# Sec+ #001: Different types of Social Engineering Techniques


<!-- wp:paragraph {"align":"center","backgroundColor":"medium-gray"} -->
<p class="has-text-align-center has-medium-gray-background-color has-background"><em><strong>Marvin’s Phone rings and he picks it up. Hello?</strong></em></p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"backgroundColor":"medium-gray"} -->
<p class="has-medium-gray-background-color has-background"><strong>Scammer:</strong> Good afternoon Mr. Marvin, this is Kelvin from the security department of your bank. We've observed some suspicious behavior on your account and need your help right away to remedy the problem. </p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"backgroundColor":"medium-gray"} -->
<p class="has-medium-gray-background-color has-background"><strong>Marvin:</strong> Oh, you're serious? What kind of activity are we discussing?</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"backgroundColor":"medium-gray"} -->
<p class="has-medium-gray-background-color has-background"><strong>Scammer:</strong> Mr. Marvin, we suspect unauthorized access to your account. Many of our valued customers have faced similar issues recently, but we were able to resolve them by generating a One-Time Password (OTP) to validate their account ownership. It will be delivered to your phone, and I will guide you through the steps. </p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"backgroundColor":"medium-gray"} -->
<p class="has-medium-gray-background-color has-background"><strong>Marvin:</strong> Okay, Just let me know what I need to do.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"backgroundColor":"medium-gray"} -->
<p class="has-medium-gray-background-color has-background"><strong>Scammer: </strong>Please provide the OTP just sent to your phone.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"align":"center","backgroundColor":"medium-gray"} -->
<p class="has-text-align-center has-medium-gray-background-color has-background"><strong><em>Marvin provides the OTP to the scammer(caller)</em></strong></p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"backgroundColor":"medium-gray"} -->
<p class="has-medium-gray-background-color has-background"><strong>Scammer:</strong> You've done an excellent job. For security reasons, we must now check a few additional details. Please confirm your birth date and the last four digits Debit Card. </p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"backgroundColor":"medium-gray"} -->
<p class="has-medium-gray-background-color has-background"><strong>Marvin: </strong>Sure, my birth date is (*provides details*), and the final four digits of my Debit Card are(*provides details*). </p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"backgroundColor":"medium-gray"} -->
<p class="has-medium-gray-background-color has-background"><strong>Scammer:</strong> Thank you so much. Your account has been secured, and we thank you for your assistance. Is there anything else I can do for you today? </p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"backgroundColor":"medium-gray"} -->
<p class="has-medium-gray-background-color has-background"><strong>Marvin: </strong>No, Thank you.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"backgroundColor":"medium-gray"} -->
<p class="has-medium-gray-background-color has-background">Marvin hangs up, unaware of the scammer's deception. Days later, he checks his bank account and discovers that it has been fully drained. In this terrible scenario, Marvin falls prey to the social engineering fraud, unintentionally providing the scammer with his OTP and personal information. His discovery comes too late, as his bank account has been fully wiped. OUCH!!!</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p></p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"align":"center","fontSize":"medium"} -->
<p class="has-text-align-center has-medium-font-size"><strong>Sit back, relax, and sip your favorite drink as I take you on a delightful adventure!!!</strong></p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"align":"center","style":{"color":{"gradient":"radial-gradient(rgb(122,220,180) 0%,rgb(0,208,130) 100%)"}},"fontSize":"medium"} -->
<p class="has-text-align-center has-background has-medium-font-size" style="background:radial-gradient(rgb(122,220,180) 0%,rgb(0,208,130) 100%)"><strong>1.1</strong> <strong>What is Social Engineering?</strong></p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The term "<strong>social engineering</strong>" refers to a variety of strategies used to "<strong>compel</strong>" people into disclosing information or acting on behalf of a threat actor. Social engineering is a type of attack that primarily targets Humans. It frequently involves some type of social connection and capitalizes on positive characteristics such as a willingness to help others. It's also known as "<strong>hacking the human</strong>"</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"align":"center","style":{"color":{"gradient":"linear-gradient(105deg,rgb(122,220,180) 0%,rgb(0,208,130) 100%)"}},"fontSize":"medium"} -->
<p class="has-text-align-center has-background has-medium-font-size" style="background:linear-gradient(105deg,rgb(122,220,180) 0%,rgb(0,208,130) 100%)"><strong>1.2 Social Engineering Techniques</strong></p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Social engineering attacks can take many different forms and can be carried out everywhere there is human interaction. The most popular types of&nbsp;social engineering techniques&nbsp;are as follows.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#1:</strong> <strong>Phishing</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Phishing involves deceiving victims into disclosing sensitive information through the fraudulent use of email.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>It often poses as a reliable source, such as a reputable organization, to obtain personal information.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>This technique combines social engineering with spoofing to create the appearance of a legitimate entity to manipulate the target.