Phishing Awareness Workshop

๐ŸŽฃ Phishing Awareness

How to spot that it's phishing โ€” and what to do about it

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Rules of the game โš ๏ธ

Everything here is in a lab, with consent, for defense.

You confirmed this at registration โ€” so, briefly:
we recreate attacks so that you can recognize them.

We do not attack people.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

What we'll cover

  1. What social engineering is + real cases
  2. 10 signs of phishing
  3. ๐ŸŽฎ Game "Phishing or not?" (Google Quiz)
  4. ๐Ÿ–ฅ๏ธ Live demo: GoPhish
  5. ๐Ÿ“ฑ Quishing (QR phishing)
  6. ๐Ÿ“ž Vishing + AI voice / deepfake
  7. ๐Ÿ–ผ๏ธ Hidden and malicious files
  8. ๐Ÿ†• Modern attacks: when even MFA doesn't always save you
  9. ๐Ÿ† Final quiz
educational material ยท for defense, not for attack
Phishing Awareness Workshop

1. Social Engineering

"Hacking a human is easier than hacking a system"

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Social engineering targets emotions, not code

The attacker doesn't break the encryption โ€” they make you click.

4 levers of influence:

  • โฐ Urgency โ€” "do it now, or elseโ€ฆ"
  • ๐Ÿ‘” Authority โ€” "it's the director / IT / the bank"
  • ๐Ÿ˜ฑ Fear โ€” "your account has been hacked"
  • ๐ŸŽ Curiosity/greed โ€” "you've won", "look at this photo"

If a message makes you rush and feel โ€” that's a red flag.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Types of social engineering

Type Channel Example
Phishing Email "Your Microsoft account is locked"
Smishing SMS "A DHL parcel is waiting, pay โ‚ฌ1 extra"
Vishing Call "This is the bank, read out the code from the SMS"
Quishing QR code QR for "parking payment" โ†’ fake site
BEC Email (boss spoof) "Urgently pay this invoice, I'm in a meeting"
Spear phishing Targeted An email just for you, with your details
educational material ยท for defense, not for attack
Phishing Awareness Workshop

Real cases (this isn't theory)

Case Year How they broke in
Twitter โ†— (Musk, Obama) 2020 Vishing โ†’ internal panel
Uber โ†— 2022 MFA fatigue: 100 "Approve?" pushes
MGM / Caesars โ†— (casinos) 2023 Call to the helpdesk โ†’ MFA reset
Retool โ†— 2023 SMS + call + AiTM combined

The victims weren't "stupid". These were tech companies with MFA.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

โŒ Classic bait

"Your Microsoft account is locked. Sign in here."

"Congratulations! You've won an iPhone ๐Ÿ“ฑ"

"Urgently check the invoice (attachment)."

"Unusual sign-in to your account. Confirm your identity."

The common thread: urgency + an action + a link/attachment.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

2. How to spot phishing

10 signs

educational material ยท for defense, not for attack
Phishing Awareness Workshop

๐Ÿ” 10 signs of phishing

  1. ๐ŸŒ Odd domain (microsft-login.com, paypa1.com)
  2. โœ๏ธ Errors in the text / strange language
  3. โฐ Urgency and pressure
  4. ๐Ÿ˜ฑ Threats ("your account will be deleted")
  5. ๐Ÿ“Ž Unusual attachment (.zip, .html, .iso)
  6. ๐Ÿ“ท QR code instead of a normal link
  7. ๐Ÿ”‘ Asks for your password / MFA code
  8. ๐Ÿ’ณ Asks you to pay urgently
  9. ๐Ÿ‘ค Unusual sender (name โ‰  address)
  10. ๐Ÿ”— Suspicious links (hover, don't click!)
educational material ยท for defense, not for attack
Phishing Awareness Workshop

Sign #1 โ€” domain and sender

The sender's name lies. The address tells the truth.

From: Microsoft Security <no-reply@microsft-secure-login.ru>
                          ^^^^^^^^ typo       ^^^ odd zone
  • microsft instead of microsoft (typosquatting)
  • paypa1 (a "1" instead of an "l")
  • .ru / .xyz / .top where you'd expect .com
  • a subdomain of lies: microsoft.login-verify.com โ†’ the real domain is login-verify.com!

