hackmas2026 - So you're interested in social engineering? The very first steps
Watch on YouTubeVideo summary
Kirill Solovyov, a security expert with fifteen years of experience, introduces the foundational steps for conducting social engineering attacks that primarily target organizations rather than individuals. He distinguishes these real-world tactics from "movie hacking," emphasizing that actual attacks often involve inspecting passwords over the phone or leveraging AI-assisted techniques within a linear progression of research, targeting, trust-building, and exploitation. The presentation outlines various attack vectors, including impersonating authority figures to bypass policies, reverse social engineering where victims feel compelled to seek help, and physical access methods like tailgating or using fake badges. Additional techniques cover acquiring keys through cameras, eavesdropping during distracted moments, dumpster diving for sensitive data, and remote attacks via phishing, vishing, or insecure Wi-Fi hotspots, while also noting historical contexts like malware delivered via postal mail.
A critical component of successful social engineering is the creation of a strong pretext, which involves crafting a believable fake identity with a consistent role, name, and goal that aligns with the target environment, such as a janitor who can access an office but not a server room. Solovyov stresses the importance of self-conviction in this persona to maintain confidence under pressure and advises avoiding hard targets like trained security guards in favor of individuals lacking specific protocols, such as back-office IT staff or bank managers. To succeed, attackers must leverage the natural desire of people to help and avoid conflict by threatening legal action if requests are denied, while also utilizing Open-Source Intelligence (OSINT) tools like Google Dorks, Wayback Machine, and Shodan to gather background information on targets before engaging them.
Practical preparation involves mental simulation of scenarios from both the attacker's and target's perspectives, practicing alternative personas, and building pretexts through storytelling exercises. The speaker highlights that while automated OSINT tools have evolved, manual geo-searches remain useful for verifying events, and emphasizes that confidence, determination, and readiness for challenges are essential traits for any social engineer. Ultimately, the goal is to move with purpose even when facing obstacles, understanding that success with one target enables moving to another in a continuous cycle of reconnaissance and execution.
Read the full video transcript
Hello everybody. This is going to be in
English. I don't speak German that well.
Uh thank you so much for coming in to my
talk.
So,
uh my name is Kirill Solovyov and uh
I have been running a security company.
Like we hack people and companies,
mostly companies, professionally. Uh
that includes some social engineering as
well. So, I have been doing that for
well, 15 years that that I've been
I've been with the company.
Um this presentation is the very first
steps for social engineering. Anyone
here has done it professionally before?
No one. Unprofessionally? As a hobby?
Yeah, okay.
Uh five people, good. Yeah. Uh so,
that's basically what we're going to go
through here in this talk. Um I will try
to give you both the theory, some
examples from my experience, and if we
do have the time, I'll try to leave you
with some exercises that you can do
in your life without harming others to
to try and uh
improve your skills.
>> [clears throat]
>> So, this is um SMBC, Saturday Mornings
Breakfast Cereal, one of one of the
comics that I that I frequent. Uh some
of you may have seen it.
So, here's uh you know, the
We had we had a joke uh with a friend
many, many years ago that, you know, you
have to you have to sniff the jaws on
port 53 and then you can get access to
the super root. Uh so, this is this is
kind of movie hacking, right? And uh the
second panel of the comic is is is real
hacking, you know, you have a Robert
Hackerman that just, you know, inspects
your password over the phone. And uh
that's where the future lies in, I
believe. Um
the new AI things will also try to do
social engineering. Yeah, they may help
social engineer, but I think we are
many, many years away
uh from them physically walking up to
you and trying to social social engineer
you. Now, the doing it through the phone
is a different thing. That might happen.
So,
uh that's the agenda for today. Quite a
lot of stuff here.
Uh about eight eight different things to
go through. So, let's let's get on with
it.
Um who has worked with cyber kill chain
before? Anybody?
One, two, two people professionally
working, I imagine. Uh so, Lockheed
Martin created the cyber kill chain. Uh
it's basically seven steps that bad guys
do uh when they try to attack your
company, that they go through. Um
I personally apply it um in red teaming.
When you want to simulate the attack,
then what you do is
you try and follow the steps of the bad
guys.
Now,
social engineering usually usually
comes in reconnaissance phase. Sometimes
sometimes you use it in phase three as
well when you do delivery, right? But
it's mostly
it's mostly applicable in in the
reconnaissance phase, right? That's when
you try to understand
uh what the company is, what is the
employee structure, if someone is in
vacation, maybe what what are the server
names and so on, you know, the basic
basic stuff. So, we going to do we we
will have a small chapter on OSINT here
as well.
So, what is social engineering, right?
That's the academic
academic way to say it, but basically I
love to define it as it's getting
someone to do what they're not supposed
to do
or getting someone to say something that
they are supposed
to keep secret.
Um so, that's the attack cycle. It
applies to organizations. Um I will try
not to talk about hacking individuals,
right? That's rarely can be used
professionally, uh except I don't know
if you're part of secret service, you
might you might want to hack a high high
value target, I imagine. But other than
that, usually uh you apply social
engineering with the master goal of
hacking an organization. So, for an
organization, you have this cycle which
you cannot have if you're hacking
individual. You do research, you target
a person, you build trust, and then you
exploit that trust.
Now, what does it mean and why is it a
cycle? And my personal pet peeve, I've
done bunch of certifications
like you know, the the the fake ones
that they that exist in the corporate
world world, not because I want to
because my customers want me to teach
them, so I have to do them. And my pet
peeve is
unnecessary cyclic graphs, you know,
where you know, they're just four steps,
let's say, and they're connected with a
force arrows well. This is not
necessary, this is necessary. So, the
goal here is, you know, once you're done
with this first person, you go move
forward to the second person. Let me
give an example here. Let's say I called
you up on the phone.
And
I asked very very nicely, "Hey, so
listen, can you give me the server
name?"
And anyone would would give me the
server name of your company?
No one would, right?
But
imagine I called you up and I had some
background info.
I could call myself
in the name of one of your colleagues.
