
Imagine a scenario. It's a cold October morning, and the design institute is located in the regional center of one of Russia's regions. Someone from the HR department visits one of the job posting pages on the institute's website, which was published a couple of days ago, and sees a photo of a cat. The morning quickly becomes less boring...
In this article, Pavel Suprunyuk, the technical director of the auditing and consulting department at Group-IB, discusses the role of socio-technical attacks in practical security assessment projects, the unusual forms they can take, and how to protect against such attacks. The author notes that the article is of a review nature; however, if any aspect piques the readers' interest, Group-IB experts are ready to answer questions in the comments.
Part 1. Why so serious?
Let's return to our cat. After a while, the HR department removes the photo (screenshots here and further are partially redacted to avoid revealing real names), but it stubbornly reappears, gets deleted again, and this happens several more times. The HR department realizes that the cat has serious intentions and doesn't want to leave, so they call for the help of a web developer — the person who created the website and understands it, and now administers it. The developer accesses the site, deletes the annoying cat once more, discovers that it was posted under the name of the HR department itself, then speculates that the HR password has leaked to some online hooligans, and changes it. The cat no longer appears.

What actually happened? Specialists from Group-IB conducted penetration testing on the group of companies that included the institute, in a format similar to Red Teaming (in simpler terms, this is simulating targeted attacks on your company using the most advanced methods and tools from the arsenal of hacker groups). We have detailed information about Red Teaming. It's important to know that a wide range of attacks from the pre-agreed list may be applied during such a test, including social engineering. Clearly, the cat's placement was not the ultimate goal of what was happening. The actual goal was as follows:
- the institute's website was hosted on a server within the institute's own network, not on third-party servers;
- a leak of the human resources account was discovered (a log file of emails in the root of the site). It was not possible to administer the site with this account, but it was possible to edit job vacancy pages;
- by modifying the pages, one could place their own JavaScript scripts. Normally, they make pages interactive, but in this situation, the same scripts could be used to steal from the visitor's browser what distinguished the human resources department from the programmer, and the programmer from an ordinary visitor — the session identifier on the site. The cat was the trigger for the attack and served as a distraction. In HTML markup, this looked like this: if the image loaded, the JavaScript had already executed and your session identifier along with data about your browser and IP address had already been stolen.
- With the stolen administrator session identifier, one could gain full access to the site, place executable PHP pages, which would mean gaining access to the server's operating system, and then into the local network itself, which was an important intermediary goal of the project.
The attack ended with partial success — the administrator session identifier was stolen, but it was tied to an IP address. It was not possible to bypass this; we were unable to escalate privileges on the site to administrator level, but we did lift our spirits. The final result was eventually achieved on another part of the network perimeter.
Part 2. I write to you — what more can I say? I also call and stand at your office, dropping USB drives.
What happened in the situation with the cat is an example of social engineering, albeit not entirely classic. In fact, there were more events in this story: there was the cat, the institute, the human resources department, and the programmer, but there were also emails with clarifying questions that were supposedly written by 'candidates' to the very human resources department and personally to the programmer, to provoke them into visiting the site page.
Speaking of emails. A regular email — perhaps the main transport for conducting social engineering — has remained relevant for a couple of decades and sometimes leads to the most unusual consequences.
We often tell the next story at our events because it is very illustrative.
Typically, based on the results of social engineering projects, we compile statistics that, as is well known, are dry and boring. A certain percentage of recipients opened the attachment from the email, a certain percentage clicked the link, and these three even entered their login and password. In one project, we recorded more than 100% input of passwords — meaning more were entered than were sent out.
It happened like this: a phishing email supposedly from the CISO of a government corporation was sent, demanding to ‘urgently test changes in the email service.’ The email reached the head of a large division responsible for technical support. The head was very diligent in executing orders from higher management and forwarded it to all subordinates. The call center itself turned out to be quite large. In general, situations where someone forwards ‘interesting’ phishing emails to their colleagues, who also fall for it, are quite common. For us, this is the best feedback on the quality of the email composition.

