---
title: 6 Ways to Launch a Targeted Cyberattack
description: 6 Ways to Launch a Targeted Cyberattack
---

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/head-logo-2.svg "TowerWall")](https://towerwall.com/)

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/towerwall-logo-white-test.svg "TowerWall")](https://towerwall.com/)

- [Our Partners](https://towerwall.com/how-we-protect-you/our-technology-partners/)
- Our Solutions 
    - - Our Cybersecurity Solutions 
                  - We operationalize infosec,  
                     building security solutions that  
                     safeguard your most critical assets.
          - - [Solutions Overview](https://towerwall.com/cybersecurity-solutions/)
                  - [Risk Assessments & Security Reviews](https://towerwall.com/cybersecurity-solutions/risk-assessments-security-reviews/)
                  - [Program & Policy Development](https://towerwall.com/cybersecurity-solutions/program-policy-development/)
                  - [Incident Response & Remediation](https://towerwall.com/cybersecurity-solutions/incident-response-remediation/)
                  - [Managed Detection & Response](https://towerwall.com/cybersecurity-solutions/managed-detection-response/)
          - - [Compliance & Privacy](https://towerwall.com/cybersecurity-solutions/compliance-privacy/)
                  - [Comprehensive Security Training](https://towerwall.com/cybersecurity-solutions/comprehensive-security-training/)
                  - [Vulnerability Protection](https://towerwall.com/cybersecurity-solutions/vulnerability-protection/)
                  - [Penetration Testing](https://towerwall.com/cybersecurity-solutions/penetration-testing/)
- Virtual Security Officers 
    - - Virtual Security Officer 
                  - Leverage the experience and  
                     security acumen of Towerwall’s  
                     on-demand security experts.
          - - [Virtual Chief Information Security Officer (VCISO)](https://towerwall.com/virtual-security-officers/virtual-chief-information-security-officer-vciso/)
                  - [Virtual Data Protection Officer (vDPO)](https://towerwall.com/virtual-security-officers/virtual-data-protection-officer-vdpo/)
                  - [Virtual Chief Privacy Officer (vCPO)](https://towerwall.com/virtual-security-officers/virtual-chief-privacy-officer-vcpo/)
- We Advise 
    - - We Advise 
                  - One-size security solutions only  
                     lead to failure.
          - Industries 
                  - [Higher Education](https://towerwall.com/industries/higher-education/)
                  - [Financial Services & Banking](https://towerwall.com/industries/financial-services-banking/)
                  - [Healthcare](https://towerwall.com/industries/healthcare/)
                  - [BioPharma & Bio-Therapeutics](https://towerwall.com/industries/biopharma-bio-therapeutics/)
                  - [Retail](https://towerwall.com/industries/retail/)
                  - [Government](https://towerwall.com/industries/government/)
                  - [Catholic Diocese](https://towerwall.com/industries/catholic-diocese-cybersecurity/)
                  - [Cannabis](https://towerwall.com/industries/cannabis/)
                  - [Small Business](https://towerwall.com/industries/small-business/)
                  - [Enterprise](https://towerwall.com/industries/enterprise/)
          - Trends & Threats 
                  - [Remote Workforce](https://towerwall.com/trends-threats/remote-workforce/)
                  - [Vendor Questionnaire](https://towerwall.com/trends-threats/vendor-questionnaire/)
                  - [HIPAA](https://towerwall.com/trends-threats/hipaa/)
                  - [Ransomware](https://towerwall.com/trends-threats/ransomware/)
                  - [GDPR](https://towerwall.com/trends-threats/gdpr/)
                  - [Cloud Security](https://towerwall.com/trends-threats/cloud-security/)
                  - [Phishing](https://towerwall.com/trends-threats/phishing/)
                  - [Cybersecurity Insurance](https://towerwall.com/trends-threats/cybersecurity-insurance/)
- [Resources](https://towerwall.com/resources/) 
    - - Resources 
                  - Our latest insights, events,  
                     and tools to keep you safe.
          - - [Insights](https://towerwall.com/resources/?resources_category=MTU%3D&focusarea=0&industries=0&search=)
                  - [Webinars](https://towerwall.com/resources/?resources_category=MTg%3D&focusarea=0&industries=0&search=)
                  - [Whitepapers](https://towerwall.com/resources/?resources_category=MTY%3D&focusarea=0&industries=0&search=)
                  - [View All](https://towerwall.com/resources/)
- [Company](https://towerwall.com/company/) 
    - - Our Company 
                  - We are the industry’s leading cybersecurity preparedness partner.
          - - [Who We Are](https://towerwall.com/company/)
                  - [Our Team](https://towerwall.com/company/our-team/)
                  - [Our Approach](https://towerwall.com/our-approach/)
                  - [Our Values](https://towerwall.com/company/our-values/)
          - - [Awards & Recognition](https://towerwall.com/company/awards-recognition/)
                  - [Certifications & Affiliations](https://towerwall.com/company/certifications-affiliations/)
                  - [Community Involvement](https://towerwall.com/company/community-involvement/)
                  - [Careers](https://towerwall.com/company/careers/)
                  - [Contact Us](https://towerwall.com/company/contact-us/)

Topics  Spear phishing emails, Targeted Cyberattack, Cyberattack, penetration testing, cannabis, Enterprise

# 6 Ways to Launch a Targeted Cyberattack

[By Michelle Drolet](https://blog.towerwall.com/author/towerwall2020)

[Read More](https://blog.towerwall.com/author/towerwall2020)

