Malware
Clone phishing
Clone phishing is resending a real, previously delivered email with the link or attachment swapped for a malicious one. Because the message matches something the recipient already trusted, it passes a casual glance.
How it is measured
You detect it by comparing the new message with the original: same subject, same body, same signature, but the link host or attachment hash differs. Mail headers show a different sending server or a mismatched Return-Path, and SPF, DKIM, or DMARC results may fail.
Hover over every link. A real invoice from `billing.acme.example` should not point to `acme-billing.review`. Count how many messages arrive that reuse a thread you already closed.
Worked example
A bookkeeper receives a PDF invoice from a supplier on Monday and pays it. On Thursday a second message arrives with the same subject plus "Updated invoice", same body, same logo. The attached link goes to `files-share.supplier-docs.top`, not the supplier's domain.
The bookkeeper phones the supplier on a known number. They sent nothing. The mail server logs show the Thursday message came from a hacked mailbox at a third company.
How it differs
Clone phishing copies a known message. Phishing in general invents a message and hopes someone trusts it. Spear phishing targets a named person with researched details. Clone phishing needs a victim who already got the original, so it often follows a breach of the sender's mailbox or a leaked thread.
Common errors
Trusting a message because it quotes a real earlier one. Checking only the display name. Opening an attachment because the filename matches. Ignoring a DMARC failure banner. Replying to confirm instead of calling a number you already have.
In practice
Make a rule that payment details and links in follow-up messages get confirmed on a second channel. Turn on DMARC reporting for your own domain so you see spoofed copies of your mail. Teach staff to check the real link target, not the link text.