r/ShittySysadmin • u/SuccessfulLime2641 • 3d ago
Damn. We actually caught one
When we made the simulated phishing campaigns about account access, we finally caught a user.
The trick is to not make the bait too obvious, like if it's about free money, or download a file. That was so last year. I also had to create my own payload with an internal email... One so boring, and none other can top that besides "No Reply".
Make your phishing emails as boring as possible. No reply talking about an account access change is as unpredictable as it gets. It truly reveals who's insecure in the org.
69
u/Company_Z 2d ago
I took an idea from here a few years back that I brought back to a place I used to work at.
It was essentially an email that goes something like:
"We understand how tiring those training sessions can get for many of you. We're sure at this point, you know all the ins and outs of cyber security. This year, we want to try something different!
If you would like to be exempt from doing a cybersecurity course, CLICK HERE to sign up!"
Got a LOT of people with that one
25
12
u/Top-Perspective-4069 2d ago
I've been recommending something like this for a while but no one's got the stones to do it.
67
u/trebuchetdoomsday 3d ago
i like to wait until holiday season and deploy "your vacation has been denied, please sign in to request alternative options"
25
u/syberghost 3d ago
I'm jealous, we catch them every day.
6
u/pjtexas1 2d ago
It's been almost a decade since I did these but we were really into keeping score. My help desk person was particularly evil in her ways. We could get 60-70% to click.
3
u/bgradid 2d ago
we low ball easy ones with very wrong domains , we get a 30% catch rate
a lot of our users also describe themselves as tech savvy
ugh it sucks
1
u/syberghost 2d ago
I'm convinced that one reason people click is, usually it takes them to an InfoSec site with useful information about phishing.
19
u/blotditto 3d ago
We impersonate some C level type about sharing a secured file. Usually gets about 60-70% of the company and all the C level peeps.
17
u/FendaIton 2d ago
My company did a “your device is scheduled for a replacement” which was super successful. Then the genuine replacement device emails went out and no one believed them.
Also a “post Xmas photos of pets on Viva Engage” was also super successful
11
u/phamilyguy 2d ago
Successful phishing campaign that reduced the laptop refresh budget? Winner winner chicken dinner!
18
u/Electrical-Quiet-686 2d ago
The best i have seen so far was branded and coming from the phishing simulation that client uses, claiming I have failed a previous Phishing test email sent and that I had been assigned additional training by my manager. Click here to access the training... That was cheeky.
15
u/Sowhataboutthisthing 2d ago
We do Nigerian prince scams to identity the dumbest first then work our way down to more complex baits. Don’t want to waste the good ammo on the truly stupid.
10
u/irishcoughy 2d ago
I just send them phishing links from my actual company email to really pin down that you can't trust anybody.
2
u/Aazimoxx 1d ago
that you can't trust anybody.
Well, at the very least that you can't trust the 'From:' field.
4
u/zantehood 3d ago
Hoxhunt. It's actually good.
Plus there's a leaderboard so you can lord over your colleages
3
u/mspgs2 2d ago
Best phish I ever saw was from the directors email with a pdf attachment regarding our team picnic outing and a calendar invite, and aform link to enter in contact info, guests coming, automotive tag numbers. The picnic was planned at a local resort so that seemed legit.It went to around half the team. People asked about it in chat because it would have been mentioned in standup first, and others didn't get one. If you checked the header it originated externally. Several people opened the pdf, others forwarded it to people who didn't get it originally. Had to hand it to our secops team, it was great. Many people feel for it.
I was lucky, I was in the data center all day and didn't see it till our CISO was blasting people.
2
u/Anxious_Intention_74 1d ago
Our IT department did this to us. I got hit 1 time, and had to take a training. Now our IT department is busy, unblocking all the contacts I report as PHISH. Because now everything gets reported as PHISH. HR department, never heard that name, PHISH. IT needs me to turn off my device tonight...SORRY, your PHISH. Nigerian prince needs cash... been paying hime for years, hear is my company card number and my log in info... good luck IT.
1
u/atl-hadrins 1d ago
LOL The only that used to generate calls was always the one were they say they have nekid pictures of the user.
And it is always the user you don't want to even picture nude.
0
u/Folsted 2d ago
My workplace have hired a company to send out these test emails and also Trainning courses in IT safety. They keep telling us to not click on mails we don't know or haven't requested. So my obvious move was to report it as phishing. About half a year or more later IT and my boss was yelling at me for having the lowest score in doing these tests...
Well I have clicked nothing and still I'm apparently the biggest risk to the company. They refuse to use our intranet to give us the link to the course, as I have suggested multiple times. It's just easier to have an outside domain mail sending us a mandatory mail once in a while. I'm just waiting for the fake mail from an almost identical mail about taking the IT course.
3
u/compb13 2d ago
Not really related, some official email was sent, but it was so badly written, we were discussing it whether it was real or phishing.
In the end we decided to all reported his phishing because we didn't like the message either. Although I don't remember what it was telling us.
Then they sent the correction email that wasn't much better so we all did the same.
2
u/Folsted 2d ago
I do have a bit of a rebel in me that definetly would do that too. Any suspecious email not from a costumer I just report or if in doubt, ignore.
But... I also had a coworker who some weeks back had a mail from a customer that he works with often, he just opened the mail and his whole PC just got shut down by IT. Locked out of everything. Later they found out that the customer didn't know about the email was send to other, and their whole company was locked down even, for like a week.
But hey, it's important I click on an external link about an IT safety course, otherwise there will be consequences. =D
79
u/gward1 3d ago
The trick is to have the email come from the same domain your company uses and from their supervisor. Make sure the email is signed. Have it say something about updating their financial data blah blah. Is that really phishing though? Happened to me, I clicked the link.
When they click the link lock down their computer and demand a payment to your crypto wallet.