The Art of Phishing: Exploiting the Inherent Trust in Conversation
Picture this: an employee receives a meeting invite from a prospective client. It is expected; they’ve been emailing back and forth with this contact for weeks now. Today was set as the date for the meeting. The other party has sent an invite from their system because the one previously sent from the employee is not allowing them to join. The employee clicks the Teams link expecting it to open the meeting.
Instead, Edge opens, and the computer initiates a download for something that looks familiar, but not Teams familiar. It asks to join the session or enable screen sharing in a way that feels slightly uncomfortable. Maybe it asks to run something. Maybe it opens a page that doesn’t quite look right. But, by that point, the employee is already halfway through the process, and this is from someone they “know.”
It still feels like the computer is just trying to join a meeting, and not just a meeting – the meeting. The one this employee has been building a relationship through email with the potential lead in order to land. They know this person and have “talked” to them for a while now, so it must just be a different system than they’re used to. That’s the attack.
Building Trust for Phishing
This is a phishing technique that’s been seen more frequently. Fake meeting invitations designed to get users to install remote access or screen-sharing software under the assumption they’re joining a legitimate call. What makes it effective isn’t its sophistication. It doesn’t contain malware or zero-day exploits. It’s something much simpler. It exploits trust.
In a world where compliance policies and conditional access have made it increasingly difficult for threat actors to steal credentials and log into systems from their own side, they are finding ways to gain access from the employee’s side. It’s logical; it is the easiest means of ingress in today’s security landscape. And it works.
It works because joining meetings is something employees do every day. IT and cybersecurity teams teach people to look for anomalies, unexpected files, unsolicited credential requests, and uncharacteristic behaviors. But, joining a meeting invite from someone an employee has already been planning a meeting with is real, expected, and tangible.
Once they realize it is an attack, it feels very personal because of the very reason it worked – they’ve broken the trust that was built over time.
What to Look for and How to Prevent an Attack
If the prompts in one of these fake meeting links are followed, the consequences can escalate quickly.
Granting screen sharing access or installing a remote access tool can give an attacker visibility into an organization’s system and potentially much more. It can turn into credential theft, data exposure, or broader access into the environment. All from what looked like a routine meeting.
So, how can companies combat this? The most effective way is staying informed and by simply being aware of the possibility. Even though these attacks are subtle, there are still signs worth paying attention to, like an unexpected change or out-of-context meeting invite, a link that requires one to download something to join, or behavior that doesn’t match the normal meeting experience.
These attacks also often include the time-honored phishing tactic of urgency. Attackers might say the meeting is in a tight window and the inability to join the employee’s invite is wasting that valuable time; there is a natural feeling of panic when a prospective client can’t join a meeting.
These attacks rely on speed: quick clicks, minimal thought, familiar patterns, and repetitive processes. Breaking that pattern, even briefly, is often enough to stop the attack entirely.
One simple habit to consider is joining client-provided meeting invites from a mobile device instead of one’s primary workstation. Nearly all of these tactics target Windows-based systems, and on an iPhone or Android, it will simply fizzle and hopefully end the trance of the implied trust.
Final Thoughts
Phishing continues to evolve, but the underlying principle remains the same: attackers succeed when they can position themselves inside trusted interactions. That’s what makes this trend worth paying attention to. It’s not just about fake links or malicious downloads; it’s about how easily trust can be leveraged when it’s embedded in something as routine as a conversation.
The goal isn’t to become suspicious of every message, but to be aware of the moments where trust is being assumed rather than verified.
For more information on Cybersecurity risks, response and more, be sure to visit our SOC & Technology Consulting, Cybersecurity, and Forensic Examination pages, and don’t hesitate to contact Partner Dave Hammarberg regarding our services.
About the Author
Dustin Kinn joined McKonly & Asbury in 2022 and is the firm’s Director of Information Technology.