{"id":8332,"date":"2026-05-20T09:36:36","date_gmt":"2026-05-20T07:36:36","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=8332"},"modified":"2026-06-15T13:54:28","modified_gmt":"2026-06-15T11:54:28","slug":"metoda-literelor-kobold-in-atacurile-de-phishing","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/","title":{"rendered":"Ce este metoda \u201eKobold Letters\u201d \u00een atacurile de phishing?"},"content":{"rendered":"<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">Phishing attacks continue to evolve, making fraudulent messages increasingly difficult to identify. Some attacks no longer rely on obvious warning signs such as poor grammar, suspicious formatting, or generic content.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Kobold Letters method is an example of a more sophisticated phishing technique. It uses subtle manipulation, realistic communication, and psychological triggers to convince recipients to reveal sensitive information or take actions that compromise their security.<\/p>\n\n\n\n<\/div>\n\n<div id=\"mybox-2390751441\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Acces timpuriu<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Mai ave\u021bi nevoie de ajutor?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contacta\u021bi echipa noastr\u0103 de servicii pentru clien\u021bi.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Trimite mesaj<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">Understanding how this method works can help reduce the risk of falling victim to increasingly convincing phishing campaigns.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#What_is_the_Kobold_Letters_method\" >What is the Kobold Letters method?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#How_Kobold_Letters_work\" >How Kobold Letters work<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#Realistic_presentation\" >Realistic presentation<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#Psychological_pressure\" >Psychological pressure<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#Personalization\" >Personalization<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#Emotional_manipulation\" >Emotional manipulation<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#Warning_signs_to_look_for\" >Warning signs to look for<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#How_to_protect_yourself_against_Kobold_Letters\" >How to protect yourself against Kobold Letters<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#Verify_the_sender\" >Verify the sender<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#Check_links_before_clicking\" >Check links before clicking<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#Avoid_opening_unexpected_attachments\" >Avoid opening unexpected attachments<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#Enable_multi-factor_authentication\" >Enable multi-factor authentication<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#Keep_software_updated\" >Keep software updated<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#Train_employees_regularly\" >Train employees regularly<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/the-kobold-letters-method-in-phishing-attacks\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_is_the_Kobold_Letters_method\"><\/span>What is the Kobold Letters method?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The term &#8220;Kobold Letters&#8221; refers to phishing messages designed to blend into everyday communication.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The name comes from the German word <em>kobold<\/em>, which describes a small, elusive household spirit. In cybersecurity, it refers to messages that are deliberately subtle and difficult to detect.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unlike traditional phishing emails, Kobold Letters avoid obvious mistakes. Instead, they focus on creating believable scenarios that encourage recipients to act quickly without questioning the message.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These attacks often imitate legitimate communication from:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>banks and financial institutions<\/li>\n\n\n\n<li>online stores<\/li>\n\n\n\n<li>delivery companies<\/li>\n\n\n\n<li>internet service providers<\/li>\n\n\n\n<li>colleagues or business partners<\/li>\n\n\n\n<li>friends or family members<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The goal is usually to obtain sensitive information, such as login credentials, payment details, or access to internal systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are not familiar with the broader phishing landscape, read:<br><a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/what-is-phishing-and-how-does-it-work\/\">https:\/\/mybox.com\/help\/knowledgebase\/what-is-phishing-and-how-does-it-work\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_Kobold_Letters_work\"><\/span>How Kobold Letters work<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Kobold Letters combine social engineering techniques with carefully crafted content.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers typically rely on several elements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Realistic_presentation\"><\/span>Realistic presentation<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Messages are designed to resemble legitimate communication as closely as possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They often include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>company logos<\/li>\n\n\n\n<li>professional formatting<\/li>\n\n\n\n<li>copied email signatures<\/li>\n\n\n\n<li>accurate terminology<\/li>\n\n\n\n<li>familiar writing styles<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Some attacks also use domain names that closely resemble legitimate websites.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Psychological_pressure\"><\/span>Psychological pressure<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Many messages create a sense of urgency to encourage quick decisions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Common examples include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>warnings about account suspension<\/li>\n\n\n\n<li>notifications about failed payments<\/li>\n\n\n\n<li>requests to verify login details<\/li>\n\n\n\n<li>urgent security alerts<\/li>\n\n\n\n<li>unexpected refund offers<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Creating time pressure reduces the likelihood that recipients will verify the request.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Personalization\"><\/span>Personalization<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers may use publicly available information to make messages appear more authentic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, emails may include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the recipient&#8217;s name<\/li>\n\n\n\n<li>company details<\/li>\n\n\n\n<li>previous data breach information<\/li>\n\n\n\n<li>recent purchases or subscriptions<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Personalized messages often appear more trustworthy than generic phishing attempts.