and that untrusted source could look a lot like his superior's email (boss@c0mpany.com vs boss@company.com)
And depending on the resources of the hacker, the email could be stylised just for him, talking about something important that's (perhaps something bad) happening now and the notBoss is telling him to check this months info, and kindly providing him with a pdf that Mathew hastily opens with his latest version of Adobe Acrobat with a zero day vulnerability that hasn't been discovered yet.
Yeah agreed, combining social engineering with technical exploits and you can get really good results. I almost fell into one trap myself one day: Basically I was having an argument with a service provider, and somehow I received an email talking about the same type of issue (just high level, without the minute details) with a link attached. I had to check it many times to make sure that it was a fraud email...
And depending on the resources of the hacker, the email could be stylised just for him, talking about something important that's (perhaps something bad) happening now and the notBoss is telling him to check this months info, and kindly providing him with a pdf that Mathew hastily opens with his latest version of Adobe Acrobat with a zero day vulnerability that hasn't been discovered yet.
It could also be literally anything.