A SOC analyst reviews a phishing report where corporate mobile users received an SMS appearing to be from IT support containing a link to a 'mandatory security update.' Clicking the link opened a page that looked identical to the corporate MDM enrollment portal. Users who entered credentials had their corporate email accounts compromised. What attack type is this?
- A.B. A legitimate MDM re-enrollment notification that was misdirected to personal devices
- B.A. SMiShing (SMS phishing) combined with a credential harvesting page mimicking the corporate MDM portal
- C.C. Vishing: a voice phishing campaign that also uses SMS for follow-up
- D.D. An NFC tag placed near the office entrance that triggered the malicious page when tapped
Why B is correct
SMiShing (SMS phishing) uses text messages to lure victims to malicious pages. In this case, the attack combines SMiShing delivery with a credential harvesting page spoofing the corporate MDM portal. The combination of SMS delivery + fake corporate portal = SMiShing + corporate portal phishing. It is not a legitimate MDM notification. Vishing is voice-based. NFC tags require physical proximity and tap interaction.
Know someone studying for Mobile Security Fundamentals? Send them this one.