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Emotional_manipulation\"><\/span>Emotional manipulation<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Kobold Letters frequently exploit emotions such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>fear<\/li>\n\n\n\n<li>curiosity<\/li>\n\n\n\n<li>trust<\/li>\n\n\n\n<li>excitement<\/li>\n\n\n\n<li>empathy<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A message that triggers an emotional response can make users more likely to overlook warning signs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Warning_signs_to_look_for\"><\/span>Warning signs to look for<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Although these attacks are designed to appear legitimate, there are often small inconsistencies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pay attention to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>unexpected requests for sensitive information<\/li>\n\n\n\n<li>unusual urgency<\/li>\n\n\n\n<li>changes to normal communication patterns<\/li>\n\n\n\n<li>sender addresses that do not exactly match official domains<\/li>\n\n\n\n<li>links that redirect to unfamiliar websites<\/li>\n\n\n\n<li>attachments you were not expecting<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If a message requests credentials, payment information, or file downloads, verify the request through an official communication channel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Learning how to inspect message headers can help identify spoofed emails and suspicious senders. See:<br><a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/cum-fac-o-analiza-de-baza-a-sursei-unui-e-mail-din-punctul-de-vedere-al-expeditorului\/\">https:\/\/mybox.com\/help\/knowledgebase\/how-do-i-do-a-basic-analysis-of-the-source-of-an-email-from-the-senders-point-of-view\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_protect_yourself_against_Kobold_Letters\"><\/span>How to protect yourself against Kobold Letters<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No single security measure can prevent all phishing attacks. Effective protection relies on a combination of awareness, verification, and technical safeguards.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Verify_the_sender\"><\/span>Verify the sender<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If a message requests urgent action, contact the organization directly using official contact information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do not use phone numbers, links, or email addresses provided in the suspicious message.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Check_links_before_clicking\"><\/span>Check links before clicking<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Hover over links to inspect the destination URL before opening them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Small differences in spelling or domain names can indicate a phishing attempt.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Avoid_opening_unexpected_attachments\"><\/span>Avoid opening unexpected attachments<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Attachments may contain malicious files or links designed to compromise your device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you were not expecting a file, confirm its legitimacy before opening it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Enable_multi-factor_authentication\"><\/span>Enable multi-factor authentication<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Multi-factor authentication adds an extra layer of protection if your password is compromised.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even if an attacker obtains your login credentials, they may still be unable to access your account.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Keep_software_updated\"><\/span>Keep software updated<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Regular updates help protect devices against known vulnerabilities that attackers may attempt to exploit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This includes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>operating systems<\/li>\n\n\n\n<li>web browsers<\/li>\n\n\n\n<li>email clients<\/li>\n\n\n\n<li>antivirus software<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Train_employees_regularly\"><\/span>Train employees regularly<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For businesses, user awareness is an essential part of cybersecurity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regular phishing simulations and security training help employees recognize suspicious behavior before it leads to an incident.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you manage a website or online business, understanding data protection requirements is also important:<br><a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/how-to-make-your-website-gdpr-compliant\/\">https:\/\/mybox.com\/help\/knowledgebase\/how-to-make-your-website-gdpr-compliant\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Website owners should also review their CMS security settings regularly. For WordPress websites, enabling diagnostic tools can make incident analysis easier:<br><a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/cum-se-activeaza-modul-de-depanare-in-wordpress\/\">https:\/\/mybox.com\/help\/knowledgebase\/how-to-enable-wordpress-debug-mode\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Kobold Letters method relies on subtle manipulation rather than obvious deception. These attacks use realistic communication, emotional triggers, and carefully crafted messages to gain trust and encourage quick action.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The most effective defense is a combination of caution, verification, and ongoing security awareness.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a message creates urgency or requests sensitive information, pause before responding and verify its authenticity through a trusted channel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[10],"manual_kb_tag":[810,1296,7770,7771,7772,7773,7774,7775,7776,739],"class_list":["post-8332","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-safety","manual_kb_tag-phishing-attacks","manual_kb_tag-phishing-emails","manual_kb_tag-kobold-letters","manual_kb_tag-kobold-letters-method","manual_kb_tag-sophisticated-phishing","manual_kb_tag-realistic-phishing","manual_kb_tag-emotional-manipulation","manual_kb_tag-urgency-manipulation","manual_kb_tag-personalized-phishing","manual_kb_tag-social-engineering"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/8332","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":2,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/8332\/revisions"}],"predecessor-version":[{"id":8333,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/8332\/revisions\/8333"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/media?parent=8332"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manualknowledgebasecat?post=8332"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb_tag?post=8332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}