4 ms·
TL;DR: - Fake LinkedIn profile gets in touch with the victim, pretending to be an employer. - Conversation moves to WhatsApp or email. - Victim receives a Mi
by andrecarini 4y ago
TL;DR:
- Fake LinkedIn profile gets in touch with the victim, pretending to be an employer.
- Conversation moves to WhatsApp or email.
- Victim receives a Microsoft Word document with malicious macros; or
- Victim is instructed to download and run a malicious executable, "here's your assessment test as part of the interview process".
- Computer is infected.
It doesn't get any more basic than that. I'd go so far as to say that anyone falling for this is not a security researcher, sorry. (at least the technical type, maybe if you're the clueless policy type that has no technical wits).
- junon 4y agoThis just sounds like a run of the mill malware attack... I don't know any security researcher that'd be complying with this stuff or running executables outside of a sandbox.
- _8j50 4y agoNot all security researchers are security professionals. A lot of bug bounty hunters and exploit researchers are desparate to be employed at a famous firm (e.g.:project0). Anyone can fall for a phish and even open the document but the lame part here is enabling of macros. My guess is that people that work with exploits are too focused on exploitation, they don't think about simple social engineering like this. Having spent several years in this area of security, what you have to understand is that everyone, without exception, once their guard is down it is game over. For example, you never ask a person if they clicked on a suspicious link or email because if the phish worked then in the victim's mind it is still legitimate. I have had people argue with me about the legitimacy of the email after they were compromised. Unless you think about this every day,your mental defenses stop working the moment you are convinced it is all real. Let me put it a different way, our brains do pattern recognition, they don't do parsing. A sentence could be worded all out of order yet if the pattern matches we read it in the intended correct way. Our brain auto-corrects (and this also applies to vision in general lol). If you are trying to be a researcher at google or microsoft and you have been corresponding with a person you know is from there and is offering you a job, when you see a macro you will probably think "I can't believe a company like this uses macros" not "hmm, what if all if this is a scam" you are too caught up on the reward the social-engineer is dangling in front of you. The best defense against this is segregation. Use a separate physical machine on a separate physical network (minimal usb drive reuse between them) to separate where you open your email, chat, visit random sites vs where you do research, store important docs,etc... If this was a corporation I would say the second pc would be a "privileged accesss workstation" (MS term).
- peddling-brink 4y agoAgreed. To your last point, Qubes OS goes really far to accomplish this. Install is reasonable provided you use a supported laptop.