什么是网络钓鱼?识别与防范在线欺诈
Security

什么是网络钓鱼?识别与防范在线欺诈

网络钓鱼是一种社会工程学攻击,通过伪造邮件、假冒网站或短信欺骗用户提供敏感信息。了解如何识别钓鱼攻击、IDN同形字攻击,以及通过SPF/DKIM/DMARC进行防护。

系列文章: Bảo mật
  1. 1 什么是恶意软件?分类、特征及预防方法
  2. 2 什么是DDoS?识别迹象、应对方法与有效防御指南
  3. 3 什么是网络钓鱼?识别与防范在线欺诈
  4. 4 什么是DNS Sinkhole?DNS Sinkhole技术的应用与使用方法
  5. 5 什么是OAuth 2.0?授权访问与谷歌登录原理
  6. 6 什么是木马病毒?关于Trojan恶意软件的基本知识
  7. 7 Zero Trust 是什么?'永不信任,始终验证'安全模型
  8. 8 VPN是什么?虚拟专用网络与WireGuard、OpenVPN协议
  9. 9 MFA 是什么?多因素认证与 2FA 对比详解
  10. 10 什么是防火墙?在网络安全中的角色和功能
  11. 11 什么是SQL注入?数据库攻击与防护
  12. 12 什么是XSS?跨站脚本攻击与防护
✦ 快速摘要
网络钓鱼是一种社会工程学攻击,通过伪造邮件、假冒网站或短信欺骗用户提供敏感信息。了解如何识别钓鱼攻击、IDN同形字攻击,以及通过SPF/DKIM/DMARC进行防护。
这篇文章怎么样?

网络钓鱼是黑客最危险的武器之一——无需利用技术漏洞,只需欺骗人心。深入了解网络钓鱼的工作原理及其各种变体,是保护自身和组织免受日益复杂的网络攻击的第一步。

什么是网络钓鱼?通过网络和电子邮件实施的社会工程学

网络钓鱼是一种社会工程学攻击,攻击者伪装成可信组织或个人——银行、谷歌、亚马逊,甚至是您的同事——欺骗受害者执行有害操作:交出密码、信用卡号、一次性验证码,或安装恶意软件。

网络钓鱼的核心在于利用人类心理,而非技术漏洞。常被利用的情绪包括:

  • 恐惧: "如果您不立即验证,您的账户将在24小时内被锁定"
  • 贪婪: "您已赢得5000元奖励,点击此处领取"
  • 信任: "IT部门的HR要求您更新VPN密码"
  • 紧迫: "如果您不在2小时内确认,您的订单将被取消"

根据Verizon数据泄露调查报告(DBIR),约90%的数据泄露始于一封钓鱼邮件。这不是因为系统脆弱,而是因为人始终是安全链中最容易被攻破的环节。

网络钓鱼并非新现象——这一术语可追溯至20世纪90年代,当时黑客冒充AOL窃取账户凭据。但如今的攻击愈发精密、个性化,难以与合法通信区分。

网络钓鱼的类型

电子邮件钓鱼——大规模、无个性化

最经典、最常见的形式。攻击者发送数百万封伪装成银行、PayPal、亚马逊或热门服务的虚假邮件,内容通常包含指向伪造登录页面的链接,要求受害者输入凭据。

由于是大规模无个性化发送,普通钓鱼邮件往往较容易识别——用语笼统、存在拼写错误、发件人域名陌生。然而,低成功率被庞大规模所弥补:1000万封邮件中哪怕只有0.1%上当,攻击者就能获得1万名受害者。

鱼叉式钓鱼——个性化、定向攻击

鱼叉式钓鱼针对特定个人或组织。攻击者事先对目标进行深入研究——全名、职位、同事、当前项目——并利用这些信息制作极具说服力的邮件。

例如:"您好,小明,根据总经理李红的要求,请在今天下午5点前查阅附件中的Q4合同并批准。"

这封邮件使用了真实姓名,提及了真实上级,并制造了时间压力。鱼叉式钓鱼的成功率远高于普通钓鱼——部分研究显示可达30-40%。

鲸鱼攻击——针对CEO、CFO等高管

鲸鱼攻击是针对"大鱼"的鱼叉式钓鱼——CEO、CFO或其他高级管理人员。目标通常是实施商业邮件诈骗(BEC):说服CFO将资金转入攻击者控制的账户,或获取敏感财务信息。

