pctechguide.com

  • Home
  • Guides
  • Tutorials
  • Articles
  • Reviews
  • Glossary
  • Contact

Case Study on a Spear Phishing Campaign from the Energy Secto

Earlier this week, we wrote an article on the threats of spear phishing. We thought we could drive the lesson home with a story about a spear phishing attack that happened recently.

A very sophisticated spear phishing campaign has exploited a major energy company. The scam used a clever ruse to get around the organization’s Microsoft email security software. It relied on a complicated phishing attack that was sent from Google Drive. According to Aaron Riley, a researcher from cybersecurity firm Cofense, the scammers impersonated as the CEO of the organization.  The scammers sent an email via Google Drive and said they were sharing “sharing an important message” with the employees. Nobody wanted to disbelieve the CEO of the company.

The email was not sent directly by a hacker. The originator of the email was actually Google Drive. It was received by subordinates, but it triggered a major “warning”: the email address did not conform to the company’s internal naming convention for emails. But most employees wouldn’t take the time to verify the threat and clicked the link anyways, Riley told us. This proves that the desire to avoid investing a few seconds to versify something can be a tragic mistake.

The link was incorporated in email content. It linked to a legitimate Google Drive filled with numerous documents that employees could download. Also, Microsoft’s email spam detection tool does not determine the destination that the user is going to be taken after clicking on the link on the Google Drive. Even though the Google Drive link may not look malicious, the final destination that the user will be referred to could contain malicious malware or be part of a devious social engineering scheme by hackers. As a result, the user could be lulled into  a false sense of security.

Let’s review the email received by employees:

Dear colleague, I want to share a few thoughts and deliver a quick review regarding topic X. These thoughts will be explained in detail. All employees are obligated to read, know and interpret it, as well as share their opinions. I appreciate your constant help in improving our organization. CLICK HERE TO SEE THE UPDATE. Note: the message is of great import and all workers should view the link.

Riley explained that scanning past the first link wouldn’t solve the problem. The email inspection application still would not be able to evaluate links that were present on the following pages unless the user was trying to download them.

The phishing attack was not detectable, because there was not an immediately visible threat.

Once a user accessed a document on Google Drive, nothing immediately happened that was malicious. The targets were given an explanation of a public business decision by the “CEO” and then asked to view a related document via another link.

Any employees that decided to click the link embedded in the Google Drive document were sent to a fake login page that had recently been registered at the domain. Once the victims provided their credentials, they were shared with the scammers.

The real lesson here is that employees could have been taught to look for suspicious emails and could have prevented the attack. In addition to the fact that the CEO’s email address was incorrect, the information about the “business decision” was over a year out of date. Additionally, two sentences in the document contained very poor English: “I appreciate your constant help in improving our organization” and “the email is of great import and all employees should access the link”, which are informal. This is already a warning sign that should not have been missed.

Riley noted that exactly the same sentences were witnessed in a similar scam that had targeted major universities, indicating that the hacker has a known MO, which will make it easier to detect future phishing. By recognizing sentences that have already been used, a future attack could be recognized. It is important, then, to pay special attention to the content of an email you receive.

Filed Under: Articles

Latest Articles

Thinking of Selling Your Phone? Follow These Tips First

Smartphones and tablets have grown exponentially the past few years. People trade them in quite often because they want the newest device or they are presented with a new deal. If you are in the position to trade in your device or sell it to obtain a new one, then there are a few things you should … [Read More...]

Remove ICE Cyber Crimes Center

ICE Cyber Crimes Center warning is not from ICE the United States government agency. This is an extortion scam that is a clone of another virus called FBI Money PAK. If you would like to confirm this just look at http://www.ice.gov/news/releases/1302/130215washingtondc2.htm They made a press … [Read More...]

The Google Nexus 7 4G LTE Tablet

Now, Google Nexus 7 4G LTE Tablet brings in the best integration of portability, power and the sharpness for a 7 inch tablet screen can offer. It has a simple and clean design for a slim casing, with a thin edge-soft to touch, and a matte back cover. Enjoy the Features New slim design It … [Read More...]

Everything You Need to Know About Sourcing Circuit Boards From U.S. Suppliers

In This Article This article includes: Why Source PCBs From the United States?How to Get a Quote From a U.S.-Based PCB ManufacturerThe Top U.S. … [Read More...]

Top Taplio Alternatives in 2025 : Why MagicPost Leads for LinkedIn Posting ?

LinkedIn has become a strong platform for professionals, creators, and businesses to establish authority, grow networks, and elicit engagement. Simple … [Read More...]

Shocking Cybercrime Statistics for 2025

People all over the world are becoming more concerned about cybercrime than ever. We have recently collected some statistics on this topic and … [Read More...]

Gaming Laptop Security Guide: Protecting Your High-End Hardware Investment in 2025

Since Jacob took over PC Tech Guide, we’ve looked at how tech intersects with personal well-being and digital safety. Gaming laptops are now … [Read More...]

20 Cool Creative Commons Photographs About the Future of AI

AI technology is starting to have a huge impact on our lives. The market value for AI is estimated to have been worth $279.22 billion in 2024 and it … [Read More...]

13 Impressive Stats on the Future of AI

AI technology is starting to become much more important in our everyday lives. Many businesses are using it as well. While he has created a lot of … [Read More...]

Guides

  • Computer Communications
  • Mobile Computing
  • PC Components
  • PC Data Storage
  • PC Input-Output
  • PC Multimedia
  • Processors (CPUs)

Recent Posts

Scanner Operation

On the simplest level, a scanner is a device which converts light (which we see when we look at something) into 0s and 1s (a computer-readable … [Read More...]

What is L2 (Level 2) cache memory?

Most PCs are offered with a Level 2 cache to bridge the processor/memory performance gap. Level 2 cache - also referred to as secondary cache) … [Read More...]

New AI Technology Detects and Prevents Cheating in Online Games

AI technology has been central to the video game industry since the very beginning. However, we are only recently starting to discover the true … [Read More...]

[footer_backtotop]

Copyright © 2026 About | Privacy | Contact Information | Wrtie For Us | Disclaimer | Copyright License | Authors