3 ms·
presumably he opened a pdf with a zero-day from an untrusted source
by think814 6y ago
presumably he opened a pdf with a zero-day from an untrusted source
- GreenWatermelon 6y agoand that untrusted source could look a lot like his superior's email (boss@c0mpany.com vs boss@company.com) And depending on the resources of the hacker, the email could be stylised just for him, talking about something important that's (perhaps something bad) happening now and the notBoss is telling him to check this months info, and kindly providing him with a pdf that Mathew hastily opens with his latest version of Adobe Acrobat with a zero day vulnerability that hasn't been discovered yet. It could also be literally anything.
- markus_zhang 6y agoYeah agreed, combining social engineering with technical exploits and you can get really good results. I almost fell into one trap myself one day: Basically I was having an argument with a service provider, and somehow I received an email talking about the same type of issue (just high level, without the minute details) with a link attached. I had to check it many times to make sure that it was a fraud email...
- mr_mitm 6y agoPresumably he opened an Office document containing macros. Macros are able to execute system commands and load malicious PowerShell code. Executable files are blocked by pretty much all corporate e-mails systems. Zero-days for PDF viewers are rare. After all, most hacking attacks are things like ransomware campaigns, where everyone is a potential victim and phishing mails are sprayed all over the internet. A zero-day would be burnt pretty quickly. However, many users legitimately need office macros and also need to open office documents to collaborate with contractors or customers. Many times, the phishing mail comes from a legitimate address because the other company has been compromised already. The solution would be to only allow signed macros, but depending on the size of the organization, that can be costly.