Cyberstudy
PDF p.39 In progress

Message-Based Vectors

Open PDF at p.39 12 flashcards

Summary

PDF p.39

Message-based vectors involve delivering malicious files or links through various messaging platforms to trick users into opening them. These vectors can exploit vulnerabilities in email, SMS, instant messaging, web, and social media platforms.

In plain words

Supplementary — not from your PDF

Attackers send malicious links or files through email, text messages, chat apps and social media. Some 'zero-click' exploits don't even need you to open anything.

Detailed explanation

PDF p.39
  • Email
    • Method: Sending malicious file attachments via email.
    • Technique: Social engineering to persuade users to open attachments.
  • Short Message Service (SMS)
    • Method: Sending files or links via text messaging.
    • Protocol: Uses Signaling System 7 (SS7), which has numerous vulnerabilities.
    • Monitoring: Organizations typically lack monitoring capabilities for SMS.
  • Instant Messaging (IM)
    • Method: Sending files or links via IM apps on Windows, Android, or iOS.
    • Security: Generally more secure than SMS due to encryption, but still vulnerable.
  • Web and Social Media
    • Method: Concealing malware in files attached to posts or as downloads.
    • Drive-By Download: Automatic infection of vulnerable browser software.
    • Disinformation Campaigns: Persuading users to install malicious apps.
  • Zero-Click Exploits
    • Definition: Exploits that trigger simply by receiving an attachment or viewing an image, without user interaction.
  • Social Engineering
    • Method: Persuading users to reveal passwords or weaken security configurations, possibly through voice calls.

Important terms

taken from the text above
Protocol
Uses Signaling System 7 (SS7), which has numerous vulnerabilities.
Drive-By Download
Automatic infection of vulnerable browser software.
Disinformation Campaigns
Persuading users to install malicious apps.
Zero-Click Exploits
Exploits that trigger simply by receiving an attachment or viewing an image, without user interaction.
SMS Short Message Service SS7 System 7 IM Instant Messaging

Examples & real-world scenarios

Supplementary — not from your PDF
  • An email with a malicious attachment and a convincing story.
  • A text message link to a fake parcel-tracking page.
  • A social media post pushing a malicious app.

Scenario

Staff get urgent texts that seem to come from IT, asking them to 'verify' their account through a link. Because SMS is rarely monitored by the organization, reporting procedures and training matter even more.

Common mistakes

Supplementary — not from your PDF
  • Thinking encrypted chat apps are immune. Encryption protects the channel, not you from what's sent over it.
  • Believing you're always safe if you don't click. Zero-click exploits exist, which is why patching matters.

Practical skills

Supplementary — not from your PDF
  • Name a technical and a human control for each messaging channel.

What I should remember

Key Points PDF p.39
  • Email
    • Method: Malicious attachments.
    • Technique: Social engineering.
  • SMS
    • Method: Files/links via text messaging.
    • Protocol: SS7 vulnerabilities.
    • Monitoring: Limited organizational capability.
  • Instant Messaging
    • Method: Files/links via IM apps.
    • Security: Encryption, but still vulnerable.
  • Web and Social Media
    • Method: Malware in posts/downloads.
    • Drive-By Download: Automatic infection.
    • Disinformation: Malicious app installation.
  • Zero-Click Exploits
    • Definition: No user interaction needed.
  • Social Engineering
    • Method: Revealing passwords, weakening security.