โœ… Read the domain right to left: the last part before / is the real owner.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

The link text โ‰  where it leads.

๐Ÿ–ฑ๏ธ Try it live โ€” hover (do NOT click) over this "safe" link:

https://www.paypal.com/secure

โ†ณ At the bottom of the browser / in the tooltip the real address appears: evil-login-verify.xyz

โœ… On a computer: hover the cursor, look at the URL at the bottom of the screen.
โœ… On a phone: long-press โ†’ show link.
โœ… Not sure โ€” don't click, go to the site manually.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

What if the email looks perfect?

Modern phishing has no typos (AI writes flawlessly).
Then a process works, not a "gut feeling":

  • ๐Ÿ›‘ Pause. Is the email pushing you to hurry? That's already a signal.
  • ๐Ÿ“ž Second channel. Call/ask directly โ€” don't reply to the email itself.
  • ๐Ÿ” Never enter a password/code via a link from an email.
  • ๐Ÿšฉ Report button in Gmail/Outlook โ€” use it.

Verify, don't trust. This is Zero Trust for people.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

3. ๐ŸŽฎ Game "Phishing or not?"

We vote together

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Google Phishing Quiz (Jigsaw)

๐Ÿ“ฑ Scan from the screen โ€”
take it yourself

๐Ÿ”— phishingquiz.withgoogle.com โ†—

Rules:

  1. We look at an example email together.
  2. We vote: โœ‹ Phishing or ๐Ÿคš Legit?
  3. We discuss why โ€” what to look at.
educational material ยท for defense, not for attack
Phishing Awareness Workshop

4. ๐Ÿ–ฅ๏ธ GoPhish โ€” Live Demo

What an attack looks like from the inside

educational material ยท for defense, not for attack
Phishing Awareness Workshop

What is GoPhish

An open-source platform for legal phishing simulations.

It shows what the attacker sees:

  • ๐Ÿ“ง who received the email
  • ๐Ÿ‘๏ธ who opened it
  • ๐Ÿ–ฑ๏ธ who clicked the link
  • โŒจ๏ธ who entered data on the fake page

โš ๏ธ Only your own test accounts / with consent. Passwords in the demo are fake.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

GoPhish: anatomy of a campaign

Sending Profile  โ†’  who sends (SMTP)
      +
Email Template   โ†’  the email itself (HTML, with {{.FirstName}})
      +
Landing Page     โ†’  fake login page (+ data capture)
      +
Users & Groups   โ†’  who we send to (test accounts)
      =
        Campaign  โ†’  launch + real-time dashboard

The defense visible here: technical mail checks make delivery of the forgery harder.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

GoPhish: what it teaches defense

  • ๐Ÿ“Š You see how easily people click โ€” without blame.
  • ๐Ÿท๏ธ A red "[EXTERNAL]" banner on mail from outside โ€” simple but effective.
  • โœ… Technical mail checks โ€” make sender forgery harder.
  • ๐Ÿšจ The Report Phishing button turns victims into a sensor.
  • ๐Ÿ” Regular simulations โ†“ the click rate over time.
educational material ยท for defense, not for attack
Phishing Awareness Workshop

A look "under the hood" of the email

An email has technical checks of whether the sender is real โ€” the mail system does them itself.

In Gmail: โ‹ฎ โ†’ "Show original":

โœ… You see PASS โ€” good. You see FAIL โ€” a reason not to trust the email.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

5. ๐Ÿ“ฑ Quishing (QR phishing)

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Quishing โ€” why it's dangerous

A QR code = a link you don't see with your eyes.

  • Bypasses email filters (it's just an image!)
  • On a phone it's harder to check the URL
  • Often in PDF "invoices", on "parking meters", "menus"
๐Ÿ”ด Scan it with your phone โ†’ see what happens (our page)

โœ… Defense: the camera shows the URL before opening โ€” read it. Don't scan QR codes from random stickers.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

6. ๐Ÿ“ž Vishing + AI voice

"Hi, it's the directorโ€ฆ"

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Voice and video aren't proof either

๐Ÿ“ž A call "from the boss": authority + urgency + a familiar voice.

