1
00:00:00,540 --> 00:00:02,250
In this lesson, I'm going to show you

2
00:00:02,250 --> 00:00:05,250
how easy it is to conduct your own phishing campaign

3
00:00:05,250 --> 00:00:06,510
so you can test your users

4
00:00:06,510 --> 00:00:08,580
and see if they know the correct practices

5
00:00:08,580 --> 00:00:10,710
and how to avoid a phishing scam.

6
00:00:10,710 --> 00:00:12,150
Now, in this campaign

7
00:00:12,150 --> 00:00:14,370
what we're going to do is create our own email.

8
00:00:14,370 --> 00:00:15,203
We're going to send it out

9
00:00:15,203 --> 00:00:17,400
to our users inside our organization,

10
00:00:17,400 --> 00:00:19,230
see if they click on any of those links.

11
00:00:19,230 --> 00:00:22,440
And if they do, we're going to provide them remedial training.

12
00:00:22,440 --> 00:00:25,020
To do all of this, it's not complicated at all.

13
00:00:25,020 --> 00:00:27,150
In fact, you can use a free program

14
00:00:27,150 --> 00:00:29,790
that's provided by Trend Micro to do this for you.

15
00:00:29,790 --> 00:00:32,220
This program is called Phish Insights.

16
00:00:32,220 --> 00:00:34,740
To access Phish Insight, you simply need to go

17
00:00:34,740 --> 00:00:37,920
to phishinsight.trendmicro.com.

18
00:00:37,920 --> 00:00:39,240
If you've never used it before,

19
00:00:39,240 --> 00:00:41,370
you will have to sign up and create an account.

20
00:00:41,370 --> 00:00:44,220
Again, this is a wonderful free tool.

21
00:00:44,220 --> 00:00:46,260
Next, you'll log into your account.

22
00:00:46,260 --> 00:00:48,900
So if we want to create a campaign for ourself,

23
00:00:48,900 --> 00:00:51,840
we're just going to click on Create a Campaign.

24
00:00:51,840 --> 00:00:53,730
Now, I'm going to make a very small campaign here

25
00:00:53,730 --> 00:00:55,050
of just one target.

26
00:00:55,050 --> 00:00:56,490
So I'm just going to key in the recipient

27
00:00:56,490 --> 00:00:58,860
of who I want to send this message to.

28
00:00:58,860 --> 00:01:01,830
And the person I'm going to send it to is Jason,

29
00:01:01,830 --> 00:01:03,780
so I'm just going to call my list name Jason.

30
00:01:03,780 --> 00:01:08,780
And I'm going to put Jason, Dion, jason@diontraining.com

31
00:01:08,910 --> 00:01:13,800
and his title, which is instructor, and that should be fine.

32
00:01:13,800 --> 00:01:15,180
And then we'll hit Continue,

33
00:01:15,180 --> 00:01:17,070
and you'll see that I now have first name Jason,

34
00:01:17,070 --> 00:01:19,110
last name Dion, department is instructor

35
00:01:19,110 --> 00:01:20,370
and his email address.

36
00:01:20,370 --> 00:01:21,780
Go ahead and hit Done.

37
00:01:21,780 --> 00:01:23,400
Next, I'll go down to step two,

38
00:01:23,400 --> 00:01:25,260
which is selecting a template.

39
00:01:25,260 --> 00:01:26,880
What I'm going to do is I'm going to select one

40
00:01:26,880 --> 00:01:28,980
that looks like a LinkedIn connection request

41
00:01:28,980 --> 00:01:30,750
'cause we get those all day long

42
00:01:30,750 --> 00:01:34,050
and most of us don't think twice about clicking on them.

43
00:01:34,050 --> 00:01:35,340
So if I just click on that,

44
00:01:35,340 --> 00:01:36,930
this is the email they're going to get.

45
00:01:36,930 --> 00:01:39,030
It's going to say, "Jason, please add me

46
00:01:39,030 --> 00:01:40,680
to your LinkedIn network."

47
00:01:40,680 --> 00:01:42,720
And all these places would add in Jason Dion.

48
00:01:42,720 --> 00:01:45,960
Hi Jason Dion, I'd like to join your LinkedIn network.