A little later, we were exposed (the email was retrieved from a compromised mailbox):

The success of the attack was due to the fact that a number of technical deficiencies in the client’s email system were exploited during distribution. It was configured in such a way that any email could be sent on behalf of any sender within the organization without authorization, even from the internet. This meant one could impersonate the CISO, or the head of technical support, or anyone else. Moreover, the email interface, seeing emails from ‘its own’ domain, kindly inserted a photo from the address book, adding realism to the sender.
In truth, such an attack does not involve particularly complex technologies; it is a successful exploitation of a very basic email configuration flaw. It is regularly discussed on specialized IT and security resources, yet there are still companies that have all of this in place. Since no one tends to thoroughly check the service headers of the SMTP email protocol, an email is usually assessed for ‘danger’ based on warning icons in the email interface, which do not always reflect the complete picture.
Interestingly, this type of vulnerability works in the opposite direction as well: an attacker can send an email on behalf of your company to an external recipient. For example, they could forge an invoice for a recurring payment in your name, providing different banking details instead of yours. Aside from fraud and cash-out issues, this is probably one of the simplest methods for stealing money through social engineering.
In addition to stealing passwords through phishing, a classic method of social engineering attacks is the distribution of executable attachments. If these attachments bypass all the defenses that modern companies typically have in place, a remote access channel is created to the victim's computer. To demonstrate the consequences of the attack, the acquired remote control can lead to access to particularly sensitive confidential information. It is noteworthy that the vast majority of attacks that the media warns us about start precisely in this manner.
In our auditing department, out of curiosity, we estimate some approximate statistics: what is the total value of the assets of companies to which we gained "Domain Administrator" level access primarily through phishing and the distribution of executable attachments? This year, it reached approximately 150 billion euros.
It is clear that sending provocative emails and posting cat pictures on websites are not the only methods of social engineering. In these examples, we attempted to showcase the variety of attack forms and their repercussions. Besides emails, a potential attacker could call to obtain the necessary information, distribute media (such as USB drives) with executable files in the target company's office, get a job as an intern, or gain physical access to the local network posing as a video surveillance camera installer. All of these, by the way, are examples from our successfully completed projects.
Part 3. Learning is light, while the unlearned live in darkness.
A reasonable question arises: well, there is social engineering, it seems dangerous, but what should companies do about it? Captain Obvious comes to the rescue: they need to protect themselves, and in a comprehensive manner. Some of the defense will focus on the already classic security measures, such as technical information protection means, monitoring, and organizational legal support for processes, but in our opinion, the main focus should be on working directly with employees as the weakest link. No matter how much you strengthen the technology or enforce strict regulations, there will always be a user who finds a new way to break everything. Moreover, neither the regulations nor the technology will keep up with the user's creative approach, especially if they are prompted by a skilled attacker.
First and foremost, it's important to train the user: to explain that even in their routine work, situations related to social engineering can arise. For our clients, we often conduct on digital hygiene — an event that teaches basic skills to counteract attacks in general.
I can add that one of the best protective measures is not merely memorizing information security rules, but rather a slightly detached assessment of the situation:
- Who is my interlocutor?
- Where did their proposal or request come from (it never happened before, and now it has)?
- What is unusual about this request?
Even an unusual font type in a message or an atypical communication style from the sender can trigger a chain of doubts, stopping an attack. Written instructions are also necessary, but they work differently and cannot specify all possible situations. For example, information security administrators include warnings not to enter your password on third-party sites. But what if a "corporate" network resource is asking for your "own" password? The user thinks, "Our company already has a dozen services with a single sign-on, why not add another one?" From this follows another rule: a well-structured workflow directly influences security; if a neighboring department can request information only in writing and only through your supervisor, a request from someone claiming to be an "authorized partner of the company" over the phone will seem nonsensical to you. Be particularly wary if your interlocutor insists on doing everything right now, or "ASAP," as is fashionable to say. Even in regular work, such a situation is often unhealthy, and under conditions of potential attacks, it acts as a strong trigger. There's no time to explain, just run my file!
