SECRETS OF SOCIAL ENGINEERING |Free Antivirus
SECRETS OF SOCIAL ENGINEERING
Art of influence and manipulation, social engineering holds a central place in external frauds. These are methods and techniques that allow, at the end of a relational approach based on influence and manipulation, to gain access to an information system or confidential information to document a scam. What are the main driving forces behind social engineering? How to protect yourself?
Fraud today is organized crime
The time of the more or less lonely hacker is over. We can only quote Interpol in its latest report on this point: “ In the past, cybercrime was carried out by isolated individuals or small groups. Today, we are seeing very complex cybercrime networks bringing together individuals from all over the world, in real time, to commit crimes on an unprecedented scale. Criminal organizations are increasingly turning to the internet to facilitate their activities and maximize their profits as quickly as possible. The crimes themselves are not necessarily new: theft, fraud, illegal gambling, the sale of fake drugs… But they evolve along with the opportunities, thus becoming more widespread and more devastating. “Companies are therefore dealing with a very large part.
The Avalanche cyber criminal network
A Major international investigation carried out jointly by Europol, Interpol and the FBI has brought an end to the cybercrime activities of a large network of hackers. They had taken over half a million computers in 180 Countries through malicious attachments, and were using them without the knowledge of their users to generate attacks. Their booty is estimated at several hundred million euros.
The art of intelligence
The most effective frauds are also the best informed. For criminals, it is key to obtain as much useful information as possible about the target, before taking action. Identity theft, such as fraud against the president, banker or supplier, will be all the more successful when the company's decision-making chain has been deciphered: the attack will come at the best time, and the ground will be known. With the information gathered, the swindler will use his charisma, his know-how and his nerve, very often to trigger a transfer to a ghost destination.
He has plenty of means to know his target in great detail. Starting with the internet, visible and invisible, where many sources of information coexist:
sites of the target, its customers, partners, suppliers, etc.
economic and financial information sites,
professional and personal social networks of employees,
forums, instant messaging mailing lists,
blogs, dating sites, recruitment platforms ...
But intelligence gathering goes through many other means, such as:
the installation of spyware, from an infected attachment or USB key “forgotten” in the company,
the trash search,
a fake telephone survey,
a business meeting,
an internal or external job interview,
classical listening (on the train or plane, at a restaurant, etc.)
Manipulation and deception
The criminal will now attack the target that the information-gathering work has enabled him to isolate. He knows the decision-making circuits, he knows who is saying "you" or "you" to whom, he knows the weak points of his victim. He will demonstrate all his talents of conviction, using proven methods. Christophe Casalegno, of the Digital Network group, lists them as follows:
Build trust : settle into an ordinary process, share jargon,
Exchange help : Let me help you and / or can you help me?
Use authority : it creates stress while seemingly relieving the responsibility of the target, who acts on order. (NB: the fraudsters have drawn all the consequences of the Milgram experience on submission to authority…!)
Give the illusion of a choice
Adapt your technique : sympathy, authority, charm, reciprocity ...
When it comes to deception - usually identity theft - the choice is vast. The fraudster can pretend to be the president or a hierarchical superior, an administration, a supplier, a bank, the company's IT department, the police, the fire brigade, a delivery man… and the list is not closed! The action could be multimodal, and use the telephone, email or instant messaging, social networks, a face to face meeting ...
Can we protect ourselves against social engineering?
Prevention is essential, and its main lines are known. Upstream: protection of computer systems, telephone systems, establishment of more robust procedures for identifiers and passwords, etc. Downstream, double control over cash outflows, separation of order and execution, double signature. But apart from the fact that not all of these policies are rolled out overnight, prevention is no longer enough to protect companies Free antivirus.
Scammers are motivated, resourceful, and creative. Their computer spy tools are constantly changing, and they even find integrated solutions for phishing or ransomware in SaaS mode on the darknet… with pay-as-you-go!
Faced with an uncontrollable risk, taking out insurance remains the only way to deal immediately with the unforeseeable, by covering and indemnifying the losses suffered.

Comments
Post a Comment