Even though the world is densely connected by digital signals, malicious software does not flow freely from computer to computer. First, not all programs are capable of damaging all devices. Secondly, all devices have a shell that, at least in the basic configuration, offers sufficient protection.

Hackers have only two ways to install malicious software on third-party devices: have physical access to them or use the owner as an unsuspecting infection vehicle. The first scenario is complex to implement: not only should the hacker be able to physically get his hands on the PC but he should also know the access password. The second option is easier to implement: it exploits the weaknesses of those who operate the computer to inadvertently make them install what they want.

Over the years, an entire trend has developed around techniques to induce users to carry out certain harmful actions: social engineering.

What is social engineering?

Social engineering uses forms of psychological manipulation to induce users to provide sensitive information or perform potentially dangerous actions. This type of attack typically occurs in several phases:

In the initial phase, the hacker carries out careful investigations on the victim and collects information on potential entry points into the system, on the security protocols used and on any weak points. In this phase, the attack method and the individual who will act as a vector are also established.

In the next phase, the hacker acts to gain the victim's trust and induce him to perform the desired actions aimed at granting access to the system.

Once the plan has been executed, the final phase of the attack consists in the simple cancellation of the traces, both those in the system and the social ones visible to the unaware carrier.

Social engineering is particularly dangerous because it exploits human error instead of relying on vulnerabilities in software and operating systems, so attacks are neither predictable nor resolvable by installing an update.

The best known attack techniques

With the exception of Denial-of-Service (DoS) attacks, every hacker attack is based on forms of social engineering. The most well-known cyber-attacks are:

Literally "bait", which can be physical (for example a USB stick) or virtual (a hidden link in an email).

Pop-up windows that appear while browsing certain Internet sites suggesting that your computer may be infected? That's an example of scareware.

Scareware is harmless software that has the sole objective of scaring the user and inducing him to take potentially harmful initiatives such as installing supposed self-defense software, which is in fact the malware one should defend oneself from.

It is one of the most common techniques and is based on emails sent to a wide range of people. The text of the messages is specifically created to generate a sense of fear, urgency or curiosity in the potential victim. The goal is to trick the victim into revealing sensitive information by clicking on links to malicious websites or opening attachments packed with malware.

Come difendersi?

It is possible to lower the chances of your PC being infected, simply by keeping some small precautions in mind:

  • Open email attachments carefully
  • Be wary of tempting offers received via email
  • Lock your laptop when you leave
  • Scegliere l’autenticazione a più fattori
  • Utilizzare software anti-malware

Would you like to learn more about technologies and methods to defeat cyber-attacks on critical infrastructures? Register to receive a free consultation on the 1st level University Master's Degree in Cybersecurity & Defense in collaboration with the University of Catania.

Consult the UniCt announcement or download the brochure.