16.2 Phishing, Spearphishing, Whaling, Vishing, and Smishing

Key Takeaways

  • Objective 4.8 classifies the phishing family by channel and target: generic phishing, spearphishing (specific person or role), whaling (senior executives), vishing (voice), and smishing (SMS).
  • Credential harvesting — collecting usernames, passwords, multi-factor codes, or session material through deceit — is the typical goal of the phishing family.
  • Open-source intelligence emails and org charts are not authorization to phish; social-engineering tests need explicit rules of engagement for each channel.
  • Spearphishing is not whaling: a high-dollar pretext against an accounts-payable clerk is still spear; a whale is who, not how expensive the fraud is.
  • Vishing is a voice call and smishing is SMS; neither is implied by a network CIDR, and authorizing email phishing does not silently authorize calls or texts.
Last updated: August 2026

Objective 4.8Given a scenario, perform social engineering attacks using the appropriate tools — is the human matching drill on the same 35 percent Attacks and Exploits domain. This section is the phishing family: phishing, spearphishing, whaling, vishing, smishing, and the usual payoff credential harvesting. Dumpster diving, surveillance, shoulder surfing, tailgating, eavesdropping, watering hole, impersonation, and the named tools — Social Engineering Toolkit (SET), Gophish, Evilginx, theHarvester, Maltego, Recon-ng, and Browser Exploitation Framework (BeEF) — belong in the next section.

Social engineering is never implied by a network CIDR. The RoE must explicitly allow SE: channels (email, SMS, voice), pretext themes, whether production mail gateways may be used, how you store harvested secrets, and a stop condition when a real human is distressed or when a live credential is captured. Public open-source intelligence (OSINT) is not a license to phish. Domain 2 taught you to collect emails and org charts. 4.8 is contacting those people only if the engagement said you may.

Phishing: generic lure, wide net

Phishing is untargeted or loosely targeted deceptive messaging, classically email, that tries to make many people click or reply. The lure is generic: "Your mailbox is full," "HR updated the payroll portal," "IT will disable your account." What it does: it scales. When you pick it: the stem is a blast to a large list, a commodity template, or "employees received the same fake invoice." Credential harvesting is the typical goal: a look-alike login page that collects username and password (and sometimes multi-factor authentication codes). Other payoffs exist — a malware attachment, wire-fraud instructions — but PT0-003's listed harvest bullet is the one to name when the page is a fake single sign-on (SSO) portal.

Exam trap: calling every email spearphishing because it had a logo. A logo is not targeting. Trap two: treating a real vendor's legitimate multi-factor prompt as phishing. Trap three: running a campaign against a partner domain that is not in the SoW because "the employees might click." Partner users, customers, and personal mailboxes that only appeared in a data dump are out of scope until named.

Stay inside the authorized sending path. Many engagements require you to send through a client-approved relay or a clearly labeled tester domain so production mail security can be measured without spoofing a bank the client does not own. If the RoE forbids spoofing example.com itself, a look-alike domain is a different conversation than a blast from an unapproved third-party mailbox.

Spearphishing: one person or role, OSINT-informed

Spearphishing is phishing aimed at a specific person, team, or role, using details that would not appear in a commodity blast: a project name, a manager's real travel, a ticket number, a vendor the target actually uses. What it does: it raises credibility for a small set of victims. When you pick it: the stem shows OSINT — LinkedIn, harvested mailboxes, a press release — folded into the pretext for named staff: finance clerks, a help-desk queue, a named engineer. That is still spear, not automatically whaling. Whaling is about senior executives.

Spear still needs SE authorization. Harvesting a chief financial officer's email on objective 2.4 does not authorize sending them a fake wire request. The recon tools that built the list are not the attack; sending the lure is.

Exam trap: spear equals "email with a name in the To: line." If the body is still "Dear User" and the list is 4,000 mailboxes, that is phishing with a mail merge, not spear. Trap two: spear equals whaling. A spear at a help-desk analyst is still spear even if the pretext mentions money. Trap three: treating a highly personalized mail as authorization to skip the stop condition. A distressed target or a live production password is still a halt-and-report moment when the RoE says so.

Whaling: executives

Whaling is social engineering aimed at senior leadership — C-suite, owners, board members, or similarly high-authority targets. The channel is often email (a spear at a whale) but the classification is the target, not the font. Pretexts that show up on exams: fake legal subpoena, fake merger-and-acquisition data room, fake board portal, fake bank callback for a wire the chief executive "already approved." When you pick it: the victim is an executive, or the pretext only works because the victim is an executive. When you do not: a spear at accounts-payable staff, even if the dollar amount is large. Dollar size is impact. Whale is who.

Whaling against real executives is high-risk politically. RoE should name whether C-level is in play, who will be pre-briefed, and how you halt if the executive starts a real wire. Exam trap: "whaling is any expensive fraud." Trap two: "whaling is vishing because executives prefer phone." Channel is independent: you can whale by email, SMS, or voice. Name whaling for the executive target, then name vishing or smishing if the stem also scores the channel.

