16.2 Phishing, Spearphishing, Whaling, Vishing, and Smishing
Key Takeaways
- Objective 4.8 classifies the phishing family by channel and target: generic phishing, spearphishing (specific person or role), whaling (senior executives), vishing (voice), and smishing (SMS).
- Credential harvesting — collecting usernames, passwords, multi-factor codes, or session material through deceit — is the typical goal of the phishing family.
- Open-source intelligence emails and org charts are not authorization to phish; social-engineering tests need explicit rules of engagement for each channel.
- Spearphishing is not whaling: a high-dollar pretext against an accounts-payable clerk is still spear; a whale is who, not how expensive the fraud is.
- Vishing is a voice call and smishing is SMS; neither is implied by a network CIDR, and authorizing email phishing does not silently authorize calls or texts.
Objective 4.8 — Given a scenario, perform social engineering attacks using the appropriate tools — is the human matching drill on the same 35 percent Attacks and Exploits domain. This section is the phishing family: phishing, spearphishing, whaling, vishing, smishing, and the usual payoff credential harvesting. Dumpster diving, surveillance, shoulder surfing, tailgating, eavesdropping, watering hole, impersonation, and the named tools — Social Engineering Toolkit (SET), Gophish, Evilginx, theHarvester, Maltego, Recon-ng, and Browser Exploitation Framework (BeEF) — belong in the next section.
Social engineering is never implied by a network CIDR. The RoE must explicitly allow SE: channels (email, SMS, voice), pretext themes, whether production mail gateways may be used, how you store harvested secrets, and a stop condition when a real human is distressed or when a live credential is captured. Public open-source intelligence (OSINT) is not a license to phish. Domain 2 taught you to collect emails and org charts. 4.8 is contacting those people only if the engagement said you may.
Phishing: generic lure, wide net
Phishing is untargeted or loosely targeted deceptive messaging, classically email, that tries to make many people click or reply. The lure is generic: "Your mailbox is full," "HR updated the payroll portal," "IT will disable your account." What it does: it scales. When you pick it: the stem is a blast to a large list, a commodity template, or "employees received the same fake invoice." Credential harvesting is the typical goal: a look-alike login page that collects username and password (and sometimes multi-factor authentication codes). Other payoffs exist — a malware attachment, wire-fraud instructions — but PT0-003's listed harvest bullet is the one to name when the page is a fake single sign-on (SSO) portal.
Exam trap: calling every email spearphishing because it had a logo. A logo is not targeting. Trap two: treating a real vendor's legitimate multi-factor prompt as phishing. Trap three: running a campaign against a partner domain that is not in the SoW because "the employees might click." Partner users, customers, and personal mailboxes that only appeared in a data dump are out of scope until named.
Stay inside the authorized sending path. Many engagements require you to send through a client-approved relay or a clearly labeled tester domain so production mail security can be measured without spoofing a bank the client does not own. If the RoE forbids spoofing example.com itself, a look-alike domain is a different conversation than a blast from an unapproved third-party mailbox.
Spearphishing: one person or role, OSINT-informed
Spearphishing is phishing aimed at a specific person, team, or role, using details that would not appear in a commodity blast: a project name, a manager's real travel, a ticket number, a vendor the target actually uses. What it does: it raises credibility for a small set of victims. When you pick it: the stem shows OSINT — LinkedIn, harvested mailboxes, a press release — folded into the pretext for named staff: finance clerks, a help-desk queue, a named engineer. That is still spear, not automatically whaling. Whaling is about senior executives.
Spear still needs SE authorization. Harvesting a chief financial officer's email on objective 2.4 does not authorize sending them a fake wire request. The recon tools that built the list are not the attack; sending the lure is.
Exam trap: spear equals "email with a name in the To: line." If the body is still "Dear User" and the list is 4,000 mailboxes, that is phishing with a mail merge, not spear. Trap two: spear equals whaling. A spear at a help-desk analyst is still spear even if the pretext mentions money. Trap three: treating a highly personalized mail as authorization to skip the stop condition. A distressed target or a live production password is still a halt-and-report moment when the RoE says so.
Whaling: executives
Whaling is social engineering aimed at senior leadership — C-suite, owners, board members, or similarly high-authority targets. The channel is often email (a spear at a whale) but the classification is the target, not the font. Pretexts that show up on exams: fake legal subpoena, fake merger-and-acquisition data room, fake board portal, fake bank callback for a wire the chief executive "already approved." When you pick it: the victim is an executive, or the pretext only works because the victim is an executive. When you do not: a spear at accounts-payable staff, even if the dollar amount is large. Dollar size is impact. Whale is who.
Whaling against real executives is high-risk politically. RoE should name whether C-level is in play, who will be pre-briefed, and how you halt if the executive starts a real wire. Exam trap: "whaling is any expensive fraud." Trap two: "whaling is vishing because executives prefer phone." Channel is independent: you can whale by email, SMS, or voice. Name whaling for the executive target, then name vishing or smishing if the stem also scores the channel.