FBI估计,2016年至2022年间,BEC在全球造成的损失超过260亿美元——超过了勒索软件。

短信钓鱼——SMS网络钓鱼

通过短信实施的钓鱼攻击。攻击者冒充银行、快递公司或政府机构。消息通常简短:"您的包裹正在等待确认:[链接]"或"您的账户已被锁定,立即验证:[链接]"。

短信钓鱼之所以有效,是因为用户阅读短信时往往比看邮件更为放松,而手机小屏幕也使URL更难检查。

语音钓鱼——电话钓鱼

攻击者直接打电话,冒充银行工作人员、技术支持或执法机构。他们施加心理压力,让受害者提供一次性验证码、账户凭据或授权转账。

随着AI语音克隆技术的发展,语音钓鱼愈发危险——攻击者只需从公开音频中获取数分钟录音,即可克隆CEO的声音,向财务员工打电话。

克隆钓鱼——复制合法邮件

攻击者克隆受害者此前收到的合法邮件(通讯简报、订单确认、真实服务通知),将链接或附件替换为恶意版本,然后以"更新版本"或"因技术错误重新发送"为由再次发送。

克隆钓鱼尤为危险,因为受害者已熟悉原始邮件的格式,更容易信任。

伪造登录页面的剖析

一个典型的伪造登录页面按以下流程运作:

第一步——URL不同,界面相同: 攻击者创建一个与真实网站完全相同的网页——标志、配色、布局、内容。但URL不同:accounts.g00gle.comlogin-google.comgoogle-accounts-security.com,或使用IDN同形字(见下节)。

第二步——受害者输入信息: 由于界面与真实网站完全一致,受害者毫无疑虑,正常输入用户名和密码。

第三步——凭据发送至攻击者服务器: 表单提交的信息不会登录真实账户,而是发送至攻击者的服务器并被存储。

第四步——跳转至真实网站: 收集信息后,伪造页面立即将受害者重定向至真实登录页面,显示"会话已过期,请重新登录"。受害者成功登录真实网站,对刚才发生的一切毫不知情。

整个过程仅需数秒——足够攻击者获取凭据,却太快让受害者察觉任何异常。

绕过检测的技术手段

IDN同形字攻击

国际化域名(IDN)允许域名使用Unicode字符,这带来了安全漏洞:许多Unicode字符在视觉上与拉丁字母完全相同,但实际上是不同的字符。

  • 字母а(西里尔 U+0430)看起来像a(拉丁 U+0061)
  • 字母е(西里尔 U+0435)看起来像e(拉丁 U+0065)
  • 字母ο(希腊 U+03BF)看起来像o(拉丁 U+006F)

结果:pаypal.com(西里尔'а')在屏幕上看起来与paypal.com(拉丁)完全相同,但实际上是完全不同的域名。现代浏览器通过显示Punycode形式来应对:将pаypal.com显示为xn--pypal-4ve.com,但并非总能及时显示。

URL缩短器

bit.ly/abc123tinyurl.com/xyz之类的链接完全隐藏了真实的目标域名。用户仅凭缩短后的URL无法知道链接的真实去向。攻击者利用URL缩短器绕过基于域名黑名单的邮件过滤器。

在伪造网站上使用HTTPS

许多用户认为"绿色HTTPS锁形图标代表安全"——这是一个普遍的误解。HTTPS仅加密连接,并不验证网站是否合法。攻击者可以通过Let's Encrypt为任何域名(包括paypa1.com)免费申请SSL证书,伪造网站同样会显示绿色锁形图标。

子域名技巧

paypal.com.attacker.com这样的域名会让匆忙浏览的用户看到"paypal.com"并产生信任。实际上,真正的域名是attacker.com——paypal.com只是其子域名。这一技巧在URL被截断显示的移动端尤为有效。

个人防护措施

检查发件人域名——不只是显示名称

邮件客户端显示的是发件人名称(显示名称),攻击者可以随意设置为"PayPal安全团队"或"谷歌账户团队"。真正重要的是<>内的实际电子邮件地址security@paypa1.com不是security@paypal.com

