From a purely white hat perspective, please. Are there any good guides about how to perform a phishing campaign against a target? What is the best way to learn about this?
I’m particularly interested in spearphishing and whaling. Both the technical aspects (bypassing spam filters, etc) and psychological (getting targets to click the links).
Well I would recommend to check out “Social Engineering, The Art of Human Hacking”, and well the bypassing spam and filter’s AV and other it’s a completely different category, you might want to research malware development or check out MITRE so you can get familiar on what AP[Ts use for achieving that goal. That would be the technical aspects. The psychological will take some practice you should be a people person for this. A great example I can give you is an APT used the situation of COVID-19 and the COVID-19 vaccines to have people click on there links, look at the news what is trending how can you get people’s attention?. Is it a celebrity? a situation? an event?. That’s where you will need to understand OSINT to gather as much information as needed from your target. Hope this has helped.