Vishing: voice
Vishing is social engineering over voice — a phone call, voicemail, or voice-over-IP pretext. What it does: it uses urgency and authority in a channel where users cannot forward a header to information technology. Classic pictures: help desk calling to "verify" a password or a multi-factor code, a fake vendor collecting a callback number, a fake bank. When you pick it: the stem is a call. Credential harvesting still applies: the caller asks for the password, the seed, the one-time code, or for the victim to read a screen.
Exam trap: vishing equals "any social engineering." A fake badge at the door is impersonation (next section). Trap two: vishing equals smishing because both are "not email." SMS is smishing. Voice is vishing. Trap three: recording production calls without RoE and without lawful-consent rules. Voice tests have extra legal overlay; if the RoE is silent on calls, do not call. Authorizing email phishing does not silently authorize vishing.
Smishing: SMS
Smishing is social engineering over Short Message Service (SMS) (and, on many stems, the same idea on multimedia messaging or consumer chat that is still a phone number). The lure is a short link or a "your package / your parking ticket / your MFA" text. When you pick it: the channel is text message. When you do not: Slack or Teams to a named engineer is closer to spear on a corporate chat, not smishing, unless the exam literally shows SMS.
Mobile users click more carelessly than on a workstation with a warning banner. The harvest page on the phone is still credential harvesting. Exam trap: smishing as "malware on the SIM." The 4.8 bullet is the message, not a baseband exploit (those sit nearer to specialized-system mobile attacks). Trap two: sending SMS to every number in a data dump that includes customers who are not in-scope employees. Trap three: treating a shipping-carrier look-alike text as automatically in scope because marketing already texts staff. The RoE must name SMS.
Credential harvesting is the typical goal
Credential harvesting is collecting usernames, passwords, multi-factor codes, or session material through deceit rather than through a 4.3 password spray or a 4.4 host dump. The phishing family is how you ask. A twin captive portal on 4.7 can harvest too; 4.8 harvest is the human path — email, SMS, or voice lure to a fake identity provider. When you pick it: the stem's success criterion is captured secrets, not a tailgate and not a browser hook (tool matching is next). Harvested secrets are live credentials: store them in the evidence channel named in the RoE, do not paste them into public chat, and stop or rotate per RoE when a real production password lands.
Multi-factor authentication does not make harvest useless. A fake login that also prompts for the one-time code still harvested a short-lived factor. Kits that steal session cookies so multi-factor is already satisfied belong with Evilginx in the next section — conceptual identification only, not a configuration how-to.
A 4.3 spray guesses passwords against a live login. A 4.4 dump pulls hashes or tickets from a host you already occupy. 4.8 harvest is the human handing you the secret because the lure was convincing. Do not mix those three on a matching item.
Differentials you must not mix
| Term | Channel or target | Typical stem cue | Not the same as |
|---|---|---|---|
| Phishing | Generic email (or generic messaging) to many | Same mailbox-full template to a department | Spear just because a logo appeared |
| Spearphishing | Specific person or role, OSINT-informed | Named engineer, real ticket, real vendor | Whaling (executive) or a 4,000-user mail merge |
| Whaling | Senior executive | CEO, CFO, board portal, merger data room | Any high-dollar accounts-payable clerk spear |
| Vishing | Voice call | Help-desk call asking for a one-time code | Smishing; door impersonation |
| Smishing | SMS | Package-link text | Email spear; specialized-system mobile jailbreak |
| Credential harvesting | Payoff: secrets via deceit | Fake SSO page, asked-for password | 4.3 spray; 4.4 Mimikatz dump |
Worked pretext
The SoW allows email and SMS social engineering against employees in example.com, forbids voice, and forbids touching customers. OSINT listed alex@example.com (engineer) and ceo@example.com. A generic "password expire" mail to 500 staff is phishing. A mail to Alex that cites a real ticket from OSINT is spearphishing. A mail to the chief executive about a fake board data room is whaling. A text to Alex with a shipping link is smishing. A call to the chief executive is vishing and is out of RoE here. If any of those authorized lures load a fake SSO, the goal you name is credential harvesting. Tools that run the campaign — SET, Gophish, Evilginx — wait for the next section. Sequence: classify who and which channel, then name harvest if secrets were the point, then check the RoE before anyone hits send.
An authorized tester sends a mail that cites a real Jira ticket to a named help-desk analyst, and a separate mail about a fake board data room to the chief executive. How should those 4.8 attacks be classified?
The statement of work authorizes email phishing against employees. The tester wants to call the finance manager for a one-time code and text a shipping-link lure to staff cell numbers. Which statement is exam-correct?
A fake SSO page collects usernames, passwords, and one-time codes after an authorized spearphish. What is the exam-correct 4.8 payoff name?