AltaySec · ATLAS 2026.07
AML.T0052

Phishing

Bu tekniğin yerleşik Türkçe adı henüz terminoloji kanonuna eklenmedi; İngilizce adı gösteriliyor.

C · Açıklama (tarayıcıda dürüstçe simüle edilemez) AML.TA0004 · İlk Erişim AML.TA0015 · Yanal Hareket

Açıklama

Türkçe çeviri henüz mevcut değil; resmi İngilizce açıklama gösteriliyor (uydurma çeviri yapılmaz).

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Generative AI, including LLMs that generate synthetic text, visual deepfakes of faces, and audio deepfakes of speech (See Generate Deepfakes), is enabling adversaries to scale targeted phishing campaigns (See Spearphishing via Social Engineering LLM). LLMs can interact with users via text conversations and can be programmed with a system prompt to phish for sensitive information. Deepfakes can also be used in Impersonation as an aid to phishing.

Dürüstlük rozeti gerekçesi

Gerçek altyapı, geçerli kimlik bilgisi veya bir kurban gerektirir. Çalışan bir erişim, dürüst biçimde tarayıcı içinde canlandırılamaz.

Alt-teknikler

Kaynak

← Matrise dön