永远不要只信任显示名称——务必展开邮件头查看完整地址。

点击前悬停在链接上

在点击邮件中的链接前,将鼠标悬停在链接上,真实URL会显示在浏览器底部的状态栏中。如果URL与联系您的组织不匹配,请勿点击。

在移动端,长按链接可在打开前预览URL。

切勿通过邮件链接输入凭据

最安全的习惯:永远不要通过邮件中的链接登录账户。改为打开浏览器,直接输入网站地址(或使用已保存的书签)。如果账户确实存在问题,直接登录时自然会出现相应提示。

双因素认证——即使密码泄露也能保护账户

为所有重要账户启用双因素认证(2FA)。即使攻击者通过钓鱼窃取了密码,他们仍需要您的一次性验证码或硬件密钥才能登录。2FA不能阻止钓鱼攻击,但能在密码泄露时显著降低损失。

优先级:硬件密钥(YubiKey)> 身份验证器应用(TOTP)> 短信验证码(最容易受到SIM卡交换攻击)。

密码管理器——自动检测伪造域名

Bitwarden或1Password等密码管理器将凭据与特定域名绑定存储。当您访问paypa1.com(伪造)时,密码管理器不会自动填充凭据,因为该域名与其数据库中的paypal.com(真实)不匹配。

这是一种极为有效的自动防护层——即使用户未能识别伪造网站,密码管理器也不会自动填充,从而产生隐性警告。

组织级防护:SPF / DKIM / DMARC

为防止攻击者伪造您组织的域名(发送看似来自ceo@yourcompany.com的邮件),需要配置以下三条DNS记录:

# DNS TXT records for domain example.com

# SPF — only Google and Sendgrid mail servers are authorized to send
example.com. TXT "v=spf1 include:_spf.google.com include:sendgrid.net -all"

# DKIM — public key to verify email signatures
google._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIGfMA0G..."

# DMARC — reject if both SPF and DKIM fail; send reports to admin
_dmarc.example.com. TXT "v=DMARC1; p=reject; rua=mailto:dmarc@example.com; pct=100"

SPF(发件人策略框架): SPF记录列出了被授权代表您的域名发送邮件的邮件服务器。接收服务器在检查来自yourcompany.com的邮件时,会查询SPF记录,验证发件人IP是否在授权列表中。末尾的-all表示拒绝所有未列出的服务器。

DKIM(域名密钥识别邮件): DKIM为每封发出的邮件添加数字签名。您的邮件服务器使用私钥对邮件签名;接收服务器使用DNS中发布的公钥验证签名。此签名涵盖邮件内容,有助于检测传输过程中被伪造或篡改的邮件。

DMARC(基于域名的邮件身份验证、报告和一致性): DMARC规定SPF或DKIM验证失败时应用的策略:

  • p=none:仅监控,不拦截——适合部署初期
  • p=quarantine:移入垃圾邮件/垃圾箱
  • p=reject:完全拒绝邮件——生产环境的目标配置

DMARC还提供报告机制(rua):接收服务器将报告发送至您指定的电子邮件地址,让您监控谁在冒充您的域名发送邮件。

DMARC部署路线图:

  1. p=nonerua开始收集数据(2-4周)
  2. 分析报告,确保所有合法邮件服务器均已包含在SPF中并配置了DKIM
  3. 切换至p=quarantine,设置pct=10(10%的邮件)
  4. 逐步将pct提高至100%
  5. 最终切换至p=reject

什么是XSS?跨站脚本攻击

什么是勒索软件?加密型恶意软件与勒索

什么是双因素认证(2FA)?

Phishing is one of the most dangerous weapons in a hacker's arsenal — it requires no technical exploit, only human deception. Understanding how phishing works and its many variants is the first step toward protecting yourself and your organization against an ever-more-sophisticated wave of cyber attacks.

What is Phishing? Social Engineering via Web and Email

Phishing is a Social Engineering attack in which an adversary impersonates a trusted organization or individual — a bank, Google, Amazon, or even a colleague — to trick victims into taking a harmful action: handing over passwords, credit card numbers, OTP codes, or installing malware.

The core of phishing is exploiting human psychology, not technical vulnerabilities. Emotions commonly leveraged include:

  • Fear: "Your account will be locked in 24 hours if you don't verify immediately"
  • Greed: "You've won $2,000 — click here to claim your prize"
  • Trust: "IT from HR is requesting you update your VPN password"
  • Urgency: "Your order will be cancelled if you don't confirm within 2 hours"

According to the Verizon Data Breach Investigations Report (DBIR), approximately 90% of data breaches begin with a phishing email. Not because systems are weak — but because humans are always the most exploitable link in the security chain.

