Information Security
Information Security
Final Project
Submitted To
Submitted By
Insia Sharafat_010
Barira Akbar_021
BSE_VI_A
Fear
We receive a message informing us that we are being investigated for financial crimes and we
must call promptly to avoid arrest and prosecution. This social engineering attack occurs around
tax season, when people are already worried out about paying their taxes. Cyber hackers
capitalize on the tension and worry associated with tax preparation and use these dread feelings
to deceive individuals into responding with the message.
Curiosity
Computer hackers pay much attention to incidents that receive a lot of media attention and then u
se human curiosity to fool social engineering targets into acting. Following the second Boeing M
AX8 jet crash, for example, cyber thieves sent messages with attachments claiming to help each
other. After exploring a company, cyber criminals aim two or three include leaked information
about the crash. The attachment connected a version of the Worm RAT on the victim’s
computer.
Helpfulness
Humans desire to believe and workers with an email that appears to be from the targeted individu
als' boss. The email requests that they submit the password for the financial database to the boss,
emphasising that the management requires it to ensure that everyone is paid on time. The messag
e tone is urgent, leading victims to believe that by acting immediately, they are assisting their ma
nager.
Urgency
We receive emails from customer service at a popular online shopping website informing us that
they need to validate our credit card details in order to protect our account. The email phrasing e
ncourages us to answer immediately in order to prevent hackers from stealing our credit card det
ails.We give your credit card details, email address, and phone number without hesitation becaus
e we trust the online store. After a few days, we receive a call from our credit card provider infor
ming us that our credit card has been hacked or used for hundreds of dollars in fraudulent transac
tions.
Evaldas Rimasauskas, a Lithuanian national, carried out the largest social engineering attack
over two of the biggest companies i.e Google and Facebook. Rimasauskas and his team created a
fictitious corporation, posing as a computer manufacturer company that collaborated with
Google and Facebook. Rimsauskas also opened savings accounts in the name of the company.
The scam artists then sent phishing emails to particular Google and Facebook executives, billing
them for products and services that the manufacturers had legitimately given — but instructing
them to pay money into their fake accounts. Rimasauskas and his friends defrauded the two tech
powerhouses of approximately $100 million between 2013 and 2015.
Microsoft warned in February 2022 of a new spear phishing attempt by a Russian hacker outfit
targeted Ukrainian government departments and NGOs, as international leaders debate the
proper reaction to the growing tense situation among Ukraine & Russia.
Since 2021, the team known as Gamaredon has apparently been targeting "organizations crucial
to emergency response and preserving the safety of Ukrainian territory," according to Microsoft.
Gamaredon's initial attack depends on spear phishing mails delivering malware. The messages
also include a plugin that lets attackers know if they've been opened.