TechKnowSurge
VideoSecurityFree

Delivery

The delivery phase of a cyberattack focuses on getting malware into a target network through vectors such as email attachments, social engineering, removable media, and compromised third parties. Human vulnerability consistently represents the most exploitable entry point in an otherwise hardened environment.

Complete this video to capture a CTF flag worth 1 point.

About this video

The delivery phase of the cyber kill chain is where an attacker moves from preparation to action, introducing malware into a target environment through one or more available attack vectors. Because direct physical access to a target organization's systems is rarely feasible, adversaries typically rely on people inside or connected to the organization to unknowingly carry out the installation. This can include employees, contractors, third-party vendors, supply chain partners, or customers, any of whom may interact with the target network in ways that can be exploited. Since these individuals are unlikely to act maliciously by choice, attackers almost always use social engineering to deceive them into executing the delivery mechanism. Common methods include malicious email attachments, phishing links, downloads hosted on compromised websites, rogue applications, and removable media. Analyzing the target's attack surface is central to identifying which of these vectors is most likely to succeed. Technical defenses such as properly configured firewalls, routine patch management, and secured wireless infrastructure can significantly reduce the available attack surface. However, human behavior remains the most consistently exploitable weakness, as organizations must grant people access to function, and people are susceptible to deception and manipulation in ways that technical systems are not. Once delivery is successful and the malware reaches the target environment, the attack advances to the exploitation phase.

What you'll learn

What's covered

Malware Delivery Phase

Key terms

Malware
Software specifically designed to disrupt, damage, or gain unauthorized access to a system.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Threat Actor
An individual or group responsible for a security incident or attack.
Supply Chain Attack
An attack that targets the less-secure elements of a product or service's supply chain to compromise the final target.
Removable Media
Portable storage devices such as USB flash drives, SD cards, and optical discs that can be detached from a computer and used to transport, distribute, or back up data.

Topics

Cyber Kill Chain Malware Delivery Social Engineering Email Security Supply Chain Attacks Cybersecurity

Transcript

As soon as we've weaponized ourselves, usually by creating or purchasing or somehow attaining malware, we need to deliver that malware into the network.

The weaponization phase is getting the tools and resources necessary to carry out an attack. The next step is possibly to deliver that weaponization. So if we've created malware in the weaponization phase, now what we have to do is deliver that. Somebody has to do the install of the malware. But what does that look like?

Who does the install

One is we could do that. If we were the adversaries and we were targeting a business, somehow we could do the install. There are some obvious issues with this though. How do we get into the building? How do we get access to equipment? We might not have that, and it might be very difficult.

But who does have access to it? Employees of the company, different members of this organization. So then we could have some sort of victim within the organization do the install. We could also have some sort of third parties do the install.

Tricking the victim or third party

When it comes to the victim or third party, there's a good chance they're not going to want to purposely do something malicious like this. So we're probably going to have to trick them with something like social engineering. Maybe we send it through an attachment. We can send that attachment through instant messaging, email, social engineering, or text. Maybe we get them to download it from online. Maybe we use some sort of removable media for it. Maybe we use some sort of websites or apps.

We could do the same thing if there's some sort of third party, maybe somewhere in the supply chain, or a partner that they have. Maybe it's customers they have. Maybe it's a service provider or vendor that they have.

Somehow we've got to get this malware into that network that we want to compromise. This is where that attack surface comes in, where we're going to analyze those attack surfaces and look for vectors to get inside of this network. That is going to be the way we're going to deliver this malware.

Why social engineering works

One of the best ways to do this is through social engineering. From a technical perspective, people know how to lock down firewalls usually. From a patching perspective, people are patching machines and are usually pretty good about doing that, at least the IT department is, not always the end user. And people lock down things like wireless because they know it's insecure. But humans tend to be the weakest link of a network. The business has to allow humans onto this network, and humans are fallible. We make mistakes, and there are times when we can be leveraged by other people and manipulated by other people.

Once we do get that delivered into the network, we can move on to the next phase of exploitation.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →