Phishing, spam, and malvertising are delivery methods used to trick users into opening malicious content or visiting harmful sites. In remote work settings, they often exploit current events or urgency to pressure users into clicking links, opening infected documents, or trusting fraudulent domains.
What Phishing, Spam and Malvertising Are Used For
These delivery methods are designed to create a low-friction path from a user’s inbox, browser, or ad experience to a malicious payload, a fake login page, or a harmful destination. Their value to attackers is reach, plausibility, and timing, not technical sophistication.
Phishing usually relies on impersonation and urgency, spam on volume and repetition, and malvertising on trusted ad networks or compromised ad placements to push users toward compromise. In practice, the three often overlap in a single campaign.
How These Delivery Methods Work in Practice
The common pattern is social engineering plus a technical handoff. A message or ad creates enough trust, curiosity, or fear to make the user click, open, or sign in, and the next stage delivers credential theft, malware, or a session capture page.
Remote work increases exposure because users depend on email, chat, web apps, and quick self-service validation. Attackers often exploit current events, internal business language, or brand familiarity to make a malicious link look routine.
Phishing and spam are also used as staging mechanisms for broader intrusion, including malware delivery, account takeover, and fraud. Malvertising adds another path by turning ordinary browsing into an infection or redirection event without requiring the user to search for suspicious content.
Common Variants and Attack Paths
These techniques are not limited to generic fake emails. They can include credential-harvesting pages, QR-code lures, spoofed login screens, invoice or document bait, deceptive unsubscribe links, and ads that redirect through multiple layers before landing on a malicious site.
Attackers also chain them with secondary abuse such as token theft, malware downloads, or fake helpdesk flows. CoPhish OAuth phishing via Copilot Studio shows how a phishing-style flow can be adapted to steal consent and tokens rather than just passwords.
EmeraldWhale Git config credential theft illustrates a related pattern, where a lure or exposed content leads into credential harvesting and further cloud abuse. Mailchimp breach 2022 is another example of social engineering leading to downstream access and phishing enablement.
Why These Threats Persist
These methods persist because they exploit human attention, not just software flaws. They scale cheaply, adapt quickly to current events, and can bypass strong perimeter controls when users are the final trust decision point.
They also remain effective because attackers can continually test wording, infrastructure, and timing until a small fraction of recipients respond. Even when the initial lure fails, repeated exposure can create confusion, fatigue, or normalization of malicious prompts.
For defenders, the challenge is that the technique is not one thing. A message may be spam, phishing, and malware delivery at different stages, so detection and user training need to account for the whole chain rather than only one label.
Risk and Threat Considerations
These delivery methods create direct risk of credential theft, malware execution, fraud, and unauthorized access, especially when users are rushed or working through familiar channels. They also increase the chance that a single mistaken click becomes the start of an account compromise or endpoint infection.
Failure mechanism: The attacker uses trust cues, urgency, or ad placement to get a user to follow a malicious path, then captures credentials, installs malware, or redirects the user to a hostile site.
Impact: The result can be account takeover, data exposure, financial loss, lateral movement, or repeated internal phishing from a compromised mailbox or device.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP API Security Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | SI-3 — Malicious Code Protection | Phishing and malvertising often deliver malware or redirects. |
| IA-5 — Authenticator Management | Phishing commonly targets passwords, tokens, and other authenticators. | |
| AT-2 — Awareness Training | These threats depend on user interaction and recognition failures. | |
| Recommendation — Block and inspect lure-delivered content before it can execute or redirect users. Harden and rotate authenticators so stolen credentials have less value. Train users to spot urgency, spoofed domains, and credential-harvesting lures. | ||
| CIS Controls v8 | CIS-9 — Email and Web Browser Protections | Phishing, spam, and malvertising are delivered through email and web paths. |
| Recommendation — Filter malicious email and web traffic to reduce lure delivery and click-through. | ||
| MITRE ATT&CK | T1566 — Phishing | The term directly names a core ATT&CK initial-access technique family. |
| Recommendation — Map observed lure patterns to phishing techniques and tune detections accordingly. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | Phishing often aims to steal or misuse authentication material. |
| Recommendation — Strengthen authentication paths so stolen credentials and tokens are less useful. | ||
Practitioner Guidance
What to watch for: Users are most vulnerable when messages push immediate action, ask for reauthentication, or route to a domain that is close to a known service but not the real one. Training works best when it focuses on recognition of the lure pattern, not just on generic caution.
Governance implication: Treat phishing, spam, and malvertising as a shared user-exposure problem across email, browser, endpoint, and identity workflows. That means incident handling, reporting paths, and authentication controls should be designed so one successful lure does not become a full compromise.
Related resources from NHI Mgmt Group
- How should security teams defend against malvertising that leads to AiTM phishing?
- Why does malvertising create a different phishing problem than email-based attacks?
- What do security teams get wrong about malvertising-led phishing?
- Why do phishing reports matter if email filters already catch spam?