> For the complete documentation index, see [llms.txt](https://106-sam.gitbook.io/ejptv2-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://106-sam.gitbook.io/ejptv2-notes/social-engineering.md).

# Social Engineering

### Social Engineering Fundamentals

**What is a Social Engineering ?**

* I look at it as human manipulation. You are hacking human beings.
* The goal of social engineering is either to gain access or to gather information

**Manipulating Humans**

* Impersonation
* Pretexting
* Emotional Pull
* Urgency&#x20;
* Free stuff
* Blackmail/Extortion
* Quid pro quo

**Common Tactics**&#x20;

* Phishing\*
* Watering Hole
* Baiting&#x20;
* Physical Access

**Please Explain**&#x20;

* Phishing - Malicious email
  * Reply with information
  * Click on links
  * Download files
* Spear Phishing - Targeted phishing&#x20;
* Whaling - Spear phishing of high-value individuals (C- suite, Board Members)
* Smishing - Like phishing, but through SMS messaging.
* Vishing - Like phishing, but through voice calls.

**Who would fall for that?**

* Pharming - Redirecting web traffic maliciously&#x20;
* Watering Hole - Use a trusted site against you
* BEC - Business Email Compromise
* Impersonation/Spoofing - Additional tactic.

<figure><img src="/files/5Q5lFVlAWudyEUb2TrJP" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/ktYu13ydgvI4iXusQcce" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/RiQPwZZlvDURDKYKj8Bl" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/eqrSnQANzj4Hp5yrp2jf" alt=""><figcaption></figcaption></figure>

**Super Effective (Baiting)**

* USB Autorun (Rubber ducky)

USB's are not even allowed at all in the US Military organization.

* Physical Access

There is right now a trend of people making videos about walking into unauthorized areas because they're carrying a ladder.

People will trust that if you've got tools and a ladder and you're walking right into the company, right through the doors and you wave to the receptionist and walk in that you're supposed to be there working on something impersonating a service person is very, very common.

* you could be a cable person&#x20;
* you could be there for a plumber, an electrician.

If you are wearing the right things and you walk in and you say the right thing, people will trust you and be like, oh, especially if you know some inside information.

Example: Oh, i'm supposed to be talking to Mr. Miller on the third floor and fixing his toilet.

**What does that have to do with Cybersecurity ?**

Well, scams against individuals can affect a business. If you are able to take advantage of one person's account, maybe financially, taking advantage of them with a scam might not result in a complete business loss. But those same methods might result in downloading malicious files, and malware, opening up backdoor to the network, maybe sending business information or compromising information that it shouldn't be shared.

All of these as cybersecurity professionals, we need to be thinking about and setting up some defenses to protect.&#x20;

**Stop the Attack**&#x20;

* User Awareness and Training
* Security Controls
* Defense in Depth

Best way is to stop the attack

If they have least privilege, If they can't navigate across the network and proliferate, then an attacker might only have access to one machine. If you have the right firewalls in place, if you have proxies in place, that might even make it more difficult for this to work. So defense in depth and covering all of your bases starting at the lowest level and moving up.

***

### **Case Studies**

* Google and Facebook Fake Invoicing&#x20;
* FACC CEO fraud
* Robinhood Vishing
* Fake Excel File
* HTML Table Windows Logo
* FIN7 USB in Mail

**Google and Facebook Fake Invoicing**

So in 2013 to 2015, someone impersonated an electronic manufacturer that they sent fake invoices with forged executive signatures.&#x20;

* 2013-2015
* Impersonated Electronics Manufacturer
* Fake invoices with Forged Executive Signatures
* $100 million USD
* Culprit Arrested&#x20;
* Funds Recovered

**FACC CEO fraud**

Back in 2016, they're a aircraft manufacturing company, i think out of China. And they had 54 million euros stolen from them through fake president fraud. So someone compromised or impersonated the CEO's email sent an email to the CFO seeming urgent and knowing and sending it at a time where the CEO couldn't actually respond with the information of, Hey, forward or pay this invoice, sent this money now to our supplier, like finish the deal. Like you have the ability to do it. And it was such and good or decent impersonation that the CFO fell for or the finance people fell for it sent the money and it ended up with the CEO and the CFO of the company being fired for not having things properly put in place so this couldn't happen.

* 2016
* 54 million euros
* Airplane Parts Manufacturer
* Fake-president Fraud&#x20;
* CEO and CFO fired, sued

<figure><img src="/files/Sg4vjhVih2F6AFnW4gih" alt=""><figcaption></figcaption></figure>

**Robinhood Vishing**

* November 2021
* Called Customer Service&#x20;
  * Keys to System
* &#x20;\> 5 Million Emails
* 2 Million Full names
* 310 PII (birthdays, zip codes)

**Fake Excel File**

* April 2021
* Business Email Compromise (BEC)
* Looks like Excel file (.xls file extension)
  * Actually an HTML file
  * Fake Office 365 Login Page

**HTML Table Windows Logo**

* April 2021
* Email Impersonation&#x20;
* Bypass Email Filters
  * Catches Images
  * Allows Tables

**FIN7 USB Mail**

* August to November&#x20;
* Packages sent via UPS and US Postal Service
* Impersonated Department of Health and Human Services and Amazon&#x20;
* USB stick laced with malicious software

***

### Penetration Testing and Social Engineering&#x20;

**What are the vulnerabilities ?**

NIST 800115 actually talks about how to do a penetration test and includes a section on social engineering&#x20;

Talked about using Vishing as well as business email compromise to test.

* Scope Matters&#x20;
* What we are about to do with social engineering really edges on what people find acceptable and what they find to be wrong. Even if it's not criminal, people won't necessarily like to know that you're using social engineering tactics as part of your job, even if you're a good guy, white hat hackers , gray hat hackers still don't get looked well upon.
* We need to be in the bounds of the scope
* Initially we can use information gathering

External Access&#x20;

* Malware
* Credentials&#x20;

Physical Access

* Fake badges or clone their RFID card
* Rubber Ducky
* Impersonating work people

***

### Let's goPhishing!

goPhish tool

It's written in GO language. So our victim's email address is <victim@demo.ine.local>

* Start UP goPhish server
* browse to [http://localhost:3333\&#x20](https://106-sam.gitbook.io/ejptv2-notes/http:/localhost:3333\&#x20);
* advanced allow as no ssl certificate
* GOPhish, setup a profile and we are emulating an email from INE.

from: info <<support@demo.ine.local>>

host: localhost:25

username: <red@demo.ine.local>

password:&#x20;

&#x20;\> send text email button

Landing Page

{% embed url="<http://localhost:8080>" %}

INE password reset\
url: <http://localhost:8080>

capture submitted data

password reset.txt
