In the cybersecurity space, we often find ourselves in a constant game of cat and mouse with threat actors. As someone on the human risk management side, I’ve seen how attackers are becoming increasingly sophisticated in their methods, particularly when it comes to exploiting the human element of security. Today, I want to shed light on a concerning trend in the cybersecurity landscape: the rise of two-step phishing (2SP) attacks, with a particular focus on a new tactic involving Microsoft Visio files, and… holding down the Ctrl key.
The Layered Approach: A Double-Edged Sword
Just as we in the cybersecurity industry advocate for layered defensive strategies, cybercriminals are adopting similar multi-layered approaches in their attacks. This mirrors what we often emphasize in human risk management – the need for comprehensive, multi-faceted approaches to security. Two-step phishing attacks have become a cornerstone of modern cybercrime, leveraging trusted platforms to deliver malicious content in layers, effectively evading detection.
Recent research from Perception Point has unveiled a new attack methodology employing 2SP tactics, but with a twist – the use of Microsoft Visio files as a new evasion tactic. This development is particularly concerning because it exploits the familiarity and trust associated with commonly used workplace tools.

Anatomy of the New Two-Step Phishing Attacks
These sophisticated attacks begin with threat actors leveraging breached email accounts to send messages that easily pass basic authentication checks. The initial email typically contains a lure – often a business proposal or purchase order – accompanied by an urgent request for action. This tactic plays on the human tendency to respond quickly to perceived urgent matters, a behavior we often address in our security awareness training programs.
When the unsuspecting victim clicks the provided URL, they’re led to what appears to be a legitimate Microsoft SharePoint page. This page hosts a .vsdx Visio file, which contains another embedded URL behind a clickable call-to-action, usually a “view document” button.
Here’s where the attack takes a troubling twist. Victims are instructed to hold down the Ctrl key while clicking to access the embedded URL. This subtle yet highly effective action is designed to evade email security scanners and automated detection tools, as it requires human interaction that automated systems don’t typically anticipate.
How to defend against phishing attacks?
Visit our page to find out what are end-to-end phishing defense and what are its components.

The Human Factor: Our Greatest Vulnerability and Strongest Asset
This new attack methodology underscores a point we’ve long emphasized at Right-Hand Cybersecurity: the critical importance of the human element in cybersecurity. While technology plays a crucial role in defending against threats, it’s the human users who often represent both the first line of defense and the most exploitable vulnerability.
The instruction to hold down the Ctrl key is a perfect example of how attackers are finding new ways to bypass technological defenses by manipulating human behavior. It’s a stark reminder that no matter how advanced our security systems become, the human factor remains a critical component of any comprehensive security strategy.
Evolving Threats: Beyond Two-Step Phishing
It’s crucial to recognize that two-step phishing attacks are just one part of a broader landscape of evolving cyber threats. We’re seeing an increase in the use of Scalable Vector Graphics (SVG) attachments in phishing emails, allowing attackers to display malicious forms or deploy malware while evading detection by security software.
Moreover, the advancement of AI technology has empowered cybercriminals with new tools to create more convincing and personalized attacks. From AI-generated phishing emails to deepfake voice impersonation in CEO fraud schemes, the threat landscape is becoming increasingly complex and sophisticated.

Mitigating Risks: A Human-Centric Approach
In light of these evolving threats, it’s clear that a human-centric approach to cybersecurity is more crucial than ever. This doesn’t mean abandoning technological solutions – far from it. Instead, it means recognizing that our human users are both a potential vulnerability and our most adaptable line of defense.
Here are some key strategies to mitigate the risks of these sophisticated attacks:
- Continuous, Adaptive Training: Implement security awareness training that adapts to the latest threats and individual user behavior. This ensures that employees are always prepared for the most current attack methodologies.
- Foster a Culture of Security: Encourage open communication about security issues and celebrate employees who successfully identify and report potential threats. This creates an environment where security is everyone’s responsibility.
- Implement Robust Authentication: While not foolproof, strong multi-factor authentication can provide an additional layer of defense against credential theft.
- Empower Employees to Report: Provide easy-to-use tools for employees to report suspicious emails or activities. Quick reporting can be crucial in mitigating the impact of an attack.
- Regular Phishing Simulations: Conduct regular, realistic phishing simulations that mirror the latest attack techniques. This helps employees recognize and respond appropriately to real threats.
- Data-Driven Risk Assessment: Utilize analytics to understand your organization’s risk profile and tailor your security strategies accordingly.
The Road Ahead: Vigilance and Adaptation
It’s clear that our approach must be as dynamic and adaptable as the cybersecurity threats we face. The emergence of sophisticated two-step phishing attacks, along with other evolving threats, serves as a reminder of the need for continuous vigilance and adaptation in our cybersecurity strategies.
Remember, in the face of these new attacks, sometimes even the simplest advice can be the most powerful: “Don’t hold down the Ctrl key when prompted by an unexpected source”. It’s these small, mindful actions that can make the difference between a prevented attack and a breach.
In my opinion, our greatest asset remains our ability to learn, adapt, and work together. At Right-Hand Cybersecurity, we focus on empowering our users with knowledge, skills, and the right tools to build a more resilient defense against even the most sophisticated cyber threats.