I would know what the company name is, I
would know the address, I would know
what floor you're in, maybe I would know
the name of the computer you're sitting
at.
I would know a lot of background
information. And if I were to project
that knowledge onto you that I have that
that I do have that knowledge already,
and then I would ask a question, it
would be more
in line with where we are in the
conversations. It wouldn't just be out
of out of the blue. And believe it or
not, sometimes with some people you can
even build build this cycle in such a
way that you can even ask them for
for a password.
Now, a year or two ago,
I I was lucky enough to participate in
the social engineering engineering
village in a Canadian conference called
HackFest.
And
we do we do social engineering calls
there. So, you call up someone and and
you try to get flags, right? When is the
water delivered? Where are the video
cameras? Where are the security cameras?
Uh what's what kind of operating systems
do you use, right? So, all those are all
the flags and you have to get them over
the phone.
And
the fun part was
I enjoy what I enjoyed the most was the
I think it was called social engineering
at night. It was it's a French
conference, so it was
Le Le Nuit or something like that. Um
and it's a bit different. You only get
three flags. You need to
know their Wi-Fi access point name.
You need to
know their opening times. And you need
to know who you're calling because the
the joke with the social engineering at
night is that the organizers call
someone up for you and you don't know
who who you're talking to. You have no
idea what kind of company that is.
Uh usually it's it's a hotel or a
conference center.
Um so
and I I mean I grabbed all I grabbed all
three flags. I you know, I was I was
calling up I'm saying saying, you know,
this is Josh with a Quebec Special
Services. We have a special guest coming
in VIP.
Uh we need to clear out the place, you
know, reserve everything you have.
And I mean I got all three flags, but it
turned out it was a toy store.
Uh and it was really awkward when I was
saying, you know, we're going to have a
party of 20 people coming in. There's
going to be 20 local uh
local females attending as well, you
know, and all that and and toy store,
you know. This thing that thing.
>> [laughter]
>> But uh I got cut off by by the
organizers because the very helpful very
nice person on the other end were ready
to give me the Wi-Fi password. I was
like, okay, so Wi-Fi name is this, but
you know what And and she was, yeah, and
the password is, you know, in case you
need it and
or you can't you can't do that, so I was
cut off. So, in that case,
uh because um the target was so easy and
so narrow, only three things, I was able
to do that with a single person. But
what you usually do is you would build
this you would go through the thing with
a single person, single employee for
company, and then you move forward uh to
the
to the next template.
Um so, I'm going to
I'm going to talk about some of the
things here.
Research. Uh research mean meaning
either you already come in with
something from from the previous stage
here
and then you
add on something that you may find
otherwise. Or if it's the first time you
do it, you do your research, you know.
And we're going to talk about all the
methods, uh well, the basic methods, the
simple stuff here in the presentation
um in in the next slides as well.
>> [clears throat]
>> And then targeting. So, targeting means
you select someone.
Uh so, let's say I want to
I want the CEO of a large corporation to
believe that uh
that, you know, I'm one of them.
I wouldn't necessarily target well, I
would necessarily not target
the CEO initially, all right? Because I
have nothing. I don't have I don't have
a I don't have a background. I don't
have a good legend. I can't really
can't really convince them of anything.
Uh so, I target someone else, right? Uh
and then I build trust with them. Now,
how long do you think you can just shout
uh how long do you think does the
building trust phase last uh
for a single person?
Any ideas? Any versions?
Yeah.
A month? Okay. Other options?
Yeah?
>> Three months.
>> Three months?
>> A minute.
>> A minute?
>> [laughter]
>> Okay. Yeah, good. That That's That
That's good, right? Because um
when we talk about social engineering
outside of organizations, right?
Individual social engineering, uh
phishing emails is a is a great example,
all right? And
those guys, they don't necessarily
demand money immediately from you, but
they they kind of, you know, they want
to build initial trust in a single
email. So, it is possible, let's say
during a phone call to try and build
build trust in a couple minutes,
absolutely. Uh but it's also three
months was the longest as you mentioned.
It's also possible to be building trust
for for months and years. Absolutely.
Um so getting back to the CEO example,
um I don't know if anyone uses Facebook
still. I haven't used it for at least 10
years, but uh I think some people some
people some of our target do. So
um what what happens on Facebook as I
understand as my a bit younger but not
to not not Tik Tok age colleagues but a
bit younger colleagues than me
um tell me on on Facebook apparently
when someone sends you friend a friend
request you can see if you have any
common friends. So that's a thing,
right? Before trying to be invite
someone big, the big fish, you befriend
other people, right? And then you are
John Hackerman from the Acme Corporation
and the big boss sees oh okay, this guy
already knows like 50% of my employees.
So yeah, let's accept.
So that's the building trust part. And
then exploit of course, you get the
person to to give you something that you
that you want to get from them. Um so
that's it for the
uh that [laughter]
that that's it for the lure you part.
Let's get uh a bit closer. So social
engineering attack types that can be
done in person. Let's go through that uh
real quick cuz we do have to be mindful
of time.
Uh impersonation, that is that is a big
thing, right? Usually
I don't know, 90 85 90% of the time you
will be impersonating someone. You will
will not be will not be yourself, right?
Um
we've had discussion with colleagues and
with some customers about that.
All right, so um coming in as as the
hackers with a contract and then saying
you know, give us stuff because our
contract with the customers already say
that they can give us all the stuff and
we try not to do that. Well we we've
never done that.
So usually would impersonate uh someone
else. You can you also can't just say
you know, you're just a random guy. You
have to be
someone unless it's a specific example
where you where you are in distress and
need help from someone else. So speaking
of so uh three areas, VIP, user, and
tech. Uh VIPs are the scourge of IT
security. Uh that includes uh
C-levels in big corporations, and that
includes network administrators and
system administrators.
Um many, many years ago, about 10 years
ago, we were doing um
fishing campaign. When we do fishing
campaigns, we try to add something extra
with consent of of of the signing party,
of course. And what we did was we
crafted an email in such a way that if
you clicked on the link, it would
exfiltrate your the hash your NTLM hash,
the hash of your domain user. Right? So,
and when doing debrief with the
customer,
we were happy for the customer, but a
bit disappointed. We've heard that um
you know,
10% of users clicked on our link. That
was the data that we got.