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><strong>NEVER CLICK A LINK IN AN EMAIL</strong>; rather, go directly to the website</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#2: Smishing</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Smishing, a phishing variant, uses SMS text messages to trick victims into disclosing critical information.  </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>The attack starts with an SMS message that directs the user to a URL that acts as a platform for multiple attack vectors, including potentially malware-infected content.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#3: Vishing</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Vishing includes manipulating human relationships via phone calls or IP-based voice messaging services (VoIP) to collect sensitive information.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>The channel for this approach, also known as voice phishing, is voice communication technology.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#4: Spam</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Spams are unsolicited emails, sometimes known as junk email. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Spam is a social engineering approach that involves delivering unsolicited and false messages to recipients to manipulate them.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Its goal is to dupe people into acting or disclosing critical information. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Spammers take advantage of human vulnerabilities by mimicking reputable sources and employing psychological techniques</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#5: SPIM </strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>SPIM, often known as spam via instant messaging, involves the unsolicited distribution of deceptive and unwanted messages via instant messaging platforms. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>These messages frequently include malicious links or attempts to collect personal information.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#6: Spear phishing</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Spear phishing is a word used to describe a phishing attempt that targets a specific person or group of people who have a common trait.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>It is a type of phishing that uses email or the internet to target specific persons.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>It is a phishing scam in which the attacker possesses information that makes a certain victim more likely to be fooled by the attack. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Targeted phishing messages, customized to individual users and incorporating inside information, enhance the attack's credibility.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#7: Dumpster diving</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Dumpster diving involves sorting through discarded or disposed materials from an organization or individual to find valuable papers or possibly sensitive information.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>It is the technique of searching through trash or abandoned removable media for usable data that can be abused during a penetration attempt.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#8: Shoulder surfing</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Shoulder surfing is a technique to watch someone enter in their sensitive information such as password or PIN and then steal it. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Despite the name, the attacker may not even need to be close to the target, they could utilize CCTV or powerful binoculars to view the victim directly from a distance.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Use privacy filters to prevent shoulder surfing</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#9: Pharming</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Pharming is a type of impersonation attack in which customers are directed from a legitimate website to a fake website with a similar appearance. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Pharming can be accomplished through two methods: poisoning DNS servers or exploiting vulnerabilities in clients.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Pharming, unlike other forms of social engineering, utilizes a passive method that manipulates the victim's computer's DNS process, resulting in users being redirected from legitimate websites to malicious ones.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#10: Tailgating</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Tailgating, also known as piggybacking, is a social engineering technique&nbsp;that involves closely following an authorized individual to gain unauthorized access to a secure area. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>The attacker uses this approach to take advantage of someone who has properly opened a door or passed through a checkpoint using their access card or PIN.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#11: Eliciting information</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Elicitation of information is a technique&nbsp;of social engineering that entails influencing people to reveal sensitive information. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>It necessitates the development of trust, the establishment of rapport, and the utilization of human psychology.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Often Performed via vishing</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#12: Whaling</strong></p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"align":"center","style":{"color":{"text":"#ec18b0"}}} -->
