Submind YouTube summaries
Thumbnail for hackmas2026 - So you're interested in social engineering? The very first steps

hackmas2026 - So you're interested in social engineering? The very first steps

Watch on YouTube

Video summary

Kirill Solovyov, a security expert with fifteen years of experience, introduces the foundational steps for conducting social engineering attacks that primarily target organizations rather than individuals. He distinguishes these real-world tactics from "movie hacking," emphasizing that actual attacks often involve inspecting passwords over the phone or leveraging AI-assisted techniques within a linear progression of research, targeting, trust-building, and exploitation. The presentation outlines various attack vectors, including impersonating authority figures to bypass policies, reverse social engineering where victims feel compelled to seek help, and physical access methods like tailgating or using fake badges. Additional techniques cover acquiring keys through cameras, eavesdropping during distracted moments, dumpster diving for sensitive data, and remote attacks via phishing, vishing, or insecure Wi-Fi hotspots, while also noting historical contexts like malware delivered via postal mail. A critical component of successful social engineering is the creation of a strong pretext, which involves crafting a believable fake identity with a consistent role, name, and goal that aligns with the target environment, such as a janitor who can access an office but not a server room. Solovyov stresses the importance of self-conviction in this persona to maintain confidence under pressure and advises avoiding hard targets like trained security guards in favor of individuals lacking specific protocols, such as back-office IT staff or bank managers. To succeed, attackers must leverage the natural desire of people to help and avoid conflict by threatening legal action if requests are denied, while also utilizing Open-Source Intelligence (OSINT) tools like Google Dorks, Wayback Machine, and Shodan to gather background information on targets before engaging them. Practical preparation involves mental simulation of scenarios from both the attacker's and target's perspectives, practicing alternative personas, and building pretexts through storytelling exercises. The speaker highlights that while automated OSINT tools have evolved, manual geo-searches remain useful for verifying events, and emphasizes that confidence, determination, and readiness for challenges are essential traits for any social engineer. Ultimately, the goal is to move with purpose even when facing obstacles, understanding that success with one target enables moving to another in a continuous cycle of reconnaissance and execution.
Read the full video transcript
Hello everybody. This is going to be in English. I don't speak German that well. Uh thank you so much for coming in to my talk. So, uh my name is Kirill Solovyov and uh I have been running a security company. Like we hack people and companies, mostly companies, professionally. Uh that includes some social engineering as well. So, I have been doing that for well, 15 years that that I've been I've been with the company. Um this presentation is the very first steps for social engineering. Anyone here has done it professionally before? No one. Unprofessionally? As a hobby? Yeah, okay. Uh five people, good. Yeah. Uh so, that's basically what we're going to go through here in this talk. Um I will try to give you both the theory, some examples from my experience, and if we do have the time, I'll try to leave you with some exercises that you can do in your life without harming others to to try and uh improve your skills. >> [clears throat] >> So, this is um SMBC, Saturday Mornings Breakfast Cereal, one of one of the comics that I that I frequent. Uh some of you may have seen it. So, here's uh you know, the We had we had a joke uh with a friend many, many years ago that, you know, you have to you have to sniff the jaws on port 53 and then you can get access to the super root. Uh so, this is this is kind of movie hacking, right? And uh the second panel of the comic is is is real hacking, you know, you have a Robert Hackerman that just, you know, inspects your password over the phone. And uh that's where the future lies in, I believe. Um the new AI things will also try to do social engineering. Yeah, they may help social engineer, but I think we are many, many years away uh from them physically walking up to you and trying to social social engineer you. Now, the doing it through the phone is a different thing. That might happen. So, uh that's the agenda for today. Quite a lot of stuff here. Uh about eight eight different things to go through. So, let's let's get on with it. Um who has worked with cyber kill chain before? Anybody? One, two, two people professionally working, I imagine. Uh so, Lockheed Martin created the cyber kill chain. Uh it's basically seven steps that bad guys do uh when they try to attack your company, that they go through. Um I personally apply it um in red teaming. When you want to simulate the attack, then what you do is you try and follow the steps of the bad guys. Now, social engineering usually usually comes in reconnaissance phase. Sometimes sometimes you use it in phase three as well when you do delivery, right? But it's mostly it's mostly applicable in in the reconnaissance phase, right? That's when you try to understand uh what the company is, what is the employee structure, if someone is in vacation, maybe what what are the server names and so on, you know, the basic basic stuff. So, we going to do we we will have a small chapter on OSINT here as well. So, what is social engineering, right? That's the academic academic way to say it, but basically I love to define it as it's getting someone to do what they're not supposed to do or getting someone to say something that they are supposed to keep secret. Um so, that's the attack cycle. It applies to organizations. Um I will try not to talk about hacking individuals, right? That's rarely can be used professionally, uh except I don't know if you're part of secret service, you might you might want to hack a high high value target, I imagine. But other than that, usually uh you apply social engineering with the master goal of hacking an organization. So, for an organization, you have this cycle which you cannot have if you're hacking individual. You do research, you target a person, you build trust, and then you exploit that trust. Now, what does it mean and why is it a cycle? And my personal pet peeve, I've done bunch of certifications like you know, the the the fake ones that they that exist in the corporate world world, not because I want to because my customers want me to teach them, so I have to do them. And my pet peeve is unnecessary cyclic graphs, you know, where you know, they're just four steps, let's say, and they're connected with a force arrows well. This is not necessary, this is necessary. So, the goal here is, you know, once you're done with this first person, you go move forward to the