Uh but, the customer told that almost
30% of their employees reported the
campaign. Right, which is great. That's
they they've they've had had good
training, apparently.
But, um none of the 10% that clicked
went through. We didn't get NTLM hashes
from any one of them, except
the system administrators, because they
don't need an outgoing firewall. They're
super smart, and you know, they know
what they're doing, so they click, and
we got The only hashes we got were were
administrators, basically. And lucky us.
Um
Now, we can also pretend to be a user
uh and call tech support.
Now, I imagine even though this is a
hacker camp, uh most of us need to Well,
all of us need to eat something, so most
of us need to work. Uh so, many of you
work somewhere, probably in a
corporation. Uh so, you can think about
that that place for a second, right? How
is How is your tech support? If you were
to call them up on the phone
and say, you know, you're locked out,
what is the process to reset the
password? Do you Do you need to really
prove anything or not? And it depends.
It really depends on the
on the company.
Uh back in the day, uh, in about around
2005,
uh, one of I I I was locked out of from
one of the banks, right? And they needed
to reset my password. So, I called them
up and they asked to know my
ID, basically date of birth, right?
Uh, my name,
and the name I had before marriage.
Never married. So, that's what I wanted
wanted to know.
And that's it. And they gave me a new
password. All right, but that was That
was like 20 years ago. So, I believe
that some corporations which do not have
such stringent security as banks still
still do that stuff. Then we can pretend
to be tech support as well. Now, users,
they are sometimes helpless, sometimes
they can be made to feel helpless, and
then, you know, you call in as tech
support and you say, you know, we we had
this data breach and we really need to
verify that, you know, you're you, and
you know all the all the default scams,
right? Please Please tell us your
password or let's start with the
username or whatever. And please do keep
in mind this slide that we had here
before.
You don't need at every interaction, you
don't need to get their password or or
or get some sensitive files. For a
social engineer, every piece of
information is really important, even
a username, right? Or how the usernames
are made, what is the syntax of the
default username. Or in some companies,
I know it's still it's still a thing,
uh, the default mask for the passwords,
right? That's why you have password
cracking tools where you can specify
masks. Some Some system admins will just
easily They have scripts or they're very
OCD, which which can be a thing in IT,
uh, and other other fields.
They will just always create, you know,
first letter of the person's name, first
letter of the person's surname, four
random digits, the year they were hired,
right? And then all you have to guess is
four random digits. But you have to know
the the pattern, of course.
Um, right. You can also appeal to
authority. Uh, and this is this is where
things become a bit more interesting.
So, instead of, um,
instead of calling someone up and
saying, you know,
please do something that is not allowed,
something that is forbidden explicitly
by
your policy, by your security policy,
you can you can kind of say, you know,
that it's okay. Not just saying it's
okay, but imagine this. So, let's say we
did background research and we see the
structure of the company and we see that
this one person, let's let's call him
Joe, is out sick this week, right? And
we see that there's a coworker for Joe
called Peter and there's a boss boss for
Peter and Joe called Marie, right? And
then
someone would call
Peter and pretend to be Joe saying, you
know, you know, I'm out sick today.
Yeah, voice changer maybe, maybe not,
maybe just low quality connection. You
know, I'm out sick today, but Marie
really she really needs me to to to do
this one one small thing, but you know,
I cannot access my files from from
outside, right? And Peter being a
well-educated employee would say, no,
no, no. No way. This is against policy.
And then the attacker would say, you
know, yeah, but Marie called me and I
said the same thing to her. I'm totally
with you here, Peter, but she said, you
know, it's okay. She's going to take all
the blame if anything goes south.
And then Peter then Peter will be, of
course, oh, yeah, sure. Not my problem,
you know, Marie is taking the blame,
right? No one has talked to her, of
course.
Reverse social engineering.
Now, as a social engineer, I believe
that the most the hardest thing that you
are up against when you are
doing social engineering isn't how smart
the person is or how vigilant they are,
but it is their other stuff that they
need to be doing, their time, their
their attention. You know, so, you're
sitting at your computer programming or,
you know, vibing with a lamb, I don't
know what what people do these days at
computers or reading reading Mastodon
and someone someone calls you up or
sends you an email. Why would you bother
to invest your time in that? That is
that is the biggest biggest problem for
a social engineer.
So,
reverse social engineering flips it on
its head and and allows you to to solve
this thing. So,
it basically puts the victim we call the
specific victim, not a company, but the
physical person in company the mark.
That is the the term. So, we call it the
mark. So,
it puts the mark in a position where
they think they need help.
And one one of the ones way to do it,
let's say you already have physical
access to the premises or you have
someone with physical access to the
premises and you can plant
advertisements saying that, you know, IT
support phone number has changed or it
will change in a week and leave them
there for a couple days.
And then have the same accomplice, you
know, unplug a cable somewhere.
And wait for the call, right? And at
that point,
the mark is, you know,
not only on your side,
they're the one that needs something
from you. And they will do anything,
right? If you tell them that, you know,
the pin eight on their RJ45 will not
work until they change their password
and you you need their old password,
they're going to be fine with that.
Absolutely, as long as you know, the pin
starts working. Um access, how to access
stuff. So, tailgating and piggybacking,
close terms, academically there are a
difference. Um
So, both things mean getting into a
restricted zone, may it be
inside a building or the building
perimeter or the building or the
perimeter outside
Um so, tailgating means that you just go
with someone, right? And person doesn't
necessarily notice you or or at least
they pretend not to notice you. And a
piggybacking means that they
are your
accomplice, but they are your accomplice
on the spot. So, you haven't agreed
agreed to anything, but, you know, they
just let you in.
Um so, for tailgating,
the best times are where any ideas
what's the best time of the day to do
tailgating? Yes.
>> Um smoke breaks.