<p class="has-text-align-center has-text-color" style="color:#ec18b0"><em>Studies show that "The blue whale (Balaenoptera musculus) holds the title for being the largest animal on Earth"</em></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Whaling, also known as CEO spear phishing, is a type of phishing that specifically targets senior executives or rich individuals. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>It is aimed primarily at upper-level management inside a firm, such as CEOs and other high-profile persons deemed "big fish" targets.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#13: Prepending</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Prepending is a social engineering method in which an attacker inserts specified characters or phrases into the beginning of a website's URL to fool users.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>The attacker's goal in changing the URL is to establish a false sense of confidence and deceive victims into disclosing sensitive information. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>In the case of cyvally.com, for example, an attacker may establish a malicious URL such as "login.cyvally.com" to trick users into submitting their credentials. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>To defend themselves from social engineering attempts, users must be cautious and validate the entire URL.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#14: Identity fraud</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Identity theft is a type of impersonation in which an attacker creates or unlawfully obtains and uses another person's personal information. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>It makes use of certain details from a person's identification. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Credential databases (<a href="https://haveibeenpwned.com/" target="_blank" rel="noreferrer noopener">haveibeenpwned.com</a>) allow individuals to check if their personal information, such as email addresses or usernames, has been compromised in data breaches.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#15: Invoice scams</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>An invoice scam, also referred to as invoice fraud or business email compromise, tricks individuals or organizations into making false payments or disclosing sensitive financial information.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Attackers create fake invoices or mimic legitimate payment requests to deceive victims into transferring funds to their own accounts.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>To protect against invoice scams, it is crucial to establish robust verification systems and educate staff about the risks associated with fraudulent payment requests.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#16: Credential harvesting</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Credential harvesting is a social engineering technique used to obtain sensitive user credentials, such as usernames and passwords. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>The credentials obtained are valuable for unauthorized account access and can lead to identity theft and financial crime. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>To protect against credential harvesting, verify the legality of requests, use strong passwords and multi-factor authentication, keep software up to date, and educate users about the risk involved with this technique</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#17: Reconnaissance</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Reconnaissance refers to gathering information regarding a target to uncover vulnerabilities and prepare effective attacks.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>To get important information, attackers employ a variety of techniques such as open-source intelligence, other social engineering techniques, and physical surveillance.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Reconnaissance assists attackers in creating profiles of their targets, understanding their behavioral patterns, and developing specialized social engineering strategies.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#18: Hoax</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>It is a threat that doesn't genuinely exist</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Hoax&nbsp;refers to a deceptive&nbsp;scheme&nbsp;intended to manipulate individuals for personal gain. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Social engineers employ hoaxes to distribute false information, invent scenarios, or fool targets to elicit specific behaviors or obtain sensitive information.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>To avoid falling prey to social engineering hoaxes, it is vital to use critical thinking, and skepticism, and verify information sources.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#19: Impersonation</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Impersonation entails claiming to be someone else, usually a trustworthy entity, to deceive and manipulate people for personal gain.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>To gain the target's trust, social engineers adopt the identity or persona of a colleague, authority figure, or trusted organization.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#20: Watering hole attack</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Watering hole attack occurs when an attacker identifies specific groups or organizations, learns which websites they visit, and injects malicious code into those websites. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>It is another passive strategy in which the threat actor does not have to risk direct communication with the target.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>To prevent, Apply Defense-in-depth mechanism, Firewalls and IPS, Anti-virus/Anti-malware</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#21: Typosquatting</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Typosquatting, also known as URL hijacking in which an attacker registers a domain name with a frequent misspelling of an existing domain so that when a user enters a URL into a browser, they are directed to the attacker's website.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>This means that the threat actor registers a domain name that is extremely close to a legitimate one.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>For instance, "cyvally.com" could be used as a typosquatting domain for "cyvalley.com."</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#22: Pretexting</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>Pretexting is a social engineering method that entails fabricating a fictitious scenario or identity to fool others and obtain sensitive information from them.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>To acquire the target's trust and persuade them to disclose confidential data, attackers employ elaborate stories or mimic trusted persons.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph {"align":"center","gradient":"pale-ocean","fontSize":"medium"} -->
