Social engineering

Psychological trick to fool victims into putting themselves at risk

Social engineering encompasses a wide range of psychological techniques used by cybercriminals, spammers, phishers and malware creators to deceive and entrap potential victims.

Most spam uses some form of social engineering to lure traffic to spamvertised websites: boasts of incredible bargains, world-beating products or amazing benefits are all intended to suck people in to following the links provided. Sex, wealth and fear are by far the most common lures, along with warnings of unpaid bills or compromised banking systems. Bank phishing emails often pose as messages from the bank urging users to log into their account (via a spoofed version of the webpage) to change, confirm or update their details. Rogue anti-malware uses the fear key, warning people of spurious malware infestations on their systems and demanding money in return for cleanup functionality, while malware such as the Storm attack has taken advantage of human curiosity by promising information on the latest dramatic news stories, as well as the promise of human contact in the form of greetings cards, to attract new victims to infected web pages.

The end user is always the weakest link in the cybersecurity chain, and any motivational pressure which can be brought to bear may be exploited by cybercriminals.

Related web links

Related news articles

Rogue AV claims to send money to environmental causes

'Green AV' best added to blacklist to avoid red faces.

03 September 2009

Valentine's lures lead to infection

Predicted spate of romance hooks under way.

10 February 2009

Digital attacks encroach on real world

Car park flyers trick victims to malicious site.

10 February 2009

Storm mails bring spoof World War 3 news

US-Iran war story used as hook for malware barrage.

10 July 2008

Malware going local

Report sees trend toward greater localisation of threats.

22 February 2008

  see all related news stories


Poll

Do you use the same password(s) across multiple websites?
I use the same password for all sites
I have a number of passwords but use the same for some sites
I use a different password for each site
I don't sign up to any sites that require a password

Leave a comment
View 4 comments

Jobs Career Sidebar

VB100 certification

VB100 This month VB's test team put 26 products to the test on Windows Server 2008. John Hawes has the full results.
See full results.

Virus Bulletin currently has 190,938 registered users.