You are a mobile threat analyst triaging an alert that matches this scenario.
A SOC analyst reviews a phishing report where corporate mobile users received an SMS appearing to be from IT support containing a link to a 'mandatory security update.' Clicking the link opened a page that looked identical to the corporate MDM enrollment portal. Users who entered credentials had their corporate email accounts compromised. What attack type is this?
- A.SMiShing (SMS phishing) combined with a credential harvesting page mimicking the corporate MDM portal
- B.An NFC tag planted by the office entrance (the tap opened the enrollment page with no prompt shown to the user)
- C.A legitimate re-enrollment notice (misdirected to personal handsets)
- D.Vishing (a voice campaign with an SMS follow-up)
Why A is correct
SMiShing (SMS phishing) uses text messages to lure victims to malicious pages. In this case, the attack combines SMiShing delivery with a credential harvesting page spoofing the corporate MDM portal. The combination of SMS delivery + fake corporate portal = SMiShing + corporate portal phishing. It is not a legitimate MDM notification. Vishing is voice-based. NFC tags require physical proximity and tap interaction.
Know someone studying for Mobile Security Fundamentals? Send them this one.