Vishing: voice

Vishing is social engineering over voice — a phone call, voicemail, or voice-over-IP pretext. What it does: it uses urgency and authority in a channel where users cannot forward a header to information technology. Classic pictures: help desk calling to "verify" a password or a multi-factor code, a fake vendor collecting a callback number, a fake bank. When you pick it: the stem is a call. Credential harvesting still applies: the caller asks for the password, the seed, the one-time code, or for the victim to read a screen.

Exam trap: vishing equals "any social engineering." A fake badge at the door is impersonation (next section). Trap two: vishing equals smishing because both are "not email." SMS is smishing. Voice is vishing. Trap three: recording production calls without RoE and without lawful-consent rules. Voice tests have extra legal overlay; if the RoE is silent on calls, do not call. Authorizing email phishing does not silently authorize vishing.

Smishing: SMS

Smishing is social engineering over Short Message Service (SMS) (and, on many stems, the same idea on multimedia messaging or consumer chat that is still a phone number). The lure is a short link or a "your package / your parking ticket / your MFA" text. When you pick it: the channel is text message. When you do not: Slack or Teams to a named engineer is closer to spear on a corporate chat, not smishing, unless the exam literally shows SMS.

Mobile users click more carelessly than on a workstation with a warning banner. The harvest page on the phone is still credential harvesting. Exam trap: smishing as "malware on the SIM." The 4.8 bullet is the message, not a baseband exploit (those sit nearer to specialized-system mobile attacks). Trap two: sending SMS to every number in a data dump that includes customers who are not in-scope employees. Trap three: treating a shipping-carrier look-alike text as automatically in scope because marketing already texts staff. The RoE must name SMS.

Credential harvesting is the typical goal

Credential harvesting is collecting usernames, passwords, multi-factor codes, or session material through deceit rather than through a 4.3 password spray or a 4.4 host dump. The phishing family is how you ask. A twin captive portal on 4.7 can harvest too; 4.8 harvest is the human path — email, SMS, or voice lure to a fake identity provider. When you pick it: the stem's success criterion is captured secrets, not a tailgate and not a browser hook (tool matching is next). Harvested secrets are live credentials: store them in the evidence channel named in the RoE, do not paste them into public chat, and stop or rotate per RoE when a real production password lands.

Multi-factor authentication does not make harvest useless. A fake login that also prompts for the one-time code still harvested a short-lived factor. Kits that steal session cookies so multi-factor is already satisfied belong with Evilginx in the next section — conceptual identification only, not a configuration how-to.

A 4.3 spray guesses passwords against a live login. A 4.4 dump pulls hashes or tickets from a host you already occupy. 4.8 harvest is the human handing you the secret because the lure was convincing. Do not mix those three on a matching item.

Differentials you must not mix

TermChannel or targetTypical stem cueNot the same as
PhishingGeneric email (or generic messaging) to manySame mailbox-full template to a departmentSpear just because a logo appeared
SpearphishingSpecific person or role, OSINT-informedNamed engineer, real ticket, real vendorWhaling (executive) or a 4,000-user mail merge
WhalingSenior executiveCEO, CFO, board portal, merger data roomAny high-dollar accounts-payable clerk spear
VishingVoice callHelp-desk call asking for a one-time codeSmishing; door impersonation
SmishingSMSPackage-link textEmail spear; specialized-system mobile jailbreak
Credential harvestingPayoff: secrets via deceitFake SSO page, asked-for password4.3 spray; 4.4 Mimikatz dump

Worked pretext

The SoW allows email and SMS social engineering against employees in example.com, forbids voice, and forbids touching customers. OSINT listed alex@example.com (engineer) and ceo@example.com. A generic "password expire" mail to 500 staff is phishing. A mail to Alex that cites a real ticket from OSINT is spearphishing. A mail to the chief executive about a fake board data room is whaling. A text to Alex with a shipping link is smishing. A call to the chief executive is vishing and is out of RoE here. If any of those authorized lures load a fake SSO, the goal you name is credential harvesting. Tools that run the campaign — SET, Gophish, Evilginx — wait for the next section. Sequence: classify who and which channel, then name harvest if secrets were the point, then check the RoE before anyone hits send.

Loading diagram...
Classify 4.8 phishing-family stems by channel and target
Test Your Knowledge

An authorized tester sends a mail that cites a real Jira ticket to a named help-desk analyst, and a separate mail about a fake board data room to the chief executive. How should those 4.8 attacks be classified?

A
B
C
D
Test Your Knowledge

The statement of work authorizes email phishing against employees. The tester wants to call the finance manager for a one-time code and text a shipping-link lure to staff cell numbers. Which statement is exam-correct?

A
B
C
D
Test Your Knowledge

A fake SSO page collects usernames, passwords, and one-time codes after an authorized spearphish. What is the exam-correct 4.8 payoff name?

A
B
C
D