second person. Let me give an example here. Let's say I called you up on the phone. And I asked very very nicely, "Hey, so listen, can you give me the server name?" And anyone would would give me the server name of your company? No one would, right? But imagine I called you up and I had some background info. I could call myself in the name of one of your colleagues. I would know what the company name is, I would know the address, I would know what floor you're in, maybe I would know the name of the computer you're sitting at. I would know a lot of background information. And if I were to project that knowledge onto you that I have that that I do have that knowledge already, and then I would ask a question, it would be more in line with where we are in the conversations. It wouldn't just be out of out of the blue. And believe it or not, sometimes with some people you can even build build this cycle in such a way that you can even ask them for for a password. Now, a year or two ago, I I was lucky enough to participate in the social engineering engineering village in a Canadian conference called HackFest. And we do we do social engineering calls there. So, you call up someone and and you try to get flags, right? When is the water delivered? Where are the video cameras? Where are the security cameras? Uh what's what kind of operating systems do you use, right? So, all those are all the flags and you have to get them over the phone. And the fun part was I enjoy what I enjoyed the most was the I think it was called social engineering at night. It was it's a French conference, so it was Le Le Nuit or something like that. Um and it's a bit different. You only get three flags. You need to know their Wi-Fi access point name. You need to know their opening times. And you need to know who you're calling because the the joke with the social engineering at night is that the organizers call someone up for you and you don't know who who you're talking to. You have no idea what kind of company that is. Uh usually it's it's a hotel or a conference center. Um so and I I mean I grabbed all I grabbed all three flags. I you know, I was I was calling up I'm saying saying, you know, this is Josh with a Quebec Special Services. We have a special guest coming in VIP. Uh we need to clear out the place, you know, reserve everything you have. And I mean I got all three flags, but it turned out it was a toy store. Uh and it was really awkward when I was saying, you know, we're going to have a party of 20 people coming in. There's going to be 20 local uh local females attending as well, you know, and all that and and toy store, you know. This thing that thing. >> [laughter] >> But uh I got cut off by by the organizers because the very helpful very nice person on the other end were ready to give me the Wi-Fi password. I was like, okay, so Wi-Fi name is this, but you know what And and she was, yeah, and the password is, you know, in case you need it and or you can't you can't do that, so I was cut off. So, in that case, uh because um the target was so easy and so narrow, only three things, I was able to do that with a single person. But what you usually do is you would build this you would go through the thing with a single person, single employee for company, and then you move forward uh to the to the next template. Um so, I'm going to I'm going to talk about some of the things here. Research. Uh research mean meaning either you already come in with something from from the previous stage here and then you add on something that you may find otherwise. Or if it's the first time you do it, you do your research, you know. And we're going to talk about all the methods, uh well, the basic methods, the simple stuff here in the presentation um in in the next slides as well. >> [clears throat] >> And then targeting. So, targeting means you select someone. Uh so, let's say I want to I want the CEO of a large corporation to believe that uh that, you know, I'm one of them. I wouldn't necessarily target well, I would necessarily not target the CEO initially, all right? Because I have nothing. I don't have I don't have a I don't have a background. I don't have a good legend. I can't really can't really convince them of anything. Uh so, I target someone else, right? Uh and then I build trust with them. Now, how long do you think you can just shout uh how long do you think does the building trust phase last uh for a single person? Any ideas? Any versions? Yeah. A month? Okay. Other options? Yeah? >> Three months. >> Three months? >> A minute. >> A minute? >> [laughter] >> Okay. Yeah, good. That That's That That's good, right? Because um when we talk about social engineering outside of organizations, right? Individual social engineering, uh phishing emails is a is a great example, all right? And those guys, they don't necessarily demand money immediately from you, but they they kind of, you know, they want to build initial trust in a single email. So, it is possible, let's say during a phone call to try and build build trust in a couple minutes, absolutely. Uh but it's also three months was the longest as you mentioned. It's also possible to be building trust for for months and years. Absolutely. Um so getting back to the CEO example, um I don't know if anyone uses Facebook still. I haven't used it for at least 10 years, but uh I think some people some people some of our target do. So um what what happens on Facebook as I understand as my a bit younger but not to not not Tik Tok age colleagues but a bit younger colleagues than me um tell me on on Facebook apparently when someone sends you friend a friend request you can see if you have any common friends. So that's a thing, right? Before trying to be invite someone big, the big fish, you befriend other people, right? And then you are John Hackerman from the Acme Corporation and the big boss sees oh okay, this guy already knows like 50% of my employees. So yeah, let's accept. So that's the building trust part. And then exploit of course, you get the person to to give you something that you that you want to get from them. Um so that's it for the uh that [laughter] that that's it for the lure you part. Let's get uh a bit closer. So social engineering attack types that can be done in person. Let's go through that uh real quick cuz we do have to be mindful of time. Uh impersonation, that is that is a big thing, right? Usually I don't know, 90 85 90% of the time you will be impersonating someone. You will will not be will not be yourself, right? Um we've had discussion with colleagues and with some customers about that. All right, so um coming in as as the hackers with a contract and then saying you know, give us stuff because our contract with the customers already say that they can give us all the stuff and we try not to do that. Well we we've never done that. So usually would impersonate uh someone else. You can you also can't just say you know, you're just a random guy. You have to be someone unless it's a specific example where you where you are in distress and need help from someone else. So speaking of so uh three areas, VIP, user, and tech. Uh VIPs are the scourge of IT security. Uh that includes uh C-levels in big corporations, and that includes network administrators and system administrators. Um many, many years ago, about 10 years ago, we were doing um fishing campaign. When we do fishing campaigns, we try to add something extra with consent of of of the signing party, of course. And what we did was we crafted an email in such a way that if you clicked on the link, it would exfiltrate your the hash your NTLM hash, the hash of your domain user. Right? So, and when doing debrief with the customer, we were happy for the customer, but a bit disappointed. We've heard that um you know, 10% of users clicked on our link. That was the data that we got. Uh but, the customer told that almost 30% of their employees reported the campaign. Right, which is great. That's they they've they've had had good training, apparently. But, um none of the 10% that clicked went through. We didn't get NTLM hashes from any one of them, except the system administrators, because they don't need an outgoing firewall. They're super smart, and you know, they know what they're doing, so they click, and we got The only hashes we got were were administrators, basically. And lucky us. Um Now, we can also pretend to be a user uh and call tech support. Now, I imagine even though this is a hacker camp, uh most of us need to Well, all of us need to eat something, so most of us need to work. Uh so, many of you work somewhere, probably in a corporation. Uh so, you can think about that that place for a second, right? How is How is your tech support? If you were to call them up on the phone and say, you know, you're locked out, what is the process to reset the password? Do you Do you need to really prove anything or not? And it depends. It really depends on the on the company. Uh back in the day, uh, in about around 2005, uh, one of I I I was locked out of from one of the banks, right? And they needed to reset my password. So, I called them up and they asked to know my ID, basically date of birth, right? Uh, my name, and the name I had before marriage. Never married. So, that's what I wanted wanted to know. And that's it. And they gave me a new password. All right, but that was That was like 20 years ago. So, I believe that some corporations which do not have such stringent security as banks still still do that stuff. Then we can pretend to be tech support as well. Now, users, they are sometimes helpless, sometimes they can be made to feel helpless, and then, you know, you call in as tech support and you say, you know, we we had this data breach and we really need to verify that, you know, you're you, and you know all the all the default scams, right? Please Please tell us your password or let's start with the username or whatever. And please do keep in mind this slide that we had here before. You don't need at every interaction, you don't need to get their password or or or get some sensitive files. For a social engineer, every piece of information is really important, even a username, right? Or how the usernames are made, what is the syntax of the default username. Or in some companies, I know it's still it's still a thing, uh, the default mask for the passwords, right? That's why you have password cracking tools where you can specify masks. Some Some system admins will just easily They have scripts or they're very OCD, which which can be a thing in IT, uh, and other other fields. They will just always create, you know, first letter of the person's name, first letter of the person's surname, four random digits, the year they were hired, right? And then all you have to guess is four random digits. But you have to know the the pattern, of course. Um, right. You can also appeal to authority. Uh, and this is this is where things become a bit more interesting. So, instead of, um, instead of calling someone up and saying, you know, please do something that is not allowed, something that is forbidden explicitly by your policy, by your security policy, you can you can kind of say, you know, that it's okay. Not just saying it's okay, but imagine this. So, let's say we did background research and we see the structure of the company and we see that this one person, let's let's call him Joe, is out sick this week, right? And we see that there's a coworker for Joe called Peter and there's a boss boss for Peter and Joe called Marie, right? And then someone would call Peter and pretend to be Joe saying, you know, you know, I'm out sick today. Yeah, voice changer maybe, maybe not, maybe just low quality connection. You know, I'm out sick today, but Marie really she really needs me to to to do this one one small thing, but you know, I cannot access my files from from outside, right? And Peter being a well-educated employee would say, no, no, no. No way. This is against policy. And then the attacker would say, you know, yeah, but Marie called me and I said the same thing to her. I'm totally with you here, Peter, but she said, you know, it's okay. She's going to take all the blame if anything goes south. And then Peter then Peter will be, of course, oh, yeah, sure. Not my problem, you know, Marie is taking the blame, right? No one has talked to her, of course. Reverse social engineering. Now, as a social engineer, I believe that the most the hardest thing that you are up against when you are doing social engineering isn't how smart the person is or how vigilant they are, but it is their other stuff that they need to be doing, their time, their their attention. You know, so, you're sitting at your computer programming or, you know, vibing with a lamb, I don't know what what people do these days at computers or reading reading Mastodon and someone someone calls you up or sends you an email. Why would you bother to invest your time in that? That is that is the biggest biggest problem for a social engineer. So, reverse social engineering flips it on its head and and allows you to to solve this thing. So, it basically puts the victim we call the specific victim, not a company, but the physical person in company the mark. That is the the term. So, we call it the mark. So, it puts the mark in a position where they think they need help. And one one of the ones way to do it, let's say you already have physical access to the premises or you have someone with physical access to the premises and you can plant advertisements saying that, you know, IT support phone number has changed or it will change in a week and leave them there for a couple days. And then have the same accomplice, you know, unplug a cable somewhere. And wait for the call, right? And at that point, the mark is, you know, not only on your side, they're the one that needs something from you. And they will do anything, right? If you tell them that, you know, the pin eight on their RJ45 will not work until they change their password and you you need their old password, they're going to be fine with that. Absolutely, as long as you know, the pin starts working. Um access, how to access stuff. So, tailgating