 2 Minute Read

February 14, 2017

### What you need to know to defend against targeted attacks.

The threat of a targeted attack for any business is real and substantial. It's vital to ensure that your organization can identify constantly evolving threats, find abnormal and suspicious activity, and take effective action to keep your data safe.  
 Consider that, on average, attackers are in a network for more than 140 days before they're detected, and 60% of network intrusions are eventually traced back to credentials, according to [according to Microsoft](https://www.microsoft.com/en-us/cloud-platform/advanced-threat-analytics).  
 Most successful targeted attacks follow six steps or stages, though it's important to remember that these steps often run in parallel. Multifaceted attacks are common, so a robust threat response plan should address all six steps and avoid jumping to conclusions.  
 It's not just about implementing the latest safeguards and software tools; awareness is paramount if you want to keep your data safe. After all, [cybersecurity is only as strong as your weakest link -- your employees](http://www.networkworld.com/article/3095486/security/cybersecurity-is-only-as-strong-as-your-weakest-linkyour-employees.html).

### Gathering intelligence

Every attack begins with a reconnaissance mission where attackers gather data about their target, but this step continues throughout the life cycle of a targeted attack. The more data attackers can find about how your network operates or where the weak spots are, the more likely it is that they'll pull off a successful attack. A lot of that data can only be accessed within company networks, so intelligence gathering continues well beyond the initial penetration.

### Finding or creating entry points

Spear phishing emails are still disturbingly effective. Amazingly, 30% of them still get opened, [according to Verizon research](http://www.verizonenterprise.com/verizon-insights-lab/dbir/2016/). A range of different employees may be targeted to help attackers create a complete picture of the network.  
 Watering hole attacks, where a frequently visited website for the target organization is compromised to gain entry to the target network, are also growing in popularity. Once in, attackers add backdoors to systems wherever they can, creating more and more possible entry points in case older routes are discovered and closed off.

### Command and control

For a targeted attack to be effective, the attackers need to be able to take control of compromised computers and other devices and make them speak to each other. This communication creates a certain amount of noise.

Attackers go to great lengths to hide C&C traffic, often creating internal servers that can be exploited through backdoors and then used to compromise and control other machines on the target network.

### Lateral movement

Too many security systems focus on building a wall designed to keep attackers out. It may be difficult to gain access to a specific system, but once inside one system, it is often a much simpler prospect for attackers to spread laterally and gain access to more.  
 Sometimes they can even use legitimate system administration tools to hide their activity, grant more privileges to compromised accounts and devices, and gather more intelligence on how to perpetuate and spread the attack.

### Maintaining the attack

Targeted attacks are not about smashing and grabbing. They are often sustained infiltrations designed to remain in place undetected for months or even years.  
 As long as there is valuable data to be exfiltrated, it's in the interests of the attacker to keep the attack operational. That means spreading control, identifying and creating new points of entry, and possibly even patching vulnerabilities to ensure that other attackers can no longer gain entry the same way they did.

### Exfiltrating data

At the end of the day it's all about data exfiltration. This is usually the entire point of the attack, but it's also one of the riskiest steps. Extracting data is virtually impossible to do without creating noticeable network traffic that could expose the attack. Stolen data may be hidden elsewhere in the target network for later extraction, as attackers build a big enough stash to make the risk of discovery worthwhile, or they find a way to hide the network traffic.  
 It's sensible and worthwhile to build secure defenses from the wider internet, but organizations must also scrutinize internal traffic and systems. It is only by continually [monitoring, analyzing and testing your security](http://www.networkworld.com/article/3124152/security/always-be-prepared-monitor-analyze-and-test-your-security.html) that you have any chance of uncovering and foiling targeted attacks. Understanding how attackers think can help you plan a solid defense and create a response plan that will work.

#### 6 Ways to Launch a Targeted Cyberattack

Back to Top

## Related Insights

### [Don't Bite That Phishing Bait: Bet On These Five Simple Safety Rules](https://blog.towerwall.com/dont-bite-that-phishing-bait-bet-on-these-five-simple-safety-rules)

 Spear phishing emails, Targeted Cyberattack, Cyberattack, penetration testing, cannabis, Enterprise

### [Battling Ransomware: How To Prevent A Ransomware Incident](https://blog.towerwall.com/battling-ransomware-how-to-prevent-a-ransomware-incident)

 Spear phishing emails, Targeted Cyberattack, Cyberattack, penetration testing, cannabis, Enterprise

[View All Insights](https://blog.towerwall.com)

×

## Talk with us now about:

#### Your security needs.

- ![Phone](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/phone-icon.svg "Phone")
  
  [Call 774.204.0700](tel:774.204.0700)
- ![Mail](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/mail-icon.svg "Mail")
  
  [Email Us](mailto:info@towerwall.com)

### The front line of cybersecurity.™

For over 23 years, Towerwall, a woman-owned business, has helped scores of companies safeguard their data and leverage their investment in IT with advanced information security technology solutions and services. Our experience in all facets of information security coupled with serving in the CIO/CISO/ISO roles provides a unique first-hand understanding of the security challenges organizations face daily.

### Connect

- <https://blog.towerwall.com/info@towerwall.com>
- <https://www.linkedin.com/company/towerwall-inc.?trk=pro_other_cmpy>
- <https://twitter.com/Towerwall>
- <https://www.facebook.com/Towerwall>

- [Career Opportunities](https://towerwall.com/company/careers/)
- [Contact Us](https://towerwall.com/company/contact-us/)

© Towerwall, Inc. and its licensees. All rights reserved [Privacy Policy](http://towerwall.com/privacy-policy/) Sitemap [Created by Howbridge](https://meethowbridge.com/)

[![Towerwall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/footer-logo.svg "Towerwall")](https://towerwall.com/)