The Cyber Security Review | Thursday, November 10, 2022
Social engineering is the common practice of exploiting a human element to initiate and/or execute a cyberattack.
FREMONT, CA:The very prevalent tactic of using a human component to launch and/or carry out a cyberattack is known as social engineering. Human frailty and ignorance make for such easy prey that, according to Verizon's 2022 Data Breach Investigations Report, 82 per cent of attacks involved some type of social engineering.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
In cybersecurity, social engineering refers to the use of deceit to trick people into disclosing private or confidential information that could be misused. The simplest example is the mass spamming of individual email accounts with phishing scams, such as an offer for a gift certificate from a reputable company. Consumers who accept an infected file attachment or follow a link to a malicious website and provide personal information risk being used for illegal purposes.
The technique can become significantly more complex for higher-value business clients or stay basic.
Types of Social Engineering Techniques and Methods
Social engineering is accomplished in a variety of ways:
Pretexting: It is a common technique used in social engineering that includes presenting a false identity or context to a target to persuade them to divulge sensitive information or engage in compromising behaviour.
Baiting: To trick the victim, obtain private information, or infect the organisation with malware, the adversary typically makes a fictitious promise of something.
Phishing: It is when an attacker sends out numerous emails to random recipients in the hopes that one of the links or attachments will be harmful, giving them access to confidential data.
Spear Phishing: This is when an attacker sends a personalised, highly targeted phishing message to a single victim while posing as a well-known or reliable sender.
Whale Phishing is spear phishing for a high-value target, such as an important financial staff member or senior executive. To offer a plausible pretext involving access to sensitive information or the beginning of a financial activity, the attacker is likely to have first obtained thorough information about the target and organisation.
Vishing: This, also known as smishing, is a phishing effort that uses a voice call or SMS text message rather than an email.
Business Email Compromise (BEC): A cybercriminal takes control of a company email account and pretends to be the owner to trick a business associate into sending cash or private information to the attacker's account.
Pharming: This is when malicious software is installed on a computer or server to fool or divert users to dangerous websites.
Tailgating: By closely pursuing an employee or other authorised entrant who has used a credential to pass through security, a malicious actor can physically enter a guarded facility belonging to an organisation. This practice is known as tailgating or piggybacking.
Dumpster Diving: It is exactly what it sounds like, another physical attack in which a criminal searches through trash at a target organisation in search of information they might use to launch an attack.
Cybercriminals frequently pose as representatives of a reputable company, such as the target's bank, energy provider, or IT department. They use these organisations' logos and email addresses that look authentic. Once they have trust, they will ask for sensitive data like logins or account numbers so they may access your networks and steal money.
A typical strategy involves creating a fictitious scenario and threatening a negative outcome, such as a permanently locked account, paying a fine, or receiving a visit from police authorities if no action is taken very soon. The common objective is to get the victim to click on a malicious URL link, which directs them to a bogus login page where they enter their login information for a legitimate service.
The BazarCall campaign is an additional variation. Initially, a phishing email is sent. However, the email instructs the consumer to call a phone number to cancel a subscription rather than tricking them into clicking on a harmful link or attachment. The possibility that they may soon be automatically charged adds urgency. Then, fake call centres drive consumers to a website where they can download a cancellation form that downloads the malware BazarCall.
To appear more legitimate when spear-phishing, the attacker may gather useful information from LinkedIn, Facebook, and other networks. For instance, if the target is abroad and is known to use an Amex card, a call or email claiming to be from American Express may ask for identification verification to allow transactions in the nation the user is visiting. When the victim provides account information, credit card numbers, pins, and security codes, the attacker uses the information to make several online purchases.
High-value targets are the focus of whaling, thus, advanced techniques are increasingly utilised. Attackers may assume the identity of someone involved in the merger or large government grant and create enough urgency to get money transferred to a criminal group's account. A finance employee can be led to believe that their boss or another authoritative figure is asking for action using deep fake technology.
LinkedIn requests from shady characters are becoming more common. Con artists dupe unaware job seekers into opening harmful PDFs, videos, QR codes, and voicemails. Push notification spamming occurs when a threat actor repeatedly asks a user for permission via an MFA app. Users can become anxious or irritated by the volume of notifications they receive and allow a threat actor to infiltrate the network.
More in News