I’m super excited for this talk by @ChristinaLekati about social engineering through social media at #Hacktivity2019 !
Social engineering isn’t all about charm and luck — it involves a strategy & a plan, always.

You gather everything you can about the org, identify the best target based on ROI (highest reward + lowest risk of detection), then craft a story to approach them.

- @ChristinaLekati
Facebook scams were the #1 way to breach networks according to a Cisco report in 2017.

Hence, SOCMINT is becoming such a popular strategy — it helps tailor their operations & also people are shy to report “emotional compromise”
Case study by @ChristinaLekati in her #Hacktivity2019 talk: Mia Ash, used by “Cobalt Gypsy”

They first tried PupyRAT via phishing, but that didn’t work. So they created the fake person Mia Ash to establish relationships with targets (yes Mia was pretty hot)
Attackers will look at your personal brand — how you present yourself, if you excude insecurities, etc.
@ChristinaLekati

For any future attackers: my personal brand is fluffy kittens, unlimited crispy bacon, resting bitch face & intellectualism as a coping mechanism
This is @ChristinaLekati ‘s profiling matrix (unfortunately it isn’t showing up well in this pic). It includes self image, social life, & professional life combined with personality, interests, wants, & vulnerabilities.

#Hacktivity2019
Personality traits are used to build rapport. Interests / wants are the “hooks.” Vulnerabilities can be used when likability doesn’t work.

We like people who are like us, so social engineers will present themselves like you.
@ChristinaLekati #Hacktivity2019
Security culture matters, though I would argue someone trying to be nice by reviewing an Excel file shouldn’t cause your organization to crumble. Anticipate that people want to be helpful & will download crazy shit

A great talk by @ChristinaLekati at #Hacktivity2019 !
Missing some Tweet in this thread? You can try to force a refresh.

Enjoying this thread?

Keep Current with Skellyton Shortridge ☠️

Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!