Why it works:

  • ๐Ÿ‘” authority ("it's the director / IT / the bank")
  • โฐ urgency ("I'm in a meeting, quick")
  • ๐Ÿง  we're used to trusting a familiar voice

An AI voice clone is made from a few seconds of recording.
Deepfake video is already a reality too.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

AI voice and deepfake: what it's already capable of

๐ŸŽฅ We watch 1โ€“2 short videos โ€” how convincing voice and face fakes have become.

  • A voice clone from a few seconds of recording.
  • Real-time deepfake video (a Zoom call "from the manager").

๐Ÿ’ธ 2024: a company in Hong Kong lost $25M โ€” a transfer after a deepfake video call "from the CFO".

โœ… Conclusion: voice and video are no longer proof of identity.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Vishing: the "Zero Trust for voice" rule

Even if the voice sounds 100% like the boss:

  • ๐Ÿ›‘ Stop if they ask for: a password, an MFA code, a transfer, gift cards.
  • ๐Ÿ“ž Call back a number you know (not the one that called).
  • ๐Ÿ”‘ A code word for urgent financial requests.
  • ๐Ÿค No legitimate service asks for a password by voice.

A voice is no longer proof of identity.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

7. ๐Ÿ–ผ๏ธ Hidden and malicious files

When a "document" isn't what it seems

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Data can be hidden in an ordinary file

๐Ÿ–ผ๏ธ An ordinary photo can contain hidden text โ€” the eye sees no difference, the size is almost the same.

This is called steganography. It hides data (or commands for malware) "in plain sight".

โš ๏ธ Key idea: a file isn't always "just a picture" or "just a document".

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Demo: when a "document" strikes instantly

๐Ÿ–ฑ๏ธ I open an ordinary-looking document file in the browserโ€ฆ

โ†’ ๐Ÿ˜ฑ it shows "You've been hacked!" and downloads a file to the computer by itself.

I didn't press any "Enable" โ€” just opening it was enough.

โœ… Defense: don't open unexpected attachments, not even "invoices" and "documents". In doubt, ask the sender through a second channel.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Which files can be dangerous

We don't show working malware โ€” the reflex is what matters:

  • ๐Ÿ“Š Office with "Enable Content" โ€” that means "I allow code to run". A legitimate document doesn't ask for this.
  • ๐Ÿ“„ PDF / HTML โ€” can contain scripts and lead to a fake login.
  • ๐Ÿ—œ๏ธ Archives (especially password-protected) โ€” hide the payload, bypass antivirus.

โœ… Defense: don't enable macros; don't open unexpected attachments; turn on file extensions (so you catch invoice.pdf.exe).

educational material ยท for defense, not for attack
Phishing Awareness Workshop

8. ๐Ÿ†• Modern attacks

When even MFA doesn't always save you

educational material ยท for defense, not for attack
Phishing Awareness Workshop

MFA: protects very well โ€” but not 100%

MFA (two-factor) is one of the strongest defenses. Turn it on everywhere.

But it gets bypassed too:

  • ๐Ÿ” they send "Approve?" pushes again and again until the tired person taps "Yes" (that's how Uber was hacked).
  • ๐Ÿ•ต๏ธ they steal an already approved session โ€” getting in without a password and without a code.

โœ… Turn MFA on anyway โ€” without it it's far worse. And the rule: "I didn't start a login โ†’ don't approve, press Report".

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Threat landscape: summary

Attack What it targets Simple defense
Phishing attention hover + pause + Report
Email forgery trust check the sender, second channel
Vishing / deepfake trust in a voice second channel + code word
Quishing that you don't see the URL read the address from the camera
MFA bypass your fatigue don't approve what you didn't ask for
educational material ยท for defense, not for attack
Phishing Awareness Workshop

9. ๐Ÿ† Final quiz

Let's test the reflex

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Kahoot โ€” let's compete!

๐Ÿ”— (game code on the screen)

10โ€“15 questions: "Phishing or not?" + "What to do?"

Host: launch Kahoot, give the code, have fun. Questions โ€” in 40_quiz/final-quiz.md.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

๐ŸŽฏ Remember 5 things

  1. ๐Ÿ›‘ Pause before you click โ€” urgency is the signal.
  2. ๐Ÿ” Hover over links, read the domain (right to left).
  3. ๐Ÿ“ž Second channel โ€” verify the request, don't trust the email/voice.
  4. ๐Ÿ”‘ Never dictate a password/code โ€” to anyone, anywhere.
  5. ๐Ÿšจ Report โ€” your button makes everyone safer.

