You gather everything you can about the org, identify the best target based on ROI (highest reward + lowest risk of detection), then craft a story to approach them.
- @ChristinaLekati
They first tried PupyRAT via phishing, but that didn’t work. So they created the fake person Mia Ash to establish relationships with targets (yes Mia was pretty hot)
— @ChristinaLekati
For any future attackers: my personal brand is fluffy kittens, unlimited crispy bacon, resting bitch face & intellectualism as a coping mechanism
#Hacktivity2019
We like people who are like us, so social engineers will present themselves like you.
— @ChristinaLekati #Hacktivity2019
A great talk by @ChristinaLekati at #Hacktivity2019 !