Smishing

Smishing

One-liner: A phishing attack delivered via SMS text messages to trick victims into clicking malicious links or revealing sensitive information.

🎯 What Is It?

Smishing (SMS + Phishing) is a Social Engineering attack that uses text messages as the delivery mechanism. It's part of the Delivery stage of the Cyber Kill Chain. Attackers send fraudulent SMS messages impersonating trusted entities to steal credentials, install malware, or trick victims into transferring money.

πŸ”¬ How It Works

1. Attacker sends SMS from spoofed number/short code
   └── "Your bank account has been locked. Verify: https://bit.ly/xyz"

2. Victim clicks link
   └── Redirected to fake login page OR
   └── Malware download initiated

3. Credential harvesting / malware execution
   └── Attacker captures credentials
   └── Mobile malware establishes persistence

Common Smishing Lures

Category Example Message
Banking "Unusual activity detected. Verify your account: [link]"
Delivery "Your package is pending. Update delivery: [link]"
Tax/Government "IRS refund available. Claim now: [link]"
Tech Support "Your Apple ID was compromised. Secure it: [link]"
COVID/Health "Vaccine appointment available. Book: [link]"
Prize/Gift "You've won a $500 gift card. Claim: [link]"

πŸ“Š Why It's Effective

πŸ›‘οΈ Detection & Prevention

How to Detect

How to Prevent / Mitigate

For Users:

For Organizations:

🎀 Interview Angles

Common Questions

Key Talking Points

βœ… Best Practices

πŸ“š References