>> Smoke breaks, okay, yeah. I was going to
say lunch breaks, but smoke breaks, yes,
if they if there is not an internal
smoking area and and the company is evil
enough to have specific times when
everyone goes to smoke,
>> [laughter]
>> then yes. But lunch breaks is usually a
more traditional one where
where, you know, the companies usually
do say, you know, 12:00 or 1:00 p.m. is
is when you go to lunch and everyone is
coming back in, you know? And how many
people who do have a badge here in the
audience, you know, and live the
corporate life would actually going in
with your buddies after lunch with your
colleagues or buddies after lunch would
turn it down, close the door and say,
"No. Now now you put your badge after
the door."
No one would do that, right? So, you
know, you just the last or second to
last
in the queue there and and you're in.
That's tailgating, right? Piggybacking
is different thing. So,
piggybacking means getting the someone
to help you, as I as I mentioned before.
A good example is what um
what colleague, well, not really a
colleague, but, you know,
fellow social engineer in US did. So, he
he's running a social engineering
company, specifically social engineering
company and physical red teaming
company. So, not as not as wide what
what as us, but more more focused. And
what he told me that they have is they
have a fake pregnancy bellies that they
put on a female employee. They send the
female employee to Starbucks to get like
eight or
10 coffees or 12 coffees, right, in both
hands. And, you know, and then then she
arrives
at
at the outside door of the perimeter.
And
usually let in. One more thing that
needs to be added here is of course
access cards.
When doing social engineering, access
cards rarely need to be copied
electronically. It's enough to copy it
visually, right? So, if if if in that
example this employee, this attacker's
employee would have an access card, a
badge that has the right design,
most likely no one would would try to
beep the badge. They I have to look at
look at the person and and and and buzz
buzz her in in this case. So, that's
piggybacking.
Uh yeah, speaking of speaking of cards,
so key duplication.
Uh key duplication um there are
mechanical keys, there are digital keys.
It is quite easy to
uh read a mechanical key.
Is anyone surprised by that? So,
mechanical keys are very easy to read,
right? That's why we always train
customers not to leave their keychains
by the window, right? Cuz the camera and
then you just just decode it. Uh the
standard standard key used throughout
most of Europe are five positions by by
10 levels. So,
so that's five to the power of 10
combinations, but we're not
brute-forcing it. We just have to
visually understand a five five-digit
number. That's my five-digit number from
the physical key. Uh but it is uh slow
and relatively loud or relatively slow
and very loud to to make a physical key,
right? Uh it's the opposite for digital
keys. For digital keys, it's usually
it's sometimes a problem to read them,
but as when when you read them, then you
can easily duplicate it in less than a
second and with absolute no noise.
And now for acquisition. For
acquisition, eavesdropping. Um
best time for that?
I'm not talking, of course, about the
stuff NSA does. Uh I'm talking about uh
at least where I come from uh in Latvia,
eavesdropping on on the phone like
between two people two unconsenting
people talking is highly legal. Uh but
there is the form of eavesdropping that
is absolutely unregulated, which is, you
know, just sitting around at a cafe.
Um so, what's the best time to do that?
What do you think?
>> Lunch.
>> Lunch? Okay. Oh, yeah.
Yeah?
>> After-work beers.
>> After-work beers, yes. That was what I
was going at, yes. So, Friday, you know,
just as the work ends, uh people don't
want to talk about work, but they
usually take like 10 10 to 30 minutes to
to unwind by talking by talking about
work if it's their colleagues, right?
So, if if a set of colleagues were to go
out for for beers on Friday evening,
then then the first minutes are are
where you want to be. That's
eavesdropping. Shoulder surfing, yeah,
if anyone is like sitting on the phone
right now, please be aware that people
behind you can see your screen
and they can also see your keyboard. And
even if it were a laptop, they can still
see your keyboard.
I imagine at a hacker camp there may be
other people that can read keyboards. My
reading speed is about 30 35 words per
minute. So, if you type faster than
that, I cannot read what you're typing.
Of course, if you're typing on a screen
and it's visual then visible then it's
another thing. Then it's super easy. So,
keep that into account. And dumpster
diving, finally.
What it says, right? Many nice dumpsters
out there, you can go dive into them and
see maybe some data. Some data is there.
We found a lot. We found documents, we
found hard drives, we found whole PCs
being thrown out in the dumpster, right?
And they do have have hard drives and
SSDs
in them.
Um right. So,
remote social engineering attack types.
Uh phishing and spear phishing, so
untargeted and targeted, right? Just
just sending sending fake stuff and and
seeing if you fall for that like a dumb
fish.
Vishing, so fishing over voice.
Basically, that means using either
standard GSM or VoIP.
App app impersonation, not as big a
thing as it was before,
but basically we create a fake app and
the target installs it.
Uh we don't we don't really use it in
our test because that would require
consent from like everybody because app
stores are public. There are private app
stores or private ways for companies to
deliver internal apps so that can be
used, of course, in tests like that. And
there are a bunch of other types. So,
really really many of them. Delivery
vehicles are a bit more interesting. So,
I already mentioned a bunch of them,
right? I mentioned emails, of course.
So, emails, remember that's that's the
most I mean, I I think I get I get maybe
like 50 50 emails per day trying to
trying to fish me, but that's because I
I configured my own email server 30
years ago and and I don't have a an
antivirus or spam filter on it. You
know, I just love to read what what
people want to want to tell me.
Um I do use some some funky RFC hacks to
to make spammers life harder, but still
about 50 per day make it through. Post,
meaning like snail mail, right? Um maybe
maybe that hasn't happened in a while.
Anyone remembers the first ever malware?
It was US.
Any ideas?
I don't I forgot the year. It was '80s
or before.
>> Morris worm.
>> Uh what worm?
>> Morris.
>> Morris worm. I think that was way before
that.
>> [clears throat]
>> Way before.
>> Uh
yes.
>> I love you email.
>> I love you email. Oh, that's that's like
2000s, I think, right? No, no, no. Uh
I'm I'm talking about it here. It was
done via post.