49
00:01:45,960 --> 00:01:47,670
And there's the Accept or the View Profile,

50
00:01:47,670 --> 00:01:50,130
the Update subscribe, all that kind of good stuff.

51
00:01:50,130 --> 00:01:52,830
And this looks like a very realistic email,

52
00:01:52,830 --> 00:01:54,120
and it's already done for us.

53
00:01:54,120 --> 00:01:56,130
If we wanted to, we could customize it

54
00:01:56,130 --> 00:01:57,780
to make it look less like LinkedIn

55
00:01:57,780 --> 00:01:59,280
or more like something else.

56
00:01:59,280 --> 00:02:01,680
But for now, we're going to use this default.

57
00:02:01,680 --> 00:02:02,970
Next, we're going to go through

58
00:02:02,970 --> 00:02:06,210
and specify what the email address is going to come from.

59
00:02:06,210 --> 00:02:10,050
In my case, it's going to come from invitations@linkedin.com.

60
00:02:10,050 --> 00:02:12,690
Notice the email is not actually spelled out LinkedIn.

61
00:02:12,690 --> 00:02:13,980
They're missing a D.

62
00:02:13,980 --> 00:02:16,230
This is something that our user should see

63
00:02:16,230 --> 00:02:19,200
and hopefully flag it as a phishing scam

64
00:02:19,200 --> 00:02:20,640
as opposed to a real one.

65
00:02:20,640 --> 00:02:23,220
And notice that invitations is also spelled wrong.

66
00:02:23,220 --> 00:02:26,430
But if you wanted to make this look very, very realistic,

67
00:02:26,430 --> 00:02:28,920
you could actually put the exact correct

68
00:02:28,920 --> 00:02:33,300
invitations@linkedin.com and spell it all correctly.

69
00:02:33,300 --> 00:02:35,160
Next, you can set up a schedule

70
00:02:35,160 --> 00:02:37,590
and run your campaign over several weeks

71
00:02:37,590 --> 00:02:39,930
or over one week or two weeks or even a month.

72
00:02:39,930 --> 00:02:42,090
And this is good if you have a large organization

73
00:02:42,090 --> 00:02:43,290
where you're doing this with hundreds

74
00:02:43,290 --> 00:02:44,820
or thousands of employees.

75
00:02:44,820 --> 00:02:46,860
You want to see if they learn over time.

76
00:02:46,860 --> 00:02:49,710
And so by doing that, you can set up a schedule.

77
00:02:49,710 --> 00:02:52,110
You can also, then, decide what happens

78
00:02:52,110 --> 00:02:53,910
if they click on one of the links.

79
00:02:53,910 --> 00:02:56,160
So I can have, when the campaign ends,

80
00:02:56,160 --> 00:02:57,457
they will get training and be told,

81
00:02:57,457 --> 00:02:59,130
"Yes, you clicked on a link and you shouldn't have,"

82
00:02:59,130 --> 00:03:00,330
or "No, you didn't."

83
00:03:00,330 --> 00:03:01,530
Or you can do it immediately

84
00:03:01,530 --> 00:03:03,270
when they click on a link and they're phished.

85
00:03:03,270 --> 00:03:05,430
They might get something that looks like this.

86
00:03:05,430 --> 00:03:06,960
This is a webpage that would come up

87
00:03:06,960 --> 00:03:08,880
and say, "Hey, you've been phished.

88
00:03:08,880 --> 00:03:10,380
You need some remedial training.

89
00:03:10,380 --> 00:03:12,420
Click here and you'll get the training,"

90
00:03:12,420 --> 00:03:13,670
something of that nature.

91
00:03:14,700 --> 00:03:17,010
So that's the way you can do that.

92
00:03:17,010 --> 00:03:18,720
And if we go back up here

93
00:03:18,720 --> 00:03:20,490
to our invitation setting our schedule,

94
00:03:20,490 --> 00:03:21,990
or you can do it without notice.

95
00:03:21,990 --> 00:03:24,000
So I'm going to leave it with When Phished,

96
00:03:24,000 --> 00:03:25,950
and then you can send yourself a text message

97
00:03:25,950 --> 00:03:27,873
or confirm to start the campaign.

