Microsoft Defender for Endpoint
Endpoint protection

Phishing trends and techniques

In brief

The article adds examples of calendar invitations, attached emails, nested attachments, QR code phishing, and CAPTCHA-gated phishing, and updates its reference links and wording.

What Defender admins need to know

Administrators and security professionals can use the expanded guidance to recognize current phishing techniques and help prevent related attacks.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Phishing trends and techniques

Downloads

An attacker sends a fraudulent email requestingthat asks you to open or download a documentan attachment, such as a PDF.PDF, Microsoft Word document, calendar invitation (.ics), or attached email (.eml). The attachment often containsmight contain a link or message askingthat asks you to sign in to another site,an email or file-sharing site.

Attackers can also nest attachments, such as an email or file sharing websites,that contains a calendar invitation, to opencreate a multistage phishing flow. If you enter your credentials on the document. When you access these phishing sites using your sign-in credentials,site, the attacker now hasgains access to your informationaccount information.

QR code phishing

QR code phishing, also called quishing, embeds a QR code in an image, PDF, or Word document. The message asks you to scan the code with a mobile device, which opens a credential-harvesting site. This technique moves the interaction away from email link scanning and can gain additional personal information about you.onto a device where the destination URL is harder to inspect before you open it.

CAPTCHA-gated phishing

CAPTCHA-gated phishing sites require you to complete a CAPTCHA or another interaction before they display the lure or redirect you to a spoofed sign-in page. Attackers use this extra step to make the site appear legitimate and hinder automated security analysis. The final page commonly attempts to steal credentials.

Phishing emails that deliver other threats

Spear phishing is a targeted phishing attack that involves highly customized lure content. Attackers will typically do reconnaissance work by surveying social media and other information sources about their intended target.

Spear phishing may involve trickingmight trick you into logging intosigning in to fake sites and divulgingentering your credentials. I mayAttackers might also lure you into opening documents by clicking onor selecting links that automatically install malware. With thisThe malware in place,can give attackers can remotely manipulateremote control of the infected computer.

The implanted malware serves as the point of entry for a more sophisticated attack, known as an advanced persistent threat (APT). APTs are designed to establish control and steal data over extended periods. Attackers may try to deploy more covert hacking tools, move laterally to other computers, compromise or create privileged accounts, and regularly exfiltrate information from compromised networks.

For information on the latest phishing attacks, techniques, and trends, you can read these entries on the Microsoft Security blog: