Join our Newsletter — 33% off our NHI Course
Home› Glossary› Threats, Abuse & Incident Response› Phishing, Spam And Malvertising
Threats, Abuse & Incident Response

Phishing, Spam And Malvertising

← Back to Glossary
By NHI Mgmt Group Updated September 30, 2026 Domain: Threats, Abuse & Incident Response

Phishing, spam, and malvertising are delivery methods used to trick users into opening malicious content or visiting harmful sites. In remote work settings, they often exploit current events or urgency to pressure users into clicking links, opening infected documents, or trusting fraudulent domains.

What Phishing, Spam and Malvertising Are Used For

These delivery methods are designed to create a low-friction path from a user’s inbox, browser, or ad experience to a malicious payload, a fake login page, or a harmful destination. Their value to attackers is reach, plausibility, and timing, not technical sophistication.

Phishing usually relies on impersonation and urgency, spam on volume and repetition, and malvertising on trusted ad networks or compromised ad placements to push users toward compromise. In practice, the three often overlap in a single campaign.

How These Delivery Methods Work in Practice

The common pattern is social engineering plus a technical handoff. A message or ad creates enough trust, curiosity, or fear to make the user click, open, or sign in, and the next stage delivers credential theft, malware, or a session capture page.

Remote work increases exposure because users depend on email, chat, web apps, and quick self-service validation. Attackers often exploit current events, internal business language, or brand familiarity to make a malicious link look routine.

Phishing and spam are also used as staging mechanisms for broader intrusion, including malware delivery, account takeover, and fraud. Malvertising adds another path by turning ordinary browsing into an infection or redirection event without requiring the user to search for suspicious content.

Common Variants and Attack Paths

These techniques are not limited to generic fake emails. They can include credential-harvesting pages, QR-code lures, spoofed login screens, invoice or document bait, deceptive unsubscribe links, and ads that redirect through multiple layers before landing on a malicious site.

Attackers also chain them with secondary abuse such as token theft, malware downloads, or fake helpdesk flows. CoPhish OAuth phishing via Copilot Studio shows how a phishing-style flow can be adapted to steal consent and tokens rather than just passwords.

EmeraldWhale Git config credential theft illustrates a related pattern, where a lure or exposed content leads into credential harvesting and further cloud abuse. Mailchimp breach 2022 is another example of social engineering leading to downstream access and phishing enablement.

Why These Threats Persist

These methods persist because they exploit human attention, not just software flaws. They scale cheaply, adapt quickly to current events, and can bypass strong perimeter controls when users are the final trust decision point.

They also remain effective because attackers can continually test wording, infrastructure, and timing until a small fraction of recipients respond. Even when the initial lure fails, repeated exposure can create confusion, fatigue, or normalization of malicious prompts.

For defenders, the challenge is that the technique is not one thing. A message may be spam, phishing, and malware delivery at different stages, so detection and user training need to account for the whole chain rather than only one label.

Risk and Threat Considerations

These delivery methods create direct risk of credential theft, malware execution, fraud, and unauthorized access, especially when users are rushed or working through familiar channels. They also increase the chance that a single mistaken click becomes the start of an account compromise or endpoint infection.

Failure mechanism: The attacker uses trust cues, urgency, or ad placement to get a user to follow a malicious path, then captures credentials, installs malware, or redirects the user to a hostile site.

Impact: The result can be account takeover, data exposure, financial loss, lateral movement, or repeated internal phishing from a compromised mailbox or device.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP API Security Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5SI-3 — Malicious Code ProtectionPhishing and malvertising often deliver malware or redirects.
IA-5 — Authenticator ManagementPhishing commonly targets passwords, tokens, and other authenticators.
AT-2 — Awareness TrainingThese threats depend on user interaction and recognition failures.
Recommendation — Block and inspect lure-delivered content before it can execute or redirect users. Harden and rotate authenticators so stolen credentials have less value. Train users to spot urgency, spoofed domains, and credential-harvesting lures.
CIS Controls v8CIS-9 — Email and Web Browser ProtectionsPhishing, spam, and malvertising are delivered through email and web paths.
Recommendation — Filter malicious email and web traffic to reduce lure delivery and click-through.
MITRE ATT&CKT1566 — PhishingThe term directly names a core ATT&CK initial-access technique family.
Recommendation — Map observed lure patterns to phishing techniques and tune detections accordingly.
OWASP API Security Top 10API2 — Broken AuthenticationPhishing often aims to steal or misuse authentication material.
Recommendation — Strengthen authentication paths so stolen credentials and tokens are less useful.

Practitioner Guidance

What to watch for: Users are most vulnerable when messages push immediate action, ask for reauthentication, or route to a domain that is close to a known service but not the real one. Training works best when it focuses on recognition of the lure pattern, not just on generic caution.

Governance implication: Treat phishing, spam, and malvertising as a shared user-exposure problem across email, browser, endpoint, and identity workflows. That means incident handling, reporting paths, and authentication controls should be designed so one successful lure does not become a full compromise.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org