and piggybacking, close terms, academically there are a difference. Um So, both things mean getting into a restricted zone, may it be inside a building or the building perimeter or the building or the perimeter outside Um so, tailgating means that you just go with someone, right? And person doesn't necessarily notice you or or at least they pretend not to notice you. And a piggybacking means that they are your accomplice, but they are your accomplice on the spot. So, you haven't agreed agreed to anything, but, you know, they just let you in. Um so, for tailgating, the best times are where any ideas what's the best time of the day to do tailgating? Yes. >> Um smoke breaks. >> Smoke breaks, okay, yeah. I was going to say lunch breaks, but smoke breaks, yes, if they if there is not an internal smoking area and and the company is evil enough to have specific times when everyone goes to smoke, >> [laughter] >> then yes. But lunch breaks is usually a more traditional one where where, you know, the companies usually do say, you know, 12:00 or 1:00 p.m. is is when you go to lunch and everyone is coming back in, you know? And how many people who do have a badge here in the audience, you know, and live the corporate life would actually going in with your buddies after lunch with your colleagues or buddies after lunch would turn it down, close the door and say, "No. Now now you put your badge after the door." No one would do that, right? So, you know, you just the last or second to last in the queue there and and you're in. That's tailgating, right? Piggybacking is different thing. So, piggybacking means getting the someone to help you, as I as I mentioned before. A good example is what um what colleague, well, not really a colleague, but, you know, fellow social engineer in US did. So, he he's running a social engineering company, specifically social engineering company and physical red teaming company. So, not as not as wide what what as us, but more more focused. And what he told me that they have is they have a fake pregnancy bellies that they put on a female employee. They send the female employee to Starbucks to get like eight or 10 coffees or 12 coffees, right, in both hands. And, you know, and then then she arrives at at the outside door of the perimeter. And usually let in. One more thing that needs to be added here is of course access cards. When doing social engineering, access cards rarely need to be copied electronically. It's enough to copy it visually, right? So, if if if in that example this employee, this attacker's employee would have an access card, a badge that has the right design, most likely no one would would try to beep the badge. They I have to look at look at the person and and and and buzz buzz her in in this case. So, that's piggybacking. Uh yeah, speaking of speaking of cards, so key duplication. Uh key duplication um there are mechanical keys, there are digital keys. It is quite easy to uh read a mechanical key. Is anyone surprised by that? So, mechanical keys are very easy to read, right? That's why we always train customers not to leave their keychains by the window, right? Cuz the camera and then you just just decode it. Uh the standard standard key used throughout most of Europe are five positions by by 10 levels. So, so that's five to the power of 10 combinations, but we're not brute-forcing it. We just have to visually understand a five five-digit number. That's my five-digit number from the physical key. Uh but it is uh slow and relatively loud or relatively slow and very loud to to make a physical key, right? Uh it's the opposite for digital keys. For digital keys, it's usually it's sometimes a problem to read them, but as when when you read them, then you can easily duplicate it in less than a second and with absolute no noise. And now for acquisition. For acquisition, eavesdropping. Um best time for that? I'm not talking, of course, about the stuff NSA does. Uh I'm talking about uh at least where I come from uh in Latvia, eavesdropping on on the phone like between two people two unconsenting people talking is highly legal. Uh but there is the form of eavesdropping that is absolutely unregulated, which is, you know, just sitting around at a cafe. Um so, what's the best time to do that? What do you think? >> Lunch. >> Lunch? Okay. Oh, yeah. Yeah? >> After-work beers. >> After-work beers, yes. That was what I was going at, yes. So, Friday, you know, just as the work ends, uh people don't want to talk about work, but they usually take like 10 10 to 30 minutes to to unwind by talking by talking about work if it's their colleagues, right? So, if if a set of colleagues were to go out for for beers on Friday evening, then then the first minutes are are where you want to be. That's eavesdropping. Shoulder surfing, yeah, if anyone is like sitting on the phone right now, please be aware that people behind you can see your screen and they can also see your keyboard. And even if it were a laptop, they can still see your keyboard. I imagine at a hacker camp there may be other people that can read keyboards. My reading speed is about 30 35 words per minute. So, if you type faster than that, I cannot read what you're typing. Of course, if you're typing on a screen and it's visual then visible then it's another thing. Then it's super easy. So, keep that into account. And dumpster diving, finally. What it says, right? Many nice dumpsters out there, you can go dive into them and see maybe some data. Some data is there. We found a lot. We found documents, we found hard drives, we found whole PCs being thrown out in the dumpster, right? And they do have have hard drives and SSDs in them. Um right. So, remote social engineering attack types. Uh phishing and spear phishing, so untargeted and targeted, right? Just just sending sending fake stuff and and seeing if you fall for that like a dumb fish. Vishing, so fishing over voice. Basically, that means using either standard GSM or VoIP. App app impersonation, not as big a thing as it was before, but basically we create a fake app and the target installs it. Uh we don't we don't really use it in our test because that would require consent from like everybody because app stores are public. There are private app stores or private ways for companies to deliver internal apps so that can be used, of course, in tests like that. And there are a bunch of other types. So, really really many of them. Delivery vehicles are a bit more interesting. So, I already mentioned a bunch of them, right? I mentioned emails, of course. So, emails, remember that's that's the most I mean, I I think I get I get maybe like 50 50 emails per day trying to trying to fish me, but that's because I I configured my own email server 30 years ago and and I don't have a an antivirus or spam filter on it. You know, I just love to read what what people want to want to tell me. Um I do use some some funky RFC hacks to to make spammers life harder, but still about 50 per day make it through. Post, meaning like snail mail, right? Um maybe maybe that hasn't happened in a while. Anyone