulous preparation, this communication is likely to grab attention .
Attackers cunningly engage the target in an email exchange over an extended period, slowly but steadily building their trust until they feel secure enough to open any link or attachment sent to them.
The malicious link will be cleverly disguised as a seemingly important and interesting document or website – once the victim clicks on it, they are redirected to the server .
Once the victim enters their username and password to access the malicious link, these details are immediately transmitted to the attackers. This allows them to take advantage of any emails or other accounts belonging to their victims.
See also: Porsche ends its new NFT program – phishing sites appear
As the NCSC points out, malicious attackers are not only able to steal data and files stored in accounts, but they can also monitor emails and file attachments sent or received by their victims.
Attackers maliciously exploited access to a target's email account and mailing list data, as well as contact lists, to launch surveillance campaigns. Using the compromised email address, they then conduct further phishing attacks on other potential victims.
Information source: zdnet.com