We notice that users are always targeted with themes related to money in one form or another for sociotechnical attacks: promises of raises, perks, gifts, as well as information with supposedly local gossip and intrigues. In other words, the classic "deadly sins" are at work: greed, avarice, and excessive curiosity.
Effective training should always include practice. Here, penetration testing specialists can be of assistance. The next question is: what and how are we going to test? At Group-IB, we propose the following approach — to immediately choose a testing focus: either assess the readiness of the users themselves against attacks or test the company's overall security. And testing using social engineering methods, simulating real attacks — that is, with phishing, sending executable documents, phone calls, and other techniques.
In the first case, the attack is carefully prepared in collaboration with the client's representatives, mainly its IT and security specialists. The legends, tools, and techniques of the attacks are agreed upon. The client provides focus groups and user lists for the attack, which include all necessary contacts. Exceptions are created on the protection measures, as messages and executables must reach the recipient; after all, in this type of project, the reaction of people is what matters. Optionally, markers can be embedded in the attack that allow the user to guess that it is indeed an attack— for instance, by making a couple of spelling mistakes in the messages or leaving inaccuracies in the brand style. At the end of the project, there is the actual "dry statistics": which focus groups reacted and to what extent to the scenarios.
In the second case, the attack is conducted with zero prior knowledge, using the "black box" method. We independently gather information about the company, its employees, network perimeter, formulate legends for the attack, choose methods, search for possible protective measures used by the target company, adapt tools, and compile scenarios. Our specialists use both classic open-source intelligence (OSINT) methods and our own product, Group-IB's Threat Intelligence system, which can act as an aggregator of information about the company over a long period, including utilizing closed information. Of course, to ensure that the attack does not become an unpleasant surprise, its details are also agreed upon with the client. This results in a full penetration test, but its basis will be advanced social engineering. A logical option in this case is to develop the attack within the network, even obtaining the highest privileges in the internal systems. By the way, we employ sociotechnical attacks in a similar manner in , and in some penetration tests. As a result, the client will receive an independent comprehensive view of their defenses against a specific type of sociotechnical attacks, as well as a demonstration of the effectiveness (or, conversely, the ineffectiveness) of their established defense line against external threats.
We recommend conducting such training at least twice a year. Firstly, there is regular employee turnover in any company, and past experiences are gradually forgotten by staff. Secondly, the methods and techniques of attacks are constantly changing, leading to the need to adapt security processes and protective measures.
When it comes to technical measures for protection against attacks, the following are the most effective:
- Mandatory two-factor authentication for services published on the internet. Launching such services in 2019 without Single Sign-On systems, without protection against password guessing, and without two-factor authentication in a company with several hundred employees is akin to an open invitation to "break me." Properly implemented security will make the quick use of stolen passwords impossible and provide time to mitigate the effects of phishing attacks.
- Access control measures, minimizing user rights in systems, and adhering to configuration guidelines for products released by major manufacturers. These are often simple in nature yet very effective and complex to implement in practice, with many overlooking them in favor of speed. Some are so essential that without them, no security measures will suffice.
- A well-structured email filtering line. Anti-spam, thorough checking of attachments for malicious code, including dynamic testing through sandboxes. A well-prepared attack implies that the executable attachment will not be detected by antivirus tools. The sandbox, on the other hand, will test everything using files just as a person would. As a result, any potential malicious components will be revealed through the changes occurring within the sandbox.
- Protection against targeted attacks. As mentioned, traditional antivirus solutions will not detect malicious files during a well-prepared attack. The most advanced products must automatically monitor the aggregate of events occurring in the network — both at the individual host level and at the traffic level within the network. In the case of attacks, very characteristic chains of events emerge, which can be tracked and halted if focused event monitoring of this kind is in place.
Original article in the journal "Information Security / Информационная безопасность" #6, 2019.
Source: habr.com