remembers the first ever malware? It was US. Any ideas? I don't I forgot the year. It was '80s or before. >> Morris worm. >> Uh what worm? >> Morris. >> Morris worm. I think that was way before that. >> [clears throat] >> Way before. >> Uh yes. >> I love you email. >> I love you email. Oh, that's that's like 2000s, I think, right? No, no, no. Uh I'm I'm talking about it here. It was done via post. >> [laughter] >> Yes. So, um and there's an article on Wikipedia. You can look it up, all right? In this these LLM sad LLM times, at least Wikipedia is safe for now. So, you know, you can go there and and learn the truth. So, um a researcher created um an expert system. An expert system is what we had before LLMs, right? It's like a It's like a database um that and it's actually useful. Many In medical field, it's used a lot. So, a doctor cannot remember all the potential connections between all the diagnoses and and the symptoms and what else whatever else they have there. So, an expert system is a system where someone can type in some facts and then deterministically, based on a database of connections, it will provide uh you with a visual representation of uh probabilities for specific outcomes, right? Which would in this in this example would be uh different different illnesses. Now, so um uh an expert made an expert system, a very very dumb one, a very small one, which um indicated to the user what what their risk of contracting an STD is, depending on some questions that they answered. So, very really I'm even I'm even ashamed that I mentioned an expert system here right now. This is It was like 10 questions, I think. And shipped this out to different medical professionals uh over post on a diskette, on a floppy drive, uh floppy disk. And uh so far so good. Free stuff, right? License was attached. No one read the license. That hasn't changed in in like 50 years. No one still reads licenses. Um you you plug it in the computer, you play with it, it works, everything is good. Um the app would embed itself not in the boot sector, I believe, but in the uh boot system of of MS-DOS. Um and it would count the times the computer started. Now, when the computer had been started many times, uh assuming multiple days have passed uh since installation or first use of this application, um a warning would appear saying, you know, "Hey, by the way, you haven't paid uh your license fee. You should either you uh delete the program or or pay up." And couple days later or couple boots later, it would stop the computer would stop working. It would say, "Uh you haven't paid. Sorry, now you got to pay." So, and I mean, the first time I learned about this when I was when I was first learning IT about 20 25 years ago, uh I thought, "Hmm, that's an interesting business model." But, you know, it's a business model. You had a license. Uh I'm not a lawyer, but you have a license and and you set it and, you know, it's all fine. Uh but, Wikipedia article these days does state that the guy was either arrested or prosecuted or or convicted. So, not not not a good business model apparently. Uh um So first malware ever post. Now I haven't seen any malware deliveries outside of hacker conferences over post in in many many years. Yeah. Phone calls of course I mentioned that as well. Um How many of you have heard of not really trusting the phone number that you see when the phone is coming in the phone call is coming in? Not everybody. Okay, but 80% okay. Yeah, you cannot trust that stuff. It's it's it's complete completely bogus. You can just change it like that. Um what about what about messages? So the question about SMS is as follows. Let's say you you have a chat with you know an an older person in your in your life. Let's say a mother. I chat with your mother on your phone and it's legitimate chat. Do you think how many of you think it is not possible for an attacker without hacking your phone just by sending message it is not possible for an attacker just to add a message to the same conversation. One, two, three, four. Uh Depends on the app. I'm talking about SMS. >> [laughter] >> Yeah yeah yeah. Okay, so we had about four five hands up. Yeah, it's it's SMS. Yeah, so basically what what happens is an attacker can specify any any source number source SMS ID as the end for for the messages they send and your phone will look at the message as the end it will match your address book and will add it straight to the same chat. Very fun attack. So but that's that's of course SMS. That's not a phone call. USB drops. Those had gotten very ineffective recently. So you know you can just drop some USB flashes outside on wow, I have like that many slides to go. Jesus. Let's see what we can do about that. So Uh, you can just drop drop flashes uh, let's say in a parking lot. So, that's one thing you can do. It's not effective anymore. So, what we did, uh, like we started like six, seven years ago, we started printing logos on the flashes. On the flash drives. These are customer's logo or or customer's customer's logo. Uh, but that also doesn't work anymore. And then, in one hacker conference about 2 years ago, someone told said to me, "You know what we do? We put flashes in pockets of their overcoats." And now it works again. Uh, so yeah. USB drops. Um, yeah, instant message SMS, two different two different things technically, but from social engineering perspective, same stuff. Uh, of course, harder to fake the source of an instant message. Uh, social networks as well. Uh, Facebook, Mastodon, whatever whatever else is happening. I'm so happy that Mastodon has been so far fighting off all the spam and bots, but I don't think it's going to survive, but uh, I I really hope it will. Uh, yeah, traffic injection. Uh, now we spend a lot of a lot of time and money, uh, as a society to do HTTPS. HTTPS has, uh, saved us all. Uh, at the same time, we have this hotspot stuff. When you have like a free Wi-Fi, you connect and then there's an insecure page asking you to enter your credit card details or just click okay or whatever. And browsers have to accommodate that. So, that's a that's a good spot for traffic injection when, uh, victim first connects to your Wi-Fi. And of course, malware network as well be used to, uh, inject social engineering attacks. Uh, I'm going to even though I I know that I have no time at all, I really need want to tell this story here. So, we had we had this, um, this malware in Latvia, um, many, many years ago. And, the category of malware was, um, Basically, it was trying to, uh, it was extortion extortion malware. What that's the category. Now, these days, many, many younger people and and other other experts, they just, uh, draw an equivalent sign between extortion malware and cryptolocker. And those are different things. And now you don't have to encrypt anything to extort money from a user, and you don't have to extort money to encrypt anything. Now, this example of the latter one is, of course, NotPetya, the malware created by the Russian special services to attack Ukraine health sector. It It was based on Petya, which was