Social engineering has been one of the most effective ways to spread malicious software lately. Whereas software vulnerabilities tend to be patched sooner or later, things don’t appear so promising when it comes to human exploits.
For example, Microsoft has rolled out a patch that disables autorun feature for USB thumb drives. Moreover, many antivirus products now prevent the autorun.inf file from being automatically executed. It would seem that these initiatives should efficiently combat malicious code that spreads via removable drives. That’s wishful thinking, though. Why? Innate curiosity often causes people to act injudiciously. Here’s the attacker’s flow of thoughts: if you can’t get the malware launched automatically, you need to make the user run it.
Below is the list of the most common social engineering tactics cybercriminals leverage to distribute malicious code. I will also provide some relevant protection tips.
File icon replacement
An executable file can be disguised as a folder, legit application or another benign file type by means of an appropriate icon. The ever-hasty user ends up clicking on it and thereby runs the file.
Prevention:
- Consider using file management utilities, such as Total Commander.
- If you’d rather use Windows Explorer (File Explorer in Windows 10), select a folder view option ( Content or Details ) that reflects the actual type of a file before clicking on it. This is particularly important when you are working with files on removable or network drives.
Intriguing filenames
This method comes down to using an eye-catching name of an executable file (for example, Do not open.scr ) that encourages the user to run it.
Prevention:
- A prudent user should treat such filenames with caution. Check the file type using a file manager, and if it’s *.exe, *.scr, *.bat, or *.vbs, then you are better off not clicking on it.
- If it’s an executable and you can’t help launching it, at least check it with free online tools like VirusTotal. Keep in mind, though, that new malware may slip under the AV radar for the first couple of days.
Taking advantage of the user’s desire to access certain content
The user is lured to visit the malefactor’s website and sees a popup dialog that recommends downloading some codec or driver in order to view the video content. Again, curiosity may overpower common sense in this scenario.
Prevention:
- Never follow suspicious links like that and refrain from executing any files downloaded there. Installing specific video codecs might be required by some legit sites that embed ads in their videos. Is that what you really need? You’d better find the same content elsewhere.
- Use phishing filters that go with modern browsers and antivirus suites. Do not ignore their alerts.
Imitating live communication
It’s common knowledge that email services and messengers are swarming with scams that ask the recipients to send SMS or click on a booby-trapped link. Fortunately, most users can easily identify these hoaxes nowadays. This fact has incentivized cybercrooks to take their techniques a notch further.
For instance, a malware sample dubbed Piggy.zip , or H1N1 , could compromise the ICQ messenger and send the contagious file to all of the victim’s contacts. To top it off, when the recipients typed, Is this a virus? or Are you a bot? , the malicious app responded quite intelligently, No, it’s a funny Flash video about a pig, check it out or You’re a bot yourself.
Code analysis revealed that the virus simply looked for a keyword (spammer, virus, bot, etc.) and generated a response somehow correlated with this keyword. Despite the whole simplicity of intelligence imitation, this approach turned out to be extremely effective. A lot of users, including those who thought they were security-minded, got on the criminals’ hook. It’s scary to imagine what will happen if a Trojan like that is enhanced with a fully-fledged chatbot.
Prevention:
- Do not download files or follow links received from unknown senders.
- Having received a file, even from your best friend, pay attention to the style and manner of communication. If it seems unusual or otherwise suspicious, you should repeatedly ask the sender to explain what information this file contains. Sometimes making a phone call is the best option.
Sextortion scams
These days scammers look for victims by sending tons of spam emails that inform users that somebody hacked their phones or computers and recorded videos of users while they were surfing through adult sites. Usually, such emails ask to send Bitcoins or hackers are going to share those videos to your contacts. However, some recent campaigns discovered by security researchers, do not ask for ransom payments but prompt to click and view a video where you are doing some funny activities. The downloaded file installs a ransomware virus.
Prevention:
- You should understand that this is just another scam. Your device was not hacked, hackers do not have any videos of you. Adjust spam filters to maximum security. A lot of antivirus tools, webmail, and local mail clients allow this.
- If you seriously care about your data, consider using encryption and anonymization software tools like VPNs. These will hide your real IPs and scramble all Internet traffic making it useless for hackers.
Road apple
Given that various storage media, including thumb drives, have become fairly cheap, the average criminal can afford to drop a Trojanized disk or USB memory stick right onto one’s porch. A strong desire to check out what’s inside induce a lot of victims to plug it into their computer and click every and each file, unwittingly executing the malware. That’s exactly what the perpetrator’s goal is.
Prevention:
- Use a separate isolated machine to check all storage devices that reach your company from unverified sources. Virtual machines work great too.
- If you are an employee at major company and have found some storage medium on your way to work all of a sudden. be sure to refrain from experimenting with it on your own. Instead, take it to the IT security team for checkup.
- On the other hand, if you are just a student or, say, plumber, it’s very unlikely that someone will ever drop any memory sticks for you. However, you are better off checking such a find on a virtual machine anyway.
Exploiting users’ fears
As a rule, the attacker will try to dupe the user into thinking their computer is crammed up with viruses, the personal data and passwords are being leaked, the IP address is being used to send spam, etc. In order to solve all of these pseudo issues, the victim is instructed to download and install some kind of an antivirus tool immediately. Attention to detail is very important here because many of these rogue programs are copycats of popular products and bear a strong resemblance to their GUIs. These installs may result in system blocking followed by a demand to purchase the product license . Another possible outcome is the influx of other malware capable of impacting the computer and the victim’s privacy in various ways.
Prevention:
- Always ignore alerts popping up on dubious websites that say your computer is infected, your personal data is at risk, etc.
- Opt for reputable antivirus suites and download the installers from the vendor’s official site only.