Verify, don't trust.

educational material ยท for defense, not for attack
Phishing Awareness Workshop

Thank you! ๐Ÿ™

Questions?

๐Ÿ“„ I'll hand out / send the cheat-sheet.
๐Ÿ”— Google Phishing Quiz: phishingquiz.withgoogle.com
๐Ÿ”— Check if your email has leaked: haveibeenpwned.com

Stay paranoid in moderation. ๐Ÿ˜‰

educational material ยท for defense, not for attack

This is a Marp presentation. Speaker notes live in HTML comments like this one. Export: marp slides-en.md --pdf (see README in the repo root). Each slide is separated by ---.

Greet the room. Hook: "Raise your hand if you got a suspicious email or SMS in the last month." Almost everyone will. "And who's sure they never once clicked?" Silence. That's why we're here.

15 sec. Don't skip, but do NOT read the 3 rules โ€” one sentence. No-blame tone before the reveal. For DE audiences: mention ยง202a-c StGB, DSGVO/KUG, Betriebsrat verbally.

Cialdini psychology. Emphasize: emotion switches off critical thinking. A pause before acting = the main defense.

BEC = Business Email Compromise. Spear = targeted, the most dangerous because it's personalized.

Tell Uber as a story: a contractor, tired of the pushes, hit Approve. A human isn't a bug โ€” they're the target.

On the next slides we'll go deeper into the 3 most important ones: domain, sender, links.

deep-dive: the domain = everything to the right of the last dot before the first /. account.google.com.evil.ru -> owner evil.ru.

Live demo: hover over the link above โ€” the status bar shows evil-login-verify.xyz. onclick=return false โ†’ the click does nothing (safe).

Show it live in your own mail client: hover over any link, show the status bar.

Host: open them one at a time, don't rush, let people find the sign themselves. 6-8 examples is enough. After each one ask "What tipped you off?" before revealing the answer. Details โ€” in 40_quiz/spot-the-phishing.md

Switch to the VM. The click-by-click scenario โ€” in 30_gophish/setup.md and 20_runbook. Keep the browser already open.

Show the live dashboard: Email Sent -> Opened -> Clicked -> Submitted Data. This is the "wow" moment.

Emphasize: the goal of a simulation in a company isn't to punish, but to measure and train.

Don't dive into acronyms/DNS. The message is simple: mail checks the sender itself; FAIL = signal. Our fake OCM email would have shown FAIL right here.

The QR leads to hacked-landing.html (60_attachments/). BEFORE the workshop: host the reveal page on the phish_server and regenerate qr-hacked.png for the real URL (scratchpad/gen_images.py โ†’ HACKED_URL).

Demo: 60_attachments/quishing-qr.md. Generate a QR to the landing page, have someone in the room scan it (with their own phone, voluntarily).

No practical exercise. Next โ€” a short video (next slide) of what AI voice/deepfake can do now.

Links and timecodes โ€” 50_vishing/deepfake-videos.md. Keep tabs open OR download clips in advance (Wi-Fi may fail). No practical exercise.

Don't show commands โ€” the idea is enough. Anyone wanting steghide details โ€” 60_attachments/steganography-demo.md. Next โ€” a visual demo: a "document" that strikes the moment you open it.

Demo: open 60_attachments/dokument.html in the browser in front of the room, show the downloaded zlamano.txt. Safe (only Blob text, no payload). Runbook โ€” malicious-attachment-concepts.md.

Key: "Enable Content" = "I allow code". Details โ€” 60_attachments/malicious-attachment-concepts.md.

Don't dive into AiTM/FIDO2. The message is simple: MFA is a must, but don't relax โ€” don't approve what you didn't start. You can mention the personal trump card (Evilginx lab) verbally in one sentence.

A break after the heavy topics. A token prize for the winner. Alternative: Google Forms / Mentimeter.

Hand out 90_handout/cheatsheet.md. Collect feedback. Remind about the lab cleanup.