a real extortion cryptolocker, but theirs just didn't, you know, didn't allow to decrypt anything. They just wanted to damage stuff by pretending to be crypto cryptolocker for extortion. But finding an example that does extortion without encryption, anyone has any? But I don't want you to tell it, just, you know, if you know any. All right. Two two two people two people think they know, that's good, yeah. I also have one, so I'll tell I'll tell mine. So, back back in the day in Latvia, there was this this fancy malware. What it would do, it would pop up a screen, not even full screen, when you booted up your computer, and you could close it with an X, and it's gone. Until the next reboot, you're safe. You reboot again, again same window, you close it. That's it. It didn't do anything malicious, anything else malicious, anything other than the the window. Right? And people still fell for it. They still paid the money. Now, it worked in a very, very nice fashion. So, it had the some logos on it in the window. One of the logos was of the Latvian State Police, and the text went like, you know, "Hey, man, you know, we know that you have um or you you have um you do copyright infringement, you have unlicensed software on computer, and we kind of need to start criminal proceedings against you, but we're super super busy. So, let's help each other. Just go to this shop, buy this prepaid card, put the number in here, and we're done." Uh state police didn't take kindly to their logo being used that way. So, that was closed down. >> Okay. [clears throat] Components of a social engineer. Right. So, we we talked about um We talked about the technical well, relative technical stuff. Now, the the social uh stuff. I I determined that there are three things that you need to do. Uh one is confidence, right? Uh there's a term, an older English term, con man, uh which is short for confidence man. Um back in the day when you know con person was not considered as an option. Uh so, uh that basically means that uh it's it's a person who with their confidence tried tried to you know f- befuddle you. They they come up to you on the street say, you know, "Hey, can you change this 20 into 10 into two 10s?" Yeah, here, take this 50, hold that you there, and then you get then they get all the money, right? That's just one of the example examples of what con man could do. They could also on the street they could also do like the golden ring scam and and other things like that, right? But, uh confidence is is an important thing for social engineer. Uh you have to look, you have to appear as you know as you as you know what you're doing. Uh in multiple times when doing a physical test I've been in situations where I'm somewhere on in the customer premises and I'm not where I wanted to be specifically, so I have no idea where I am or where I'm going. At that point, there are couple things you can do, but none of none of these things include just you know just looking lost. Uh that will not work well, all right? Even if you're lost, you can you can go to someone and say you're lost, but then you have to have a good legend a good story behind you why you're lost. You then you're not an employee of that building, right? If you're lost. Um or you know, you just My go-to is you know, I just I just walk somewhere. Doesn't matter. I don't know where I'm walking, but I just walk somewhere with purpose. And if someone challenges, I'm I'm saying, "Sorry, I got I got I got run pee. I got to take a leak right now." And you know, I'm I'm fast. I'm moving. Toilet is probably like there are multiple toilets in big buildings. probably that way there is one. Uh one time one time I was still escorted to the toilet door and then out of the building, but um uh but usually they don't do that, you know. People people like to play nice. Um Right. And then you have have to be determined. So, you have to have determination about about what you're trying to achieve. Um Right. So, just just three components. Uh You have to be ready to be challenged, right? You can't You can't just just be You have to be on your feet, basically. Um there's a song by by a Latvian uh by a Latvian group, one of the popular ones, um Prāta vētra. I think that outlines this really really well. Now, it's in Latvian, but uh but but so the text uh um uh the text is like that. There is something to it by Brainstorm. Right. So, it means >> [clears throat and cough] >> um I reach out and got it all. Um according to my list, I was amazed. Man, that's something magical. Simply focus on what's important, put in little effort, and look, you've got it. So, that's kind of philosophy, um not only behind social engineering, behind, you know, achieving stuff in general. Um my my co-founder of the company uh also loves this this principle. I think he has it on his social profile. Now, for open-source intelligence, um I'm inclined to skip this. So, I'm just going to, you know, go over the slides like super quick. Maybe you won't even be able to read it. But basically, it means collecting intelligence or, you know, valuable information uh from openly available sources. That's what open-source intelligence is. Now, open OSINT sources include web and dark web, social networks, metadata, you know, the stuff that appears in files without you knowing, network and service scans, fingerprinting, um and what I can suggest dearly is osintframework.com. When you open it up, uh a tree will appear, or rather a tree will not appear. One two words will appear. And then you click on click on that and you can expand the mind map of, you know, different different ways to do OSINT. Really real cool resource if you if you want to learn about it or if you are wandering into new territory that you that you haven't done before. Now, for web, I have a couple of slides for that. Now, Google stopped working like a month ago. It's it's just a search The search is dead, basically. Uh but I I still included the slide here. So, you can of course do different different dorks and try to find stuff that is public that is not supposed to be in public, right? Um and then a bunch of other stuff. pastebin.com, uh online comments and news sites that might do something show something about the company. Uh now, different street view applications. Um I have two examples here. Um there are more, but it's important to have to understand that you you don't just go to one. You look at multiples because the coverage may be different, the angle may be different, and um also the date of data collection are different. So, you can get more information about what's happening there. Uh webcams, a bunch of those online without password. Uh web.archive.org, uh my heart goes out out to those guys. Uh they are doing uh amazing amazing stuff. Uh not only for OSINT, but, you know, for preserving whatever we had as a web back in the day. Um tinEye.com, I included this here just out of respect. This is the original uh reverse image searcher. There are many many tools that do that these days, including large language models, um that can help you understanding