Social Engineering & FraudMANIPULATIVE
Baiting
What it is
Leaving or offering something the target wants (a found USB drive, free software, a media download, a plausible "lost" document) that carries a hidden payload, so that curiosity or self-interest does the attacker's work.
How it works
Real-world examples
- •Stuxnet, the malware that damaged Iranian uranium centrifuges around 2009-2010, is widely reported to have crossed an air gap on removable media carried by a contractor.
- •The 2008 compromise of U.S. military networks known as Operation Buckshot Yankee began when a flash drive carrying the agent.btz worm was inserted into a laptop at a base in the Middle East.
- •The 2014 BadUSB research by Karsten Nohl and Jakob Lell showed that a drive's firmware can be rewritten to impersonate a keyboard, so a "storage device" can type commands the moment it is plugged in.
- •Consumer versions: a free movie stream that first demands a "codec update", or a QR-code sticker offering free parking that leads to a card-harvesting page.
Ethical guidelines
- ●Planting a payload to be run by someone who does not know it is there is unauthorized computer access; there is no ethical use.
- ●Authorized drop tests are defensible only inside a signed engagement, with harmless payloads that record a click rather than executing anything, followed by training.
- ●Organizations should make the safe path easy: a clearly labeled place to hand in found devices removes the "I only wanted to return it" motive.
How to defend against it
- ►Never plug a found drive into a computer you care about; hand it to IT or reception. If it must be inspected, use a disposable machine that is not on your network.
- ►Treat "free" downloads from outside official app stores and vendor sites as hostile by default; the file is the product being sold, and you are the buyer.
- ►Organizations should disable USB autorun, restrict removable media by policy, and alert on new keyboard devices appearing on managed machines.
- ►Notice the emotional pull of a label. "Confidential" and "Do not open" are written for you; the more a found object seems to invite you in, the less you should touch it.
References
- Tischer, M., Durumeric, Z., Foster, S., Duan, S., Mori, A., Bursztein, E., & Bailey, M. (2016). Users Really Do Plug in USB Drives They Find. Proceedings of the 2016 IEEE Symposium on Security and Privacy, 306-319 · linkCampus experiment with 297 dropped drives: first connection within six minutes, estimated 45-98 percent success, altruistic motive for most openers.
- Mitnick, K. D., & Simon, W. L. (2005). The Art of Intrusion: The Real Stories Behind the Exploits of Hackers, Intruders and Deceivers. WileyCase narratives of physical and media-based intrusions that rely on the target handling a planted object.
- Hadnagy, C. (2018). Social Engineering: The Science of Human Hacking (2nd ed.). WileyDiscussion of baiting and curiosity-driven attacks within the social-engineering framework.
Last reviewed
Suggest a correctionRelated Articles
Social Engineering: Why Smart People Fall for It
Social engineering does not target stupidity. It targets helpfulness, deference, and time pressure, which are the same habits that make people good at their jobs. Here is how the attacks are built and which procedures actually stop them.
7 min read
The Disinformation Playbook: How Campaigns Are Built and Where They Break
Disinformation campaigns follow a recognizable sequence: seed, launder, amplify, and let real people carry it the rest of the way. A field guide to the stages, drawn from the research, with the defences that work at each one.
8 min read