>> [laughter]
>> Yes. So, um and there's an article on
Wikipedia. You can look it up, all
right? In this these LLM sad LLM times,
at least Wikipedia is safe for now. So,
you know, you can go there and and learn
the truth. So, um
a researcher
created
um
an expert system. An expert system is
what we had before LLMs, right? It's
like a It's like a database um that and
it's actually useful. Many In medical
field, it's used a lot. So, a doctor
cannot remember all the potential
connections between all the diagnoses
and and the symptoms and what else
whatever else they have there. So, an
expert system is a system where someone
can type in some facts and then
deterministically, based on a database
of connections, it will provide uh you
with a visual representation of uh
probabilities for specific outcomes,
right? Which would in this in this
example would be uh different different
illnesses.
Now, so
um
uh an expert made an expert system, a
very very dumb one, a very small one,
which um indicated to the user what
what their risk of contracting an STD
is,
depending on some questions that they
answered. So, very really
I'm even I'm even ashamed that I
mentioned an expert system here right
now. This is It was like 10 questions, I
think. And shipped this out to different
medical professionals uh over post on a
diskette, on a floppy drive, uh floppy
disk.
And uh so far so good. Free stuff,
right? License was attached. No one read
the license. That hasn't changed in in
like 50 years. No one still reads
licenses.
Um you you plug it in the computer, you
play with it, it works, everything is
good.
Um
the
app would embed itself not in the boot
sector, I believe, but in the uh boot
system of of MS-DOS.
Um and it would count the times the
computer started.
Now, when the computer had been started
many times, uh assuming multiple days
have passed uh since installation or
first use of this application, um a
warning would appear saying, you know,
"Hey, by the way, you haven't paid uh
your license fee. You should either you
uh delete the program or or pay up."
And couple days later or couple boots
later,
it would stop the computer would stop
working. It would say, "Uh you haven't
paid. Sorry, now you got to pay."
So,
and I mean, the first time I learned
about this when I was when I was first
learning IT about 20 25 years ago,
uh
I thought, "Hmm, that's an interesting
business model." But, you know, it's a
business model. You had a license.
Uh I'm not a lawyer, but you have a
license and and you set it and, you
know, it's all fine.
Uh but, Wikipedia article these days
does state that the guy was either
arrested or prosecuted or or convicted.
So, not not not a good business model
apparently. Uh um So first malware ever
post.
Now I haven't seen any malware
deliveries outside of hacker conferences
over post in in many many years. Yeah.
Phone calls of course I mentioned that
as well.
Um
How many of you have heard of not really
trusting the phone number that you see
when the phone is coming in the phone
call is coming in?
Not everybody. Okay, but 80% okay. Yeah,
you cannot trust that stuff. It's it's
it's complete completely bogus. You can
just change it like that.
Um what about what about messages? So
the question about SMS is as follows.
Let's say you
you have a chat with you know an an
older person in your in your life. Let's
say a mother. I chat with your mother on
your phone and
it's legitimate chat.
Do you think how many of you think it is
not possible for an attacker
without hacking your phone just by
sending message it is not possible for
an attacker just to add a message to the
same conversation.
One, two, three, four.
Uh
Depends on the app. I'm talking about
SMS.
>> [laughter]
>> Yeah yeah yeah. Okay, so we had about
four five hands up. Yeah, it's it's SMS.
Yeah, so basically
what what happens is an attacker can
specify any any source number source SMS
ID as the end for for the messages they
send and your phone will look at the
message as the end it will match your
address book and will add it straight to
the same chat.
Very fun attack. So but that's
that's of course SMS. That's not a phone
call. USB drops.
Those had gotten very ineffective
recently.
So you know you can just drop some USB
flashes
outside on wow, I have like that many
slides to go. Jesus.
Let's see what we can do about that. So
Uh, you can just drop drop flashes uh,
let's say in a parking lot.
So, that's one thing you can do. It's
not effective anymore. So, what we did,
uh, like we started like six, seven
years ago, we started printing logos on
the flashes.
On the flash drives. These are
customer's logo or or customer's
customer's logo.
Uh, but that also doesn't work anymore.
And then, in one hacker conference about
2 years ago, someone told said to me,
"You know what we do? We put flashes in
pockets of their overcoats."
And now it works again.
Uh, so yeah. USB drops.
Um, yeah, instant message SMS, two
different two different things
technically, but from social engineering
perspective, same stuff. Uh, of course,
harder to fake the source of an instant
message. Uh, social networks as well.
Uh, Facebook, Mastodon, whatever
whatever else is happening. I'm so happy
that Mastodon has been so far fighting
off all the spam and bots, but I don't
think it's going to survive, but uh, I I
really hope it will. Uh, yeah, traffic
injection. Uh, now we spend a lot of a
lot of time and money, uh, as a society
to do HTTPS.
HTTPS has, uh, saved us all. Uh, at the
same time, we have this hotspot stuff.
When you have like a free Wi-Fi, you
connect and then there's an insecure
page asking you to enter your credit
card details or just click okay or
whatever. And browsers have to
accommodate that. So, that's a that's a
good spot for traffic injection when,
uh, victim first connects to your Wi-Fi.
And of course, malware network as well
be used to, uh, inject social
engineering attacks.
Uh, I'm going to even though I I know
that I have no time at all, I really
need want to tell this story here.
So, we had we had this, um,
this malware in Latvia,
um, many, many years ago. And, the
category of malware was, um,
Basically, it was trying to, uh, it was
extortion extortion malware. What that's
the category. Now, these days, many,
many younger people and and other other
experts, they just, uh, draw an
equivalent sign between extortion
malware and cryptolocker. And those are
different things. And now you don't have
to encrypt anything to extort money from
a user, and you don't have to
extort money to encrypt anything. Now,
this example of the latter one is, of
course, NotPetya, the malware created by
the Russian special services to attack
Ukraine health sector. It It was based
on Petya, which was a real extortion
cryptolocker,
but theirs just didn't, you know, didn't
allow to decrypt anything. They just
wanted to damage stuff by pretending to
be
crypto cryptolocker for extortion.
But finding an example that does
extortion without encryption, anyone has
any? But I don't want you to tell it,
just, you know, if you know any.
All right. Two two two people two people
think they know, that's good, yeah. I
also have one, so I'll tell I'll tell
mine.
So, back back in the day in Latvia,
there was this this fancy malware. What
it would do, it would pop up
a screen, not even full screen, when you
booted up your computer,
and you could close it with an X, and
it's gone. Until the next reboot, you're
safe. You reboot again, again same
window, you close it. That's it. It
didn't do anything malicious, anything
else malicious, anything other than the
the window. Right? And people still fell
for it. They still paid the money.
Now, it worked in a very, very nice
fashion. So, it had the some logos on it
in the window. One of the logos was of
the Latvian State Police,
and the text went like, you know,
"Hey, man, you know, we know that you
have um
or you you have um
you do copyright infringement, you have
unlicensed software on computer, and we
kind of need to start criminal
proceedings against you, but we're super
super busy. So, let's help each other.
Just go to this shop, buy this prepaid
card, put the number in here, and we're
done."
Uh state police didn't take kindly to
their logo being used that way. So, that
was closed down.
>> Okay. [clears throat]
Components of a social engineer. Right.
So, we we talked about um
We talked about the technical well,
relative technical stuff. Now, the the
social uh stuff. I I determined that
there are three things that you need to
do.
Uh one is confidence, right?
Uh there's a term, an older English
term,
con man,
uh which is short for confidence man.
Um back in the day when you know con
person was not considered as an option.
Uh so,
uh that basically means that uh it's
it's a person who with their confidence
tried tried to you know
f- befuddle you. They they come up to
you on the street say, you know, "Hey,
can you change this 20 into 10 into two
10s?" Yeah, here, take this 50, hold
that you there, and then you get then
they get all the money, right? That's
just one of the example examples of what
con man could do. They could also on the
street they could also do like the
golden ring scam and and other things
like that, right? But, uh confidence is
is an important thing for social
engineer. Uh you have to look, you have
to appear as you know as you as you know
what you're doing.
Uh in multiple times when doing a
physical test I've been in situations
where I'm somewhere on in the customer
premises
and I'm not where I wanted to be
specifically, so I have no idea where I
am or where I'm going. At that point,
there are couple things you can do, but
none of none of these things include
just you know just looking lost. Uh that
will not work well, all right? Even if
you're lost, you can you can go to
someone and say you're lost, but then
you have to have a good legend a good
story behind you why you're lost. You
then you're not an employee of that
building, right? If you're lost. Um
or you know, you just My go-to is
you know, I just I just walk somewhere.
Doesn't matter. I don't know where I'm
walking, but I just walk somewhere with
purpose. And if someone challenges, I'm
I'm saying, "Sorry, I got I got I got
run pee. I got to take a leak right
now." And you know, I'm I'm fast. I'm
moving. Toilet is probably like there
are multiple toilets in big buildings.
probably that way there is one.
Uh one time one time I was still
escorted to the toilet door and then out
of the building, but um
uh but usually they don't do that, you
know.
People people like to play nice. Um
Right. And then you have have to be
determined. So, you have to have
determination about about what you're
trying to achieve. Um
Right. So, just just three components.
Uh
You have to be ready to be challenged,
right? You can't You can't just just be
You have to be on your feet, basically.
Um there's a song by by a Latvian uh
by a Latvian group, one of the popular
ones, um Prāta vētra.
I think that outlines this really really
well. Now, it's in Latvian, but uh
but but so the text uh
um uh the text is like that. There is
something to it by Brainstorm.
Right. So, it means
>> [clears throat and cough]
>> um I reach out and got it all.
Um according to my list,
I was amazed. Man, that's something
magical. Simply focus on what's
important, put in little effort, and
look, you've got it. So, that's kind of
philosophy, um not only behind social
engineering, behind, you know, achieving
stuff in general. Um my my co-founder of
the company uh also loves this this
principle. I think he has it on his
social profile.
Now, for open-source intelligence, um
I'm inclined to skip this. So, I'm just
going to, you know, go over the slides
like super quick. Maybe you won't even
be able to read it. But basically, it
means collecting intelligence or, you
know,
valuable information uh from openly
available sources. That's what
open-source intelligence is.
Now, open OSINT sources include web and
dark web, social networks, metadata, you
know, the stuff that appears in files
without you knowing, network and service
scans, fingerprinting, um
and what I can suggest dearly is
osintframework.com.
When you open it up,
uh a tree will appear, or rather a tree
will not appear.
One two words will appear. And then you
click on click on that and you can
expand the mind map of, you know,
different different ways to do OSINT.
Really real cool resource if you if you
want to learn about it or if you are
wandering into new territory that you
that you haven't done before.
Now, for web, I have a couple of slides
for that.
Now, Google stopped working like a month
ago. It's it's just a search The search
is dead, basically.
Uh but I I still included the slide
here. So, you can of course do different
different dorks and try to find stuff
that is public that is not supposed to
be in public, right?
Um and then a bunch of other stuff.
pastebin.com, uh online comments and
news sites that might do something show
something about the company.
Uh now, different street view
applications. Um I have two examples
here. Um there are more, but it's
important to have to understand that you
you don't just go to one. You look at
multiples because the coverage may be
different, the angle may be different,
and um also
the date of data collection are
different. So, you can get more
information about what's happening
there.
Uh webcams, a bunch of those online
without password. Uh web.archive.org,
uh my heart goes out out to those guys.
Uh they are doing uh amazing amazing
stuff. Uh not only for OSINT, but, you
know, for preserving whatever we had
as a web back in the day.
Um tinEye.com, I included this here just
out of respect. This is the original uh
reverse image searcher. There are many
many tools that do that these days,
including large language models,
um that can help you understanding what
you're up against. Uh blockchain.info,
if you're doing something with um
cryptocurrencies. Uh shodan.io,
uh for network scans. There's also a
censys.io, of course.
Uh different leaks that you can use as
well.
Uh right. And uh there are different
people search engines. Sing. me, I think
it has survived outside of European
Union. In EU, they got nerfed back in
2019, 1 year after GDPR came into force.
Uh it's an amazing social engineering
stunt, or rather a con man stunt, uh the
Sing. me idea. Basically, no one no one
likes anonymous phone calls. No one
likes, you know, when someone is calling
you up a phone number and you have no
idea who you're going to be talking to,
right?
So, they have this amazing app that you
can install on your phone, and they
promise that instead of a anonymous
phone number, they will almost always
show you a person's name,
even if they're not in your phone book.
Uh because they have a huge database of
phone numbers. And how does it work?
Well, the user agreement basically says
that if you install this app, you agree
that your phone book is going to be
uploaded up to our cloud and shared with
everyone else.
Um back in the day, you could also use
the webpage Sing. me, and everybody was
there. I tried it on multiple Latvian uh
multiple presidents of Latvia. I tried
in other important and high-profile
people, and uh all of it's all it was in
there.
Alternatively, you can use Google Dork
as well, of course. Uh different public
registries, uh this is so-called deep
web, right? It's not easily indexable,
and it's not easily accessible to AI
models, but you can go and uh go and
look in specific registries for free,
and usually without authorization.
You can use online news as well.
And this uh todington.com/resources
is a list of links to different tools.
So, that's amazing as well. Can
recommend that.
Um
yeah, for uh social networks, there are
different hacks you can use there. You
can either register and and try to see
what you can see, or my favorite is
forget password uh feature. Usually,
some kind of second factor
identification leak is possible. Not not
implying that you can access the
account, but you can access some
information about the person.
Now, for Twitter, there was Nitter. Uh
it got DMCA'd uh 3 days ago, so I don't
know what's going to happen there. Uh
Let's let's see.
But you know, there's less and less
interesting stuff there unless you want
to
unless you have customers
in those kinds of people that that use
that kind of service.
Right.
And
to finish up OSINT, so
inteltechniques.com, I forgot the name
of the guy, but I do have a couple of
books
that he wrote.
Very valuable tools, especially for
social networks. Now, back in the day
there were automated tools that you can
just freely access on the webpage, type
in your query and his script that he
wrote would connect to the network and
fetch info for you for free.
These days most of those are just forms
that create a query and directly send
you to the specific social network. So,
nothing goes through
through him
anymore.
But still quite quite useful, right?
Especially if if you're
not an expert in specific social
network. Now, for example, back in the
day when Twitter was Twitter and it was
owned by a slightly
more palatable gentleman,
I I I used it a lot. So, I know how you
can do geo searches on Twitter, right?
For example, if you if you're thinking,
"Should I go to that concert that's
happening tonight? Has it started yet?"
What you can do is you geo fence all the
tweets back in the day and see the
pictures from the event right now and
and see, you know, how far along the
event is.
But if you don't know
how to do any of that for any of the
networks or some of the networks, then
you go there and and there's a list for
you.
Okay. [clears throat]
Now,
um
back to the tactics.
Pretext,
you have to have pretext and you have to
have it as a homework. Now, if you're
really really good and you like
adrenaline, you can just go in blank and
you just you know, make stuff up as you
go. Usually it it ends it it it doesn't
end good.
Right?
Um
Pretext includes but is not limited to
this. So what's your role, right? Who
you going to be playing?
Um
Make up a fake name, right? In countries
where name days name days are a thing,
that's that's a thing you should take
into account.
Uh when when is your name celebrated
nationally?
I've I've fallen for that once and and
now I always always do that, you know,
cuz you say, "Hey, I'm John." Oh, you
you you you had your name day last week.
And I yeah, maybe.
Uh I don't know. So and of course it has
to be it has to be reasonable. It it
can't be
it can't be too too crazy, right? And
also what's your birthday? That's that's
important for for various reasons,
right? Specifically you can also feel
more
more in, right? You really feel like the
person. You have to do that.
Why are you doing this? What's your
what's your goal? What you're trying to
achieve, right?
Uh you have to make sure that your role
matches your goal. If you if you're
trying to get into the CEO's CEO's
office, maybe a janitor is a good
is a good position, right?
If you're if you're trying to get to the
server room,
maybe a prospect employee, someone who's
applying for a job is not a good
position at that company. They probably
will not let you in the server room or
even even if you try to sneak away, you
know, you have to understand you can be
challenged at any point. And then
then that's not a good excuse to try to
be getting into the server room, right?
I I forgot my hat there. Actually used
I actually used I forgot my hat as a as
a way to try to get in last year into
into customer's premises.
That guard, even though he bought it, he
was he was really well-trained. He
kicked me up kicked me out twice during
that engagement.
Um we were we were playing cat and
mouse. He had video cameras, so it
wasn't wasn't fair.
Um
You have to convince yourself first.
That's important, right? And that that
adds up to the confidence part. If you
don't believe that you are who you are,
then no one else is going to believe you
there.
Uh and you have you can try challenging
yourself, right? Imagine these
scenarios, you know, a guard comes up.
You know, are you are you just going to
run or or or what's going to happen? I
had um
I had a situation
once. So,
I
I got into into premises using uh fake
ID card that looked okay, but was fake.
And I was doing whatever I had to be
doing. And then I noticed that someone
is pointing me out to the guard. I
noticed that from from from the
distance. And at that point I had I
thought I have like 10 20 seconds to
think of what my tactic is going to be
when the guard comes up to me.
And uh
should I I decided in those 10 20
seconds I decided in the first seconds I
decided that
I will not be showing my fake card to
him.
I will say that I lost my card.
So, and that's that that's how I got I
got I I got to stay there, right? I said
I lost my card. I had my pretext, my
identity. And the guard said, "Okay,
right?" He seems he's high up. He's he's
with the C-level. He's a assistant to
C-level. He's fine.
Even though he lost his card.
Um yeah. Could have turned out
differently, but uh you have to you have
to go through the situations and and try
to
uh try to look for holes in your story.