<p class="has-text-align-center has-pale-ocean-gradient-background has-background has-medium-font-size"><strong>#23: Influence campaigns</strong></p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul><!-- wp:list-item -->
<li>An influence campaign is a well-planned effort by a highly capable institution, such as a nation-state or terrorist organization, to influence public opinion on a certain topic. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>These campaigns frequently employ a mix of tactics, such as espionage, disinformation, hacking, and the exploitation of social media platforms. </li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>The goal is to change people's perceptions and impact public debate in support of the campaign's goals.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph -->
<p></p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"align":"center","gradient":"light-green-cyan-to-vivid-green-cyan","fontSize":"medium"} -->
<p class="has-text-align-center has-light-green-cyan-to-vivid-green-cyan-gradient-background has-background has-medium-font-size"><strong>1.3 Principles (reasons for effectiveness)</strong> <strong>of Social Engineering</strong></p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Social engineering is a popular and successful malevolent technique. Because it takes advantage of basic human trust, social engineering has shown to be a particularly effective means of persuading individuals to perform behaviors they would not otherwise perform. Social engineering attacks&nbsp;must adhere to one or more of the following principles to be effective. Using the scenario above, Principles of Social Engineering are: </p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p></p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><strong>Authority</strong>: This is using a position of power or competence to acquire the target's trust and compliance. </p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Using the idea of authority, the scammer appears as a representative from Marvin's bank's security department. The scammer obtains Marvin's trust and cooperation by claiming to have the competence and power to remedy the alleged issue.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><strong>Intimidation</strong>: This is the use of fear or threats to pressure the target into doing specific tasks or disclosing sensitive information. </p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>By highlighting unusual activity on Marvin's account, the scammer generates a sense of urgency and fear. This intimidating strategy is intended to make Marvin more receptive to the scammer's instructions without questioning them.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><strong>Consensus</strong>: This is influencing the target by evidence that others have already taken the desired action. </p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The scammer achieves consensus by telling Marvin that his help is required to remedy the security issue. By insinuating that other customers have also been affected, the fraudster hopes to make Marvin believe that his actions are consistent with those of others.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><strong>Scarcity</strong>: This is in order to motivate prompt compliance and create a sense of limited supply or urgency.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p> By emphasizing the necessity for fast action, the scammer creates a sense of scarcity. The scammer instills anxiety in Marvin by claiming that his account is at jeopardy and demands the One-Time Password (OTP) without delay, prompting Marvin to supply the needed information swiftly.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><strong>Familiarity</strong>: Creating a connection or relationship with the target through the use of shared experiences or personal information. </p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The scammer addresses Marvin by name, bringing a personal touch to the interaction. The scammer seeks to establish a connection and build confidence in this manner, making Marvin more inclined to agree with the scammer's requests.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><strong>Trust</strong>: Deception and manipulation are used to instill trust and reliance in the attacker. </p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The scammer earns Marvin's trust by impersonating a bank official, exhibiting knowledge of Marvin's personal information, and assuring him that the activities are required for account protection. Because of this trust, the scammer is able to obtain crucial information from Marvin without raising suspicions.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><strong>Urgency</strong>: Creating a time-sensitive situation that forces the target to respond fast and without careful thought. </p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The scammer instills a sense of urgency by claiming that quick action is required to remedy the purported security threat. The scammer puts pressure on Marvin to supply the sought information immediately by emphasizing the need for collaboration and prompt response.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p></p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>These principles of social engineering collectively contribute to the success of the scam, as Marvin falls victim to the deception and unknowingly provides the scammer with the necessary information to drain his bank account. It serves as a reminder of the importance of being vigilant and cautious when dealing with requests for personal information, especially in situations involving authority, urgency, and unfamiliar or unexpected interactions.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p></p>
<!-- /wp:paragraph -->

