Zscalerのブログ

Zscalerの最新ブログ情報を受信

Best Practices

Email bombs and fake CAPTCHAs: A social engineering survival guide

image
RED CANARY INTELLIGENCE
June 24, 2025 - 1 min read

Educate yourself and your organization’s users about two increasingly popular social engineering schemes: email bombing and paste and run

Social engineering is not about hacking computers; it’s about hacking people. It’s a manipulative tactic that exploits human psychology, trust, and digital conditioning to trick individuals into divulging confidential information, granting unauthorized access, or performing actions that compromise security.

SecOps Weekly video thumbnail

This year, Red Canary has consistently observed two social engineering campaigns that adversaries use to gain access into a corporate environment:

• Email bombing: a technique that involves flooding a victim’s inbox with spam email followed by a phone scam to trick the victim into providing remote access to their computer.

• Paste and run (aka ClickFix, fakeCAPTCHA): a technique used to fool users into running malicious code by taking advantage of user’s digital conditioning to get past CAPTCHA-style messages or “fix” requests.

We’ve created a free handout for educating your users about what to look for and how to stay ahead of these emerging social engineering trends.

 

GET THE GUIDE

Our ungated guide includes customizable templates for educating your users about email bombing and paste-and-run campaigns.

form submtited
お読みいただきありがとうございました

このブログは役に立ちましたか?

免責事項:このブログは、Zscalerが情報提供のみを目的として作成したものであり、「現状のまま」提供されています。記載された内容の正確性、完全性、信頼性については一切保証されません。Zscalerは、ブログ内の情報の誤りや欠如、またはその情報に基づいて行われるいかなる行為に関して一切の責任を負いません。また、ブログ内でリンクされているサードパーティーのWebサイトおよびリソースは、利便性のみを目的として提供されており、その内容や運用についても一切の責任を負いません。すべての内容は予告なく変更される場合があります。このブログにアクセスすることで、これらの条件に同意し、情報の確認および使用は自己責任で行うことを理解したものとみなされます。

Zscalerの最新ブログ情報を受信

このフォームを送信することで、Zscalerのプライバシー ポリシーに同意したものとみなされます。