Phising/Self-exploit or a proper attack vector?

Here’s some backstory.

A report I have made has been marked as Informative because the attack vector I used was supposedly “Phising or Self-exploit”. The attack vector I used was this: •Send sms or message from messaging app containing a enticing message (either a insult or something similar that mentions being in a group on the affected app, or a message from the attacker pretending to be someone that would require the message to be passed on into the group) that is a payload in disguise. •The victim would either be mad and paste the message into the group (if insult, to try and figure out who said this) or they would believe the faking person and share the message into the group •The hidden payload activates and strings get leaked from the app and get sent into the group, where presumably, there’d be a compromised account or a person in on the plan that would copy it before it gets deleted

Does this count as Phising or Self-exploit?

submitted by /u/Educational-Age3766
[link] [comments]

Read More >>