what you're up against. Uh blockchain.info, if you're doing something with um cryptocurrencies. Uh shodan.io, uh for network scans. There's also a censys.io, of course. Uh different leaks that you can use as well. Uh right. And uh there are different people search engines. Sing. me, I think it has survived outside of European Union. In EU, they got nerfed back in 2019, 1 year after GDPR came into force. Uh it's an amazing social engineering stunt, or rather a con man stunt, uh the Sing. me idea. Basically, no one no one likes anonymous phone calls. No one likes, you know, when someone is calling you up a phone number and you have no idea who you're going to be talking to, right? So, they have this amazing app that you can install on your phone, and they promise that instead of a anonymous phone number, they will almost always show you a person's name, even if they're not in your phone book. Uh because they have a huge database of phone numbers. And how does it work? Well, the user agreement basically says that if you install this app, you agree that your phone book is going to be uploaded up to our cloud and shared with everyone else. Um back in the day, you could also use the webpage Sing. me, and everybody was there. I tried it on multiple Latvian uh multiple presidents of Latvia. I tried in other important and high-profile people, and uh all of it's all it was in there. Alternatively, you can use Google Dork as well, of course. Uh different public registries, uh this is so-called deep web, right? It's not easily indexable, and it's not easily accessible to AI models, but you can go and uh go and look in specific registries for free, and usually without authorization. You can use online news as well. And this uh todington.com/resources is a list of links to different tools. So, that's amazing as well. Can recommend that. Um yeah, for uh social networks, there are different hacks you can use there. You can either register and and try to see what you can see, or my favorite is forget password uh feature. Usually, some kind of second factor identification leak is possible. Not not implying that you can access the account, but you can access some information about the person. Now, for Twitter, there was Nitter. Uh it got DMCA'd uh 3 days ago, so I don't know what's going to happen there. Uh Let's let's see. But you know, there's less and less interesting stuff there unless you want to unless you have customers in those kinds of people that that use that kind of service. Right. And to finish up OSINT, so inteltechniques.com, I forgot the name of the guy, but I do have a couple of books that he wrote. Very valuable tools, especially for social networks. Now, back in the day there were automated tools that you can just freely access on the webpage, type in your query and his script that he wrote would connect to the network and fetch info for you for free. These days most of those are just forms that create a query and directly send you to the specific social network. So, nothing goes through through him anymore. But still quite quite useful, right? Especially if if you're not an expert in specific social network. Now, for example, back in the day when Twitter was Twitter and it was owned by a slightly more palatable gentleman, I I I used it a lot. So, I know how you can do geo searches on Twitter, right? For example, if you if you're thinking, "Should I go to that concert that's happening tonight? Has it started yet?" What you can do is you geo fence all the tweets back in the day and see the pictures from the event right now and and see, you know, how far along the event is. But if you don't know how to do any of that for any of the networks or some of the networks, then you go there and and there's a list for you. Okay. [clears throat] Now, um back to the tactics. Pretext, you have to have pretext and you have to have it as a homework. Now, if you're really really good and you like adrenaline, you can just go in blank and you just you know, make stuff up as you go. Usually it it ends it it it doesn't end good. Right? Um Pretext includes but is not limited to this. So what's your role, right? Who you going to be playing? Um Make up a fake name, right? In countries where name days name days are a thing, that's that's a thing you should take into account. Uh when when is your name celebrated nationally? I've I've fallen for that once and and now I always always do that, you know, cuz you say, "Hey, I'm John." Oh, you you you you had your name day last week. And I yeah, maybe. Uh I don't know. So and of course it has to be it has to be reasonable. It it can't be it can't be too too crazy, right? And also what's your birthday? That's that's important for for various reasons, right? Specifically you can also feel more more in, right? You really feel like the person. You have to do that. Why are you doing this? What's your what's your goal? What you're trying to achieve, right? Uh you have to make sure that your role matches your goal. If you if you're trying to get into the CEO's CEO's office, maybe a janitor is a good is a good position, right? If you're if you're trying to get to the server room, maybe a prospect employee, someone who's applying for a job is not a good position at that company. They probably will not let you in the server room or even even if you try to sneak away, you know, you have to understand you can be challenged at any point. And then then that's not a good excuse to try to be getting into the server room, right? I I forgot my hat there. Actually used I actually used I forgot my hat as a as a way to try to get in last year into into customer's premises. That guard, even though he bought it, he was he was really well-trained. He kicked me up kicked me out twice during that engagement. Um we were we were playing cat and mouse. He had video cameras, so it wasn't wasn't fair. Um You have to convince yourself first. That's important, right? And that that adds up to the confidence part. If you don't believe that you are who you are, then no one else is going to believe you there. Uh and you have you can try challenging yourself, right? Imagine these scenarios, you know, a guard comes up. You know, are you are you just going to run or or or what's going to happen? I had um I had a situation once. So, I I got into into premises using uh fake ID card that looked okay, but was fake. And I was doing whatever I had to be doing. And then I noticed that someone is pointing me out to the guard. I noticed that from from from the distance. And at that point I had I thought I have like 10 20 seconds to think of what my tactic is going to be when the guard comes up to me. And uh should I I decided in those 10 20 seconds I decided in the first seconds I decided that I will not be showing my fake card to him. I will say that I lost my card. So, and that's that that's how I got I got I I got to stay there, right? I said I lost my card. I had my pretext, my identity. And the guard said, "Okay, right?" He seems he's high up. He's he's with the C-level. He's a assistant to C-level. He's fine. Even though he