Phishing is not a new phenomenon — the term dates back to the 1990s when hackers impersonated AOL to steal account credentials. But today's attacks are increasingly sophisticated, personalized, and indistinguishable from legitimate communications.

Types of Phishing Attacks

Email Phishing — Mass, Non-Personalized

The classic and most common form. Attackers send millions of fake emails impersonating banks, PayPal, Amazon, or popular services. Messages typically include a link to a fake login page, urging victims to enter their credentials.

Because they are sent at mass scale without personalization, standard phishing emails are often easier to spot — generic language, spelling errors, unfamiliar sender domains. However, low success rates are offset by enormous volume: even 0.1% of 10 million emails yields 10,000 victims.

Spear Phishing — Personalized and Targeted

Spear phishing targets a specific individual or organization. Attackers research their target carefully beforehand — full name, title, colleagues, current projects — and use that information to craft extremely convincing emails.

Example: "Hi Alex, per the request of CEO Sarah, please review the attached Q4 contract and approve before 5 PM today."

This email includes a real name, references a real superior, and creates time pressure. Success rates for spear phishing are dramatically higher than mass phishing — some studies report 30–40%.

Whaling — Targeting CEOs, CFOs, and C-Suite

Whaling is spear phishing aimed at "big fish" — CEOs, CFOs, or other senior executives. The goal is often Business Email Compromise (BEC): convincing a CFO to wire funds to an attacker-controlled account, or extracting sensitive financial data.

The FBI estimates BEC caused over $26 billion in losses globally from 2016 to 2022 — more than ransomware.

Smishing — SMS Phishing

Phishing via SMS. Attackers impersonate banks, delivery services, or government agencies. Messages are typically brief: "Your package is awaiting confirmation: [link]" or "Your account has been locked, verify now: [link]".

Smishing is effective because users tend to be less vigilant when reading SMS than email, and small mobile screens make it harder to inspect URLs.

Vishing — Voice Call Phishing

Attackers call directly, impersonating bank staff, tech support, or even law enforcement. They apply psychological pressure to extract OTP codes, account credentials, or authorize fund transfers.

With the rise of AI voice cloning, vishing is increasingly dangerous — attackers can clone a CEO's voice from just a few minutes of publicly available audio to call a finance employee.

Clone Phishing — Duplicating Legitimate Emails

Attackers clone a legitimate email the victim has already received (newsletter, order confirmation, notification from a real service), replace links or attachments with malicious versions, and resend it as an "updated version" or "resent due to a technical error."

Clone phishing is particularly dangerous because victims are already familiar with the format of the original email and are more likely to trust it.

Anatomy of a Fake Login Page

A typical fake login page follows this sequence:

Step 1 — Different URL, identical interface: The attacker creates a website with a pixel-perfect copy of the real site — logo, colors, layout, content. But the URL is different: accounts.g00gle.com, login-google.com, google-accounts-security.com, or using IDN homographs (see next section).

Step 2 — Victim enters credentials: Because the interface looks identical to the real site, the victim has no reason for suspicion and enters their username and password as normal.

Step 3 — Credentials sent to the attacker's server: Instead of logging into the real account, the form submission sends the credentials to the attacker's server, where they are stored.

Step 4 — Redirect to the real site: Immediately after collecting the information, the fake page redirects the victim to the real login page with a message such as "Session expired, please log in again." The victim logs in successfully and has no idea they were just compromised.

This entire process takes seconds — enough time for the attacker to capture credentials, but far too fast for the victim to notice anything wrong.

Techniques to Bypass Detection

IDN Homograph Attack

Internationalized Domain Names (IDN) allow domain names to use Unicode characters. This creates a vulnerability: many Unicode characters look identical to Latin characters but are technically different.

  • The letter а (Cyrillic U+0430) looks like a (Latin U+0061)
  • The letter е (Cyrillic U+0435) looks like e (Latin U+0065)
  • The letter ο (Greek U+03BF) looks like o (Latin U+006F)

Result: pаypal.com (with Cyrillic 'а') looks identical to paypal.com (Latin) on screen, but is an entirely different domain. Modern browsers counter this by displaying the punycode form: xn--pypal-4ve.com instead of pаypal.com, though this is not always shown proactively.