Uh
Right.
Let's Let's finish this up. I do have a
bunch of slides. Let's just go through
it. So,
um
some context. Everyone loves to help,
right?
Uh and people generally try to avoid
conflict.
And some people make consistently good
decisions, but most people do not make
good decisions, especially when they're
rushed.
Um
So, there are some hard targets, the
guards. I would necessarily avoid them
first years when you're doing social
engineering as a hobby or
professionally.
Uh those guys are trained to, you know,
to not do stuff that you want that you
want to be done.
Right?
Uh and the example is the hat. I even
told the guy that I'm going to their
C-level person. I had the name. I had I
had a colleague of mine calling me on my
phone at the same time as I'm
with the guard.
And I as he's calling, I turn the phone
slowly so the guard can see the face and
the name and the surname of of the
C-level in the person. Uh and I think he
bought that the person is calling me.
But he was so well trained, he said,
"No, that's that's that specific person
trained me specifically to not not do
that in any circumstances, right?" Uh
but so those are the hard targets. Uh
and people who are trained to work with
external customers, all right? Let's say
if you have a client that is a bank,
uh you would you would usually choose a
mark that is not the teller at the bank,
right? Because they have processes, they
know when to ask for ID, how to look for
for bad IDs, right? But if you if you
let's say if you were to call someone in
the back back office,
a manager, maybe um IT person,
then
they they don't know the process, you
might be able to get in there.
Uh right, so tell getting his hands
full, I gave you that example already.
Um if you are in for a long game, you
can also wait for a good hair day and
ask for a favor. Uh people love to help.
Sometimes they're grumpy, sometimes
they're not. You know, if they just had
salary paid out, if
if they just returned from vacation the
first day, good times, they can, you
know, help you out. Why not, right? Uh
one thing that I love to do outside of
engagements as well, well, I mean, I
don't I don't enjoy that outside of
engagements, but that I employ is uh
hinting at creating conflict and
providing an easy way to avoid it,
right? Uh sometimes airlines and other
corporations, they don't want to
abide by their own contracts that they
made.
Uh so, what I sometimes say in the
middle of the conversation, conversation
if I see that my request is going
nowhere, is, you know,
um
okay, okay, I understand you can't do
that. Maybe you can provide me with your
legal address so my lawyers can send a
letter and we can start proceedings.
Or maybe there's a senior associate
available after all.
And then then usually senior associate
is available
uh sometimes.
Um all right. So, [clears throat]
this is not the end of the presentation.
I still have like uh 4 minutes.
Um this is a whole subsection that I
would not have been able to include here
even if
um I was speaking three times faster.
Uh you can just go to the URL.
Or if you trust me, you can scan the QR
code.
Um and uh it's a presentation on
lobbying uh from a different conference
about 10 years ago.
And it basically uh it is relevant to
social engineering uh to the part of
building rapport and trust, all right,
how you can
um
connect with people.
All right, befriending employees and so
on.
Uh right, the exploiting part, all
right, always keep the goal of this
specific interaction in your mind. Once
you achieve the goal, feel free to push
a bit a bit further, right? Like I had
my Wi-Fi Wi-Fi access point name, but I
didn't have the password. Okay, let's
let If you want to get the password,
let's talk about the password, no
problem, right? But don't ask for too
much at the same time. You know, you for
for when when your target is a company,
you have many marks to choose from in
that company.
All right, practical exercises, the
important part. Uh let's uh
let's do
let's do this, right?
That's the first one.
Uh
yeah, [laughter] it's
it's hard. Uh I know. I wasn't talking
to anybody until uh grade four,
right? So, at at 11 years old, someone
convinced me to actually start talking
to my classmates.
So, it can be hard, but but you can do
it, right? That's the first step. Uh
another thing you can do is improve. Um
you can apply for some info classes.
They put you on the spot. They really
really help you with
getting out of situations when you if
you get into them. Uh alternative
personas, right? You can just going
through your life, you can look at the
situation that you're in and think, "Hm,
how would how would this imaginary
person act in this situation? Would they
do anything differently?" Just think
about it, right?
Um
And then you can pretend to be someone
else with a story. Now, before a lemming
it was more fun for other people as
well. Now with a lemming it's not fun
for them anymore cuz the lemmings do the
same all the time, but you can pretend
to be someone else, you know, just tell
a story. Uh it's go on Reddit, create a
create a fake account without trying to
harm anybody. Just a fun story, yeah? As
a storytelling exercise.
Uh you can do it with your friends
first, right? Don't do it with, you
know, customers or or or or someone
someone that you don't know and who
don't trust you.
Um yes, and the passive acquisition
methods.
Dig for some trash.
That's a fun thing to do. Eavesdrop on
nearby employees. Yeah, you you don't
have to have a a customer or a mission,
you know, just sit Friday evening, sit
at the bar and and see what you can
listen. You don't even have to write it
down. Just see if you can and I think
that will be really empowering.
Uh shoulder surf, right? That's that's
also a fun fun exercise. I I I stopped
it quite quickly after I started because
I felt uncomfortable with it.
Uh but uh but but you you you can try
that, yeah. Bumping into people, just
lightly bumping into people. This is
important for cloning RFID cards, right?
Uh
yeah.
Okay. So, uh those are the
passive acquisition methods that you can
start with.
Um
I don't know if I have Yeah, let's
let's uh
Uh yeah.
Build some pretexts. That's the final
thing I want to I want to talk to you
about. So, create a story in your head
that might work with something, right?
Doesn't have to be a real customer.
Doesn't have to be anything real. Please
don't go robbing robbing banks or
anything without permission, right? But
you can just just play it out. Imagine
what happens. Look from your
perspective, look from the other
person's perspective, see who there is
and what they might talk to you. What
they what they might tell you.
So, that is it for now. I don't think we
have any time for questions, but I'm
around the camp. If I get my deck
working, you can reach me on 5522. If
not, you know, just look for my face. I
might change this later.
And yeah, let's let's talk. I'll be here
until tomorrow for sure. Thank you.
>> [applause]