The delivery phase of a cyberattack focuses on getting malware into a target network through vectors such as email attachments, social engineering, removable media, and compromised third parties. Human vulnerability consistently represents the most exploitable entry point in an otherwise hardened environment.
Malware Delivery Phase
As soon as we've weaponized ourselves, usually by creating or purchasing or somehow attaining malware, we need to deliver that malware into the network.
The weaponization phase is getting the tools and resources necessary to carry out an attack. The next step is possibly to deliver that weaponization. So if we've created malware in the weaponization phase, now what we have to do is deliver that. Somebody has to do the install of the malware. But what does that look like?
One is we could do that. If we were the adversaries and we were targeting a business, somehow we could do the install. There are some obvious issues with this though. How do we get into the building? How do we get access to equipment? We might not have that, and it might be very difficult.
But who does have access to it? Employees of the company, different members of this organization. So then we could have some sort of victim within the organization do the install. We could also have some sort of third parties do the install.
When it comes to the victim or third party, there's a good chance they're not going to want to purposely do something malicious like this. So we're probably going to have to trick them with something like social engineering. Maybe we send it through an attachment. We can send that attachment through instant messaging, email, social engineering, or text. Maybe we get them to download it from online. Maybe we use some sort of removable media for it. Maybe we use some sort of websites or apps.
We could do the same thing if there's some sort of third party, maybe somewhere in the supply chain, or a partner that they have. Maybe it's customers they have. Maybe it's a service provider or vendor that they have.
Somehow we've got to get this malware into that network that we want to compromise. This is where that attack surface comes in, where we're going to analyze those attack surfaces and look for vectors to get inside of this network. That is going to be the way we're going to deliver this malware.
One of the best ways to do this is through social engineering. From a technical perspective, people know how to lock down firewalls usually. From a patching perspective, people are patching machines and are usually pretty good about doing that, at least the IT department is, not always the end user. And people lock down things like wireless because they know it's insecure. But humans tend to be the weakest link of a network. The business has to allow humans onto this network, and humans are fallible. We make mistakes, and there are times when we can be leveraged by other people and manipulated by other people.
Once we do get that delivered into the network, we can move on to the next phase of exploitation.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →