Social Engineering: Attacks Used by Hackers

Martin W Luis

Underground
ULTIMATE
PREMIUM
MEMBER
BFD Legacy
Joined
Jan 27, 2025
Messages
625
Reaction score
1,637
Deposit
175$
1738083222129.png
Have you heard of such types of information attacks as Baiting, Honey Trap, Scareware, Water Holing, Quid pro Quo? In this article, we will consider them and a number of others, including various types of phishing, and also give high-profile examples of attacks.

All these actions are taken by hackers with one goal - to get hold of users' personal data.

And first, about what unites all these types of attacks...
All these actions are taken by hackers with one goal - to get hold of users' personal data.

What is social engineering and how does it work?

Social engineering is a method of manipulating people in order to obtain confidential information from them. The information that hackers are looking for can be different, but most often these are bank details, as well as account passwords. In addition, cybercriminals may try to gain access to the victim's computer in order to install malware there, which helps to extract any information. And here hackers use a diverse arsenal of social engineering, because it is much easier to get what you want from a person (personal data) by winning their trust. This is a much more convenient way than directly hacking someone's account: it is much easier to exploit user weaknesses than to try to find a vulnerability in a service or software.

Often, attacks using social engineering tools occur in two stages. First, hackers examine the intended victim to collect the necessary background information. It is at this stage that the hacker tries to win the victim's trust. And after successful attempts to establish "good" relations, the cybercriminal, using various tricks, extracts confidential information from the victim (for example, passwords and IP addresses).

We will now talk about different types of such tricks.

Types of attacks using social engineering
There are more than ten known types of such attacks, and if you take into account the combined methods, some of which we will also consider, then their number already amounts to several dozen.

Phishing
These attacks actively exploit the human factor to collect credentials or to distribute malware. Phishing can be said to be the fraudulent use of electronic communications to deceive and benefit from users. Most often, hackers use phishing attacks to obtain confidential information such as logins and passwords, credit card details, and network credentials.

A phishing attack can also be planned in such a way that after going to a fake site, the victim will have other problems: for example, malicious spyware will be installed on the computer or the system will freeze due to a ransomware attack. In some cases, hackers are content with obtaining the victim's credit card information or other personal data for financial gain. But it happens that phishing emails are sent to obtain employee registration information or other data for further extended attacks on a specific company.

There are several types of phishing cyber attacks. These include targeted, voice, SMS phishing, as well as “whaling” (the description will make it clear why it is called that) and clone phishing.

Spear Phishing
Such attacks are similar to regular phishing, but they are aimed at a specific person or organization. Therefore, hackers first collect detailed information about their targets in order to then send emails that look as plausible as possible. People often do not even think that a phishing email came from an unreliable source. Spear phishing can be called a more advanced version of regular phishing, since it requires much more solid preparation. For this reason, it is extremely difficult to protect against such an attack using conventional technical means. In addition, the person being targeted by spear phishing is in most cases not the real target of the criminals - their ultimate goal is usually the corporate network infrastructure, having gained control over which the hackers will derive financial benefit from this.

Voice Phishing (Vishing, Voice Phishing) In this case, hackers use the phone to collect the victim's personal and financial information. For example, a hacker may pose as an employee of a bank or insurance company and, under the pretext of advertising new services, gradually find out the interlocutor's personal data. Thus, "vishers" can take their victims by surprise, offering them a loan on extremely favorable terms. And since such services are often associated with the disclosure of personal financial information, then if the hacker can convince the victim of the legitimacy of his offer, the person may not even suspect a trick and pass on confidential information to the criminal.

An example that is partly related to "whaling" phishing: in March 2019, the CEO of a British energy company received a call from a man who sounded exactly like his president. The caller was so convincing that the CEO transferred $243,000 to a "Hungarian supplier" in a bank account that actually belonged to the scammer.

Smishing (SMS phishing)

This type of phishing attack uses mobile devices. The victim receives a message supposedly from a bank number. The message usually contains some scary information (see Scareware below), and then offers a solution to the problem. A classic example: the victim's personal account was allegedly debited for an unauthorized purpose, so the person is asked to follow a link to the bank's page (of course, a fake one) or call back the phone number provided (also controlled by the scammers). People also receive messages asking to help victims of a natural disaster, but to help, they need to leave their personal information. Particularly cunning hackers can “milk” their victims for months, regularly withdrawing small amounts so as not to alert people.

“Whale” phishing (Whale Phishing)

This is a phishing attack aimed specifically at a top manager of a large company. That is why it is called “whaling”, because the victim is highly valued, and the stolen information will be much more valuable than what ordinary company employees can offer to scammers. And since the victims in this case are high-ranking people, the criminals act accordingly: for example, they send legal messages or offer to discuss serious financial issues.

The largest attack of this type, not only phishing but also using social engineering in general, was carried out by Lithuanian citizen Evaldas Rimasauskas against two of the world's largest web corporations: Google and Facebook. Rimasauskas and his team created a fake company and posed as a computer manufacturer that worked with Google and Facebook. Rimasauskas also opened bank accounts in the company's name. As a result, the web giants suffered a total loss of more than $120 million.

And here's another high-profile case: Chinese aircraft parts manufacturer FACC lost almost $60 million as a result of a scam in which fraudsters posed as high-ranking executives and tricked employees into transferring funds to them. After the incident, FACC spent several more millions trying to get compensation from its CEO and CFO in court. The company claimed that its executives had failed to implement adequate internal security controls, but the FACC's lawsuit was dismissed.

Clone Phishing

This phishing attack works by sending a fake email disguised as a legitimate one, with the address from which the email was sent being very similar to one used by known and trusted sources (e.g. Mail.crop instead of Mail.corp). That is, the phishing emails look like they were sent by your bank or service provider, and their employees are asking for your personal information.

In this way, hackers copy the form of a corporate email, creating an almost identical sample: only this email is sent not from the real one, but from a similar address. The body of the email looks the same as in the emails that the user has already received from this organization, but the links in the email are replaced with malicious ones. In addition, resourceful criminals can even explain to the victim why they are receiving the “same” message again.

In fact, such emails have only one goal: “social hackers” try to trick the recipient into revealing personal or financial information by clicking on a link in the email, which redirects the user to a seemingly similar, but criminally controlled website designed to steal personal information.
A recent example of clone phishing: In January 2022, a large-scale attack was carried out to steal credentials from the Office 365 service. Hackers were able to successfully imitate messages from the US Department of Labor (DoL). This attack is a clear example of how effective phishing attempts can be. In this case, addresses with the real dol.gov domain were replaced with addresses from pre-purchased dol-gov.com and dol-gov.us domains. At the same time, phishing emails successfully passed the security gateways of the target organizations. The emails used official DoL attributes and the emails themselves were professionally written, inviting recipients to bid on a government project. Bidding instructions were included in a three-page PDF file with an embedded “Bid” button. When victims clicked on the link, they were redirected to a phishing site that looked identical to the real DoL site. The fake auction site prompted users to enter their Office 365 credentials and even displayed an error message after the first entry. This ensured that the victim would enter their credentials twice, reducing the likelihood of an incorrect entry.

Scareware
1738083226478.png

The essence of this type of attack is that the victim is scared (most often by pop-ups when visiting sites hacked by scammers), making them think that their computer is infected with malware or has accidentally downloaded illegal content. After some time, when the hacker understands that the victim is ready, he offers a solution to this fictitious problem. However, in fact, the program that is offered to the victim under the guise of an antivirus is malware, the purpose of which is to steal the user's personal information. Thus, the creators of "scarecrows" use the technology of suggestion, causing fear in the user and pushing him to install fake antivirus software.

Baiting (bait)

A very original method of social engineering, when the calculation is made on one of the most common human vices - curiosity. The essence of bait is that the hacker intentionally leaves devices infected with malware (for example, USB drives) in places where they are sure to be found (for example, in the smoking room of an office building). The victim swallows this simple bait and inserts the flash drive into the computer, which results in the automatic installation of malware into the system. Another type of bait is distributed via the Internet. Potential victims are offered tempting advertising, which in fact leads to malicious sites or encourages users to download an application infected with malware - most often, of course, "free". In addition, hackers often combine bait with Scareware attacks, only this time the "scares" are real, because the computer is already infected.

Water-Holing ("watering hole")
The name fully reflects the essence of the attack, only the "water" here is poisoned. By exploiting network vulnerabilities, a hacker attempts to compromise a specific group of people by infecting websites that they visit and trust. Water holing attacks often target popular websites, called the “target group.” Cybercriminals who practice Water holing (also known as Watering holes) call their victims “target prey,” and most often this prey is employees of government agencies or large organizations.

Hackers study the vulnerabilities of the “target group” websites and inject malware into them, usually hidden in JavaScript or directly in the HTML code. This malicious code redirects the “prey” from the target group’s websites to another site that has malware or ads installed. The viruses are now ready to infect computers as soon as the victims visit the compromised sites.

Pretexting attack (pretext attack)
The essence of the attack is that one party simply lies to the other in order to gain access to privileged data. The fraud is often initiated by a dishonest employee who pretends to need confidential information from the victim to perform an important task. No hacking - pure psychological influence, which looks very natural.

Quid pro quo (lat. "service for a service")

Such an attack is usually carried out by fraudsters who do not have advanced hacking tools in their arsenal, but conduct preliminary research of the targets. Using this type of attack, the attacker pretends to provide an important service to the victim. For example, a hacker finds someone with high access privileges to the network and calls him on the phone, introducing himself as an employee of the company's technical support service. If negotiations are successful and the victim agrees to "help" in solving the allegedly discovered problems, the hacker begins to control the victim, forcing him to perform certain actions. These actions eventually lead to the launch of malware in the system or the theft of registration data.

Honey Trap, Honey Pot

Remember the fable about the crow and the fox? The principle of Honey Pot attacks is exactly the same. The hacker gets to know the victim and pretends to have a certain interest in them (for example, romantic or sexual attraction). Gradually, a virtual "relationship" is established, which the victim begins to take seriously. And the charming cybercriminal, wasting no time, gradually collects confidential information, which can then be used, for example, to hack social media accounts or an email box. The hacker can also get remote access to the gullible victim's computer.

Tailgating or Piggyback ("back door", "riding on the back")

Another original technique from the arsenal of social engineering specialists, which is somewhat similar to the previous one. In this case, the criminal enters a secure room, following someone with an access card. Of course, the hacker is already a "friend" of the employee with privileged access and follows him into the restricted area.

Rogue Attack (fraudulent attack)

This method is a type of Scareware attack. Malware is installed on the victim's computer under the pretext of security, and the hacker convinces the victim that this software is completely legal and safe. The installed program then creates pop-up windows and alerts that advise the user to download new "safe software". Pop-up windows often show the user several agreement options (with different scenarios). However, there is no difference: by clicking "yes" to any of these options, the user downloads a dangerous program to his computer. Now the computer is at the hacker's disposal.
 
Top Bottom