URL Shorteners

Links like bit.ly/abc123 or tinyurl.com/xyz completely conceal the true destination domain. Users cannot know where a shortened link leads just by looking at it. Attackers use URL shorteners to bypass email filters that rely on domain blacklists.

HTTPS on Fake Sites

Many users believe "the green HTTPS padlock means it's safe" — this is a widespread misconception. HTTPS only encrypts the connection; it does not verify the website is legitimate. Attackers can obtain a free SSL certificate from Let's Encrypt for any domain, including paypa1.com. The fake site still displays a green padlock.

Subdomain Tricks

A domain like paypal.com.attacker.com leads users who skim quickly to see "paypal.com" and trust the link. In reality, the actual domain is attacker.compaypal.com is merely a subdomain. This technique is particularly effective on mobile where URLs are truncated.

Personal Defenses Against Phishing

Check the Sender Domain — Not Just the Display Name

Email clients display the sender's name (display name), which an attacker can set to anything: "PayPal Security" or "Google Account Team." What matters is the actual email address inside <>: security@paypa1.com is not security@paypal.com.

Never trust the display name alone — always expand the email header to see the full address.

Before clicking any link in an email, hover your mouse over it to see the real URL appear in the browser's status bar at the bottom. If the URL does not match the organization contacting you, do not click.

On mobile, press and hold a link to see a URL preview before opening it.

The safest habit: never log into an account via a link in an email. Instead, open your browser and type the website address directly (or use a saved bookmark). If there is a genuine issue with your account, it will appear when you log in directly.

2FA — Your Shield Even When Passwords Are Stolen

Enable two-factor authentication (2FA) on all important accounts. Even if an attacker steals your password via phishing, they still need your OTP code or hardware key to log in. 2FA does not prevent phishing but significantly reduces the damage when a password is compromised.

Priority: Hardware key (YubiKey) > Authenticator app (TOTP) > SMS OTP (most vulnerable to SIM swap).

Password Managers — Automatically Detecting Fake Domains

Password managers like Bitwarden or 1Password store credentials tied to a specific domain. When you visit paypa1.com (fake), the password manager will not autofill your credentials because the domain does not match paypal.com (real) in its database.

This is an extremely effective automatic defense layer — even if a user fails to recognize a fake site, the password manager will not autofill, creating an implicit warning.

Organizational Defenses: SPF / DKIM / DMARC

To prevent attackers from spoofing your organization's domain (sending emails appearing to come from ceo@yourcompany.com), configure these three DNS records:

# DNS TXT records for domain example.com

# SPF — only Google and Sendgrid mail servers are authorized to send
example.com. TXT "v=spf1 include:_spf.google.com include:sendgrid.net -all"

# DKIM — public key to verify email signatures
google._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIGfMA0G..."

# DMARC — reject if both SPF and DKIM fail; send reports to admin
_dmarc.example.com. TXT "v=DMARC1; p=reject; rua=mailto:dmarc@example.com; pct=100"

SPF (Sender Policy Framework): The SPF record lists the mail servers authorized to send email on behalf of your domain. When a receiving server checks an email from yourcompany.com, it looks up the SPF record and verifies whether the sender's IP is in the authorized list. The -all at the end means reject all servers not listed.

DKIM (DomainKeys Identified Mail): DKIM adds a digital signature to each outgoing email. Your mail server signs the email with a private key; the receiving server verifies the signature using the public key published in DNS. This signature covers the email content, enabling detection of spoofed or tampered emails in transit.

DMARC (Domain-based Message Authentication, Reporting, and Conformance): DMARC specifies the policy to apply when SPF or DKIM fails:

  • p=none: Monitor only, no blocking — use when starting to deploy
  • p=quarantine: Move to spam/junk folder
  • p=reject: Reject the email entirely — the target configuration for production

DMARC also provides a reporting mechanism (rua): receiving servers send reports to your designated email address, allowing you to monitor who is sending emails impersonating your domain.

DMARC Deployment Roadmap:

  1. Start with p=none and rua to collect data (2–4 weeks)
  2. Analyze reports; ensure all legitimate mail servers are covered by SPF and have DKIM configured
  3. Switch to p=quarantine with pct=10 (10% of emails)
  4. Gradually increase pct to 100%
  5. Finally switch to p=reject

What is XSS? Cross-Site Scripting

What is Ransomware? Encrypting Malware and Extortion

What is 2FA? Two-Factor Authentication