Vishing

Phishing via voice calls, where attackers impersonate legitimate organizations and ask victims to share personal details over the phone.

|

Based on the sources, Vishing (Voice or VoIP Phishing) is a specific and sophisticated social engineering attack technique used by adversaries to deceive victims into disclosing sensitive personal and financial information.

Here is a detailed breakdown of Vishing:

Definition and Mechanism

Attack Implementation and Tactics

Attackers use several tricks when performing Vishing to gather sensitive information:

  1. Impersonation: The attacker pretends to be a legitimate or authorized person.
    • They may pose as a technical support agent of the target organization or a vendor/contractor.
    • They may impersonate a senior official or a person in a position of authority to extract sensitive information from a help desk.
  2. Abusing Help Desks: Help desks are frequently targeted because staff are trained to be helpful and may give away sensitive information, such as passwords or network information, without verifying the caller's authenticity. An attacker may call the help desk, pretend to be a senior official, and try to extract information.
    • Example Scenario: An attacker (Mike from tech support) might call a user reporting a slowdown and ask for their password to "check the service" on a "new server".
  3. Caller ID Spoofing: Attackers use caller ID spoofing to forge identification, making the call appear to come from a legitimate financial institution or organization.
  4. Pre-recorded Messages: Vishing often involves pre-recorded messages and instructions designed to resemble those of a legitimate financial institution.
  5. Information Sought: Through Vishing, the attacker tricks the victim into providing:
    • Bank account or credit card details for identity verification over the phone.
    • User IDs and passwords.

Context in Social Engineering

Vishing is categorized under Human-based Social Engineering techniques. It is one of the various techniques that can be used for VoIP enumeration attacks.

Countermeasures

Although Vishing specifically targets the voice communication channel, general phishing countermeasures apply to Vishing as well:

Vishing campaigns can be simulated using platforms like OhPhish to test employees' susceptibility to this specific attack vector.