Method of infection: Water-holing
OSIRIS used a Social Engineering method called “water holing” to attack German IP addresses.Β
How does water holing attack work?
- Β The victim enters the infected website.
- The website checks if the target IP is German.
- If it’s a German IP – few evasion techniques are used to bypass EDR
- And then the virus connects to its command server through the Darknet
Save Your Company from Social Engineering Attacks Like that
Register and Get your Personalized Free Exposure Report NOW,
And see where your Company is Exposed to Hackers
Recently Posted on AUMINT.io Blog
π’ CISOs: Best Free Resources to Manage Security Awareness Campaigns π’
Security awareness campaigns are your frontline defense against social engineering attacks. But managing them effectively without a budget can be tough.
Hereβs a carefully curated list of free resources every CISO can use to plan, run, and measure impactful security awareness programs:
1οΈβ£ SANS Security Awareness Planning Toolkit β Ready-made templates, calendars, and communication guides.
https://www.sans.org/security-awareness-training/resources/planning-toolkit
2οΈβ£ CISA Security Awareness Materials β Posters, videos, and tip sheets designed for wide audiences.
https://www.cisa.gov/security-awareness-resources
3οΈβ£ NIST Security Awareness and Training Guide (SP 800-50) β Framework for building and improving awareness programs.
https://csrc.nist.gov/publications/detail/sp/800-50/final
4οΈβ£ Infosec IQ Free Awareness Campaign Templates β Email and social media content to engage employees.
https://www.infosecinstitute.com/skills/awareness-free-resources/
5οΈβ£ Cyber Aware UK β Free resources and monthly campaign toolkits from the UK government.
https://www.ncsc.gov.uk/cyberaware/home
6οΈβ£ Phishing Quiz by KnowBe4 β Interactive tool to educate employees on phishing red flags.
https://www.knowbe4.com/phishing-security-test
7οΈβ£ Awareness Campaign Scorecard (by Gartner) β Measure campaign effectiveness and engagement.
https://www.gartner.com/en/documents/
Security awareness is not just about info β itβs about culture change.
Want to see how AUMINT.ioβs targeted social engineering simulations can boost your campaign results and give you actionable insights?
π Book your free intro call now: Schedule here
πΎ Save this post and transform your awareness campaigns today!
#CISO #SecurityAwareness #PhishingPrevention #HumanRisk #AUMINT