<!-- wp:quote {"fontSize":"medium"} -->
<blockquote class="wp-block-quote has-medium-font-size"><!-- wp:paragraph {"fontSize":"medium"} -->
<p class="has-medium-font-size"><strong>"Social engineering is a dance of trust and deceit, where the attacker leads and the victim follows, unaware of the dangerous steps they are taking." </strong></p>
<!-- /wp:paragraph --><cite><em><strong>- Brian Krebs</strong></em></cite></blockquote>
<!-- /wp:quote -->

<!-- wp:paragraph -->
<p></p>
<!-- /wp:paragraph -->

<!-- wp:paragraph {"align":"center","gradient":"light-green-cyan-to-vivid-green-cyan","fontSize":"medium"} -->
<p class="has-text-align-center has-light-green-cyan-to-vivid-green-cyan-gradient-background has-background has-medium-font-size"><strong>1.4</strong> <strong>Review Questions</strong></p>
<!-- /wp:paragraph -->

<!-- wp:jetpack/contact-form {"subject":"[CyVally] Sec #001:Compare and contrast different types of social engineering techniques"} -->
<div class="wp-block-jetpack-contact-form"><!-- wp:jetpack/field-checkbox-multiple {"label":"1. Which of the following social engineering techniques involves sending fraudulent emails to deceive individuals into revealing their sensitive information?\u003cbr\u003e","requiredText":"(required)"} -->
<!-- wp:jetpack/field-option-checkbox {"label":"Vishing"} /-->

<!-- wp:jetpack/field-option-checkbox {"label":"Tailgating"} /-->

<!-- wp:jetpack/field-option-checkbox {"label":"Phishing"} /-->

<!-- wp:jetpack/field-option-checkbox {"label":"Pretexting"} /-->
<!-- /wp:jetpack/field-checkbox-multiple -->

<!-- wp:jetpack/button {"element":"button","text":"Submit","lock":{"remove":true}} /--></div>
<!-- /wp:jetpack/contact-form -->

<!-- wp:jetpack/contact-form {"subject":"[CyVally] Sec #001:Compare and contrast different types of social engineering techniques"} -->
<div class="wp-block-jetpack-contact-form"><!-- wp:jetpack/field-checkbox-multiple {"label":"2 What distinguishes spear phishing from regular phishing attacks?\u003cbr\u003e ","requiredText":"(required)"} -->
<!-- wp:jetpack/field-option-checkbox {"label":"Spear phishing targets specific individuals or groups  "} /-->

<!-- wp:jetpack/field-option-checkbox {"label":"Spear phishing relies on voice communication to deceive victims"} /-->

<!-- wp:jetpack/field-option-checkbox {"label":"Spear phishing involves physical access to a target's location"} /-->

<!-- wp:jetpack/field-option-checkbox {"label":"Spear phishing uses malicious software to exploit vulnerabilities"} /-->
<!-- /wp:jetpack/field-checkbox-multiple -->

<!-- wp:jetpack/button {"element":"button","text":"Submit","lock":{"remove":true}} /--></div>
<!-- /wp:jetpack/contact-form -->

<!-- wp:paragraph -->
<p></p>
<!-- /wp:paragraph -->

<!-- wp:jetpack/contact-form {"subject":"[CyVally] Sec #001:Compare and contrast different types of social engineering techniques"} -->
<div class="wp-block-jetpack-contact-form"><!-- wp:jetpack/field-checkbox-multiple {"label":"3. Which principle of social engineering involves exploiting an individual's inclination to comply with requests from authoritative figures?\u003cbr\u003e","requiredText":"(required)"} -->
<!-- wp:jetpack/field-option-checkbox {"label":"Authority"} /-->

<!-- wp:jetpack/field-option-checkbox {"label":"Intimidation "} /-->

<!-- wp:jetpack/field-option-checkbox {"label":"Consensus"} /-->

<!-- wp:jetpack/field-option-checkbox {"label":"Scarcity"} /-->
<!-- /wp:jetpack/field-checkbox-multiple -->

<!-- wp:jetpack/button {"element":"button","text":"Submit","lock":{"remove":true}} /--></div>
<!-- /wp:jetpack/contact-form -->

<!-- wp:jetpack/contact-form {"subject":"[CyVally] Sec #001:Compare and contrast different types of social engineering techniques"} -->
<div class="wp-block-jetpack-contact-form"><!-- wp:jetpack/field-checkbox-multiple {"label":"4. Which principle of social engineering builds on established relationships and familiarity to gain trust and manipulate individuals?\u003cbr\u003e","requiredText":"(required)"} -->
<!-- wp:jetpack/field-option-checkbox {"label":"Authority"} /-->

<!-- wp:jetpack/field-option-checkbox {"label":" Intimidation"} /-->

<!-- wp:jetpack/field-option-checkbox {"label":"Familiarity "} /-->

<!-- wp:jetpack/field-option-checkbox {"label":"Trust"} /-->
<!-- /wp:jetpack/field-checkbox-multiple -->

<!-- wp:jetpack/button {"element":"button","text":"Submit","lock":{"remove":true}} /--></div>
<!-- /wp:jetpack/contact-form -->

<!-- wp:paragraph -->
<p></p>
<!-- /wp:paragraph -->