98
00:03:30,870 --> 00:03:33,450
So now you'll see that that campaign is upcoming,

99
00:03:33,450 --> 00:03:36,540
and it will start in about an hour from now.

100
00:03:36,540 --> 00:03:39,360
Once that happens, we'll be able to see who gets fooled,

101
00:03:39,360 --> 00:03:42,210
analyze those results and give those people training.

102
00:03:42,210 --> 00:03:45,030
So let's look at an example phishing email.

103
00:03:45,030 --> 00:03:48,450
I just sent one out that showed it was coming from LinkedIn.

104
00:03:48,450 --> 00:03:50,850
Now, this is what the user is going to see.

105
00:03:50,850 --> 00:03:54,120
From all looks, it looks like a legitimate email.

106
00:03:54,120 --> 00:03:56,437
If I look at the subject line, it says,

107
00:03:56,437 --> 00:03:58,650
"Jason, please add me to your LinkedIn network."

108
00:03:58,650 --> 00:04:01,590
If I look at who it came from, it came from Invitations.

109
00:04:01,590 --> 00:04:04,020
And if I look at the message, it's got the LinkedIn logo,

110
00:04:04,020 --> 00:04:06,780
it's got things that look just like a LinkedIn message.

111
00:04:06,780 --> 00:04:08,070
But it's not.

112
00:04:08,070 --> 00:04:09,390
If I click on any of these links,

113
00:04:09,390 --> 00:04:11,160
it's not going to take me to LinkedIn.

114
00:04:11,160 --> 00:04:13,530
Instead, it's going to take me to a phishing website.

115
00:04:13,530 --> 00:04:15,540
And as you see as I hover over it,

116
00:04:15,540 --> 00:04:16,829
notice what the link is.

117
00:04:16,829 --> 00:04:20,339
It's not linkedin.com, it's websitefun.club.

118
00:04:20,339 --> 00:04:21,779
Then go over here to the profile one.

119
00:04:21,779 --> 00:04:24,450
Same thing, it brings me to another area of that website.

120
00:04:24,450 --> 00:04:27,000
Changing the frequency, same thing.

121
00:04:27,000 --> 00:04:29,220
This is a classic phishing scam

122
00:04:29,220 --> 00:04:30,450
where it looks like one thing,

123
00:04:30,450 --> 00:04:32,670
but when you click on it, it goes to another.

124
00:04:32,670 --> 00:04:34,680
Notice this email is well-crafted.

125
00:04:34,680 --> 00:04:37,320
It's crafted to look exactly like LinkedIn,

126
00:04:37,320 --> 00:04:39,660
and it will trick a lot of your users.

127
00:04:39,660 --> 00:04:42,120
So one of the things we want to do with our phishing campaigns

128
00:04:42,120 --> 00:04:45,450
is to train our users that clicking links is bad.

129
00:04:45,450 --> 00:04:49,350
Instead, if I got this as a user, what should I do?

130
00:04:49,350 --> 00:04:51,000
I should open up a new web browser,

131
00:04:51,000 --> 00:04:53,970
and I should go to linkedin.com, the site I know.

132
00:04:53,970 --> 00:04:57,270
And from there I can accept or reject that friend request.

133
00:04:57,270 --> 00:04:58,440
But just getting an email,

134
00:04:58,440 --> 00:04:59,820
you don't want to click on those links

135
00:04:59,820 --> 00:05:02,970
because that is an easy way to get yourself into trouble

136
00:05:02,970 --> 00:05:04,770
because it can download malware,

137
00:05:04,770 --> 00:05:07,020
or it might just collect information from you,

138
00:05:07,020 --> 00:05:08,077
like you click on it, it says,

139
00:05:08,077 --> 00:05:10,680
"We need your username and password to log into LinkedIn."

140
00:05:10,680 --> 00:05:11,910
And they have a website sitting there

141
00:05:11,910 --> 00:05:13,680
that looks just like LinkedIn.

142
00:05:13,680 --> 00:05:15,000
And when you give them that information,

143
00:05:15,000 --> 00:05:16,770
they now have your credentials

144
00:05:16,770 --> 00:05:19,463
and they can take advantage of that for other attacks.