lost his card. Um yeah. Could have turned out differently, but uh you have to you have to go through the situations and and try to uh try to look for holes in your story. Uh Right. Let's Let's finish this up. I do have a bunch of slides. Let's just go through it. So, um some context. Everyone loves to help, right? Uh and people generally try to avoid conflict. And some people make consistently good decisions, but most people do not make good decisions, especially when they're rushed. Um So, there are some hard targets, the guards. I would necessarily avoid them first years when you're doing social engineering as a hobby or professionally. Uh those guys are trained to, you know, to not do stuff that you want that you want to be done. Right? Uh and the example is the hat. I even told the guy that I'm going to their C-level person. I had the name. I had I had a colleague of mine calling me on my phone at the same time as I'm with the guard. And I as he's calling, I turn the phone slowly so the guard can see the face and the name and the surname of of the C-level in the person. Uh and I think he bought that the person is calling me. But he was so well trained, he said, "No, that's that's that specific person trained me specifically to not not do that in any circumstances, right?" Uh but so those are the hard targets. Uh and people who are trained to work with external customers, all right? Let's say if you have a client that is a bank, uh you would you would usually choose a mark that is not the teller at the bank, right? Because they have processes, they know when to ask for ID, how to look for for bad IDs, right? But if you if you let's say if you were to call someone in the back back office, a manager, maybe um IT person, then they they don't know the process, you might be able to get in there. Uh right, so tell getting his hands full, I gave you that example already. Um if you are in for a long game, you can also wait for a good hair day and ask for a favor. Uh people love to help. Sometimes they're grumpy, sometimes they're not. You know, if they just had salary paid out, if if they just returned from vacation the first day, good times, they can, you know, help you out. Why not, right? Uh one thing that I love to do outside of engagements as well, well, I mean, I don't I don't enjoy that outside of engagements, but that I employ is uh hinting at creating conflict and providing an easy way to avoid it, right? Uh sometimes airlines and other corporations, they don't want to abide by their own contracts that they made. Uh so, what I sometimes say in the middle of the conversation, conversation if I see that my request is going nowhere, is, you know, um okay, okay, I understand you can't do that. Maybe you can provide me with your legal address so my lawyers can send a letter and we can start proceedings. Or maybe there's a senior associate available after all. And then then usually senior associate is available uh sometimes. Um all right. So, [clears throat] this is not the end of the presentation. I still have like uh 4 minutes. Um this is a whole subsection that I would not have been able to include here even if um I was speaking three times faster. Uh you can just go to the URL. Or if you trust me, you can scan the QR code. Um and uh it's a presentation on lobbying uh from a different conference about 10 years ago. And it basically uh it is relevant to social engineering uh to the part of building rapport and trust, all right, how you can um connect with people. All right, befriending employees and so on. Uh right, the exploiting part, all right, always keep the goal of this specific interaction in your mind. Once you achieve the goal, feel free to push a bit a bit further, right? Like I had my Wi-Fi Wi-Fi access point name, but I didn't have the password. Okay, let's let If you want to get the password, let's talk about the password, no problem, right? But don't ask for too much at the same time. You know, you for for when when your target is a company, you have many marks to choose from in that company. All right, practical exercises, the important part. Uh let's uh let's do let's do this, right? That's the first one. Uh yeah, [laughter] it's it's hard. Uh I know. I wasn't talking to anybody until uh grade four, right? So, at at 11 years old, someone convinced me to actually start talking to my classmates. So, it can be hard, but but you can do it, right? That's the first step. Uh another thing you can do is improve. Um you can apply for some info classes. They put you on the spot. They really really help you with getting out of situations when you if you get into them. Uh alternative personas, right? You can just going through your life, you can look at the situation that you're in and think, "Hm, how would how would this imaginary person act in this situation? Would they do anything differently?" Just think about it, right? Um And then you can pretend to be someone else with a story. Now, before a lemming it was more fun for other people as well. Now with a lemming it's not fun for them anymore cuz the lemmings do the same all the time, but you can pretend to be someone else, you know, just tell a story. Uh it's go on Reddit, create a create a fake account without trying to harm anybody. Just a fun story, yeah? As a storytelling exercise. Uh you can do it with your friends first, right? Don't do it with, you know, customers or or or or someone someone that you don't know and who don't trust you. Um yes, and the passive acquisition methods. Dig for some trash. That's a fun thing to do. Eavesdrop on nearby employees. Yeah, you you don't have to have a a customer or a mission, you know, just sit Friday evening, sit at the bar and and see what you can listen. You don't even have to write it down. Just see if you can and I think that will be really empowering. Uh shoulder surf, right? That's that's also a fun fun exercise. I I I stopped it quite quickly after I started because I felt uncomfortable with it. Uh but uh but but you you you can try that, yeah. Bumping into people, just lightly bumping into people. This is important for cloning RFID cards, right? Uh yeah. Okay. So, uh those are the passive acquisition methods that you can start with. Um I don't know if I have Yeah, let's let's uh Uh yeah. Build some pretexts. That's the final thing I want to I want to talk to you about. So, create a story in your head that might work with something, right? Doesn't have to be a real customer. Doesn't have to be anything real. Please don't go robbing robbing banks or anything without permission, right? But you can just just play it out. Imagine what happens. Look from your perspective, look from the other person's perspective, see who there is and what they might talk to you. What they what they might tell you. So, that is it for now. I don't think we have any time for questions, but I'm around the camp. If I get my deck working, you can reach me on 5522. If not, you know, just look for my face. I might change this later. And yeah, let's let's talk. I'll be here until tomorrow for sure. Thank you. >> [applause]