1
00:00:00,180 --> 00:00:01,800
In this lesson, we are going to focus

2
00:00:01,800 --> 00:00:04,743
on impersonation as a social engineering attack.

3
00:00:05,580 --> 00:00:06,584
When it comes to impersonation

4
00:00:06,584 --> 00:00:09,960
as a social engineering technique, there are four main forms

5
00:00:09,960 --> 00:00:11,940
of impersonation used by attackers.

6
00:00:11,940 --> 00:00:14,850
These are impersonation, brand impersonation,

7
00:00:14,850 --> 00:00:18,150
typosquatting, and watering hole attacks.

8
00:00:18,150 --> 00:00:20,400
First, we have impersonation.

9
00:00:20,400 --> 00:00:21,810
Impersonation refers to an attack

10
00:00:21,810 --> 00:00:23,940
where an adversary assumes the identity

11
00:00:23,940 --> 00:00:26,184
of another person to gain unauthorized access

12
00:00:26,184 --> 00:00:29,490
to resources or steal sensitive data.

13
00:00:29,490 --> 00:00:30,990
Impersonation can be accomplished

14
00:00:30,990 --> 00:00:34,470
through pretending to be someone that people like and trust

15
00:00:34,470 --> 00:00:35,940
or by pretending to be someone

16
00:00:35,940 --> 00:00:38,040
with authority that will intimidate users

17
00:00:38,040 --> 00:00:39,720
to give out some kind of sensitive

18
00:00:39,720 --> 00:00:41,610
or confidential information.

19
00:00:41,610 --> 00:00:43,980
In order for an attacker to perform a successful

20
00:00:43,980 --> 00:00:46,440
impersonation attack, the attacker must first

21
00:00:46,440 --> 00:00:48,066
collect information about the organization so

22
00:00:48,066 --> 00:00:50,550
that they can more easily earn the trust

23
00:00:50,550 --> 00:00:52,020
of the targeted users.

24
00:00:52,020 --> 00:00:53,098
For example, if I randomly call one

25
00:00:53,098 --> 00:00:56,011
of your employees and just to tell them that I might

26
00:00:56,011 --> 00:00:59,730
work in the same company, that could be constructed

27
00:00:59,730 --> 00:01:02,430
as an obvious social engineering attack.

28
00:01:02,430 --> 00:01:05,134
However, if I call the same employee and tell them

29
00:01:05,134 --> 00:01:08,190
that I'm Mike from the IT department located up

30
00:01:08,190 --> 00:01:10,830
on the third floor, and I was just calling and check and see

31
00:01:10,830 --> 00:01:13,320
if their workstation has faced some of the same issues

32
00:01:13,320 --> 00:01:16,143
as the other employees have been reported, it's very likely

33
00:01:16,143 --> 00:01:17,938
that they will assume that the attacker is really

34
00:01:17,938 --> 00:01:20,059
from the IT department and the victim is more

35
00:01:20,059 --> 00:01:23,640
likely to cooperate with the attacker's request.

36
00:01:23,640 --> 00:01:25,570
In this case, providing more details

37
00:01:26,464 --> 00:01:29,460
help to make the lies more believable to a potential victim.

38
00:01:29,460 --> 00:01:32,730
Impersonation attacks can lead to severe consequences

39
00:01:32,730 --> 00:01:35,550
including unauthorized access to sensitive data

40
00:01:35,550 --> 00:01:39,296
disruption of services, or even a complete system takeover.

41
00:01:39,296 --> 00:01:41,938
To mitigate against these types of attacks

42
00:01:41,938 --> 00:01:44,430
organizations must provide security awareness training

43
00:01:44,430 --> 00:01:46,620
to their employees on a regular basis

44
00:01:46,620 --> 00:01:49,152
so that they remain vigilant against these future attacks.

45
00:01:49,152 --> 00:01:52,113
Second, we have brand impersonation.

46
00:01:53,040 --> 00:01:55,884
Brand impersonation is a more specific form

47
00:01:55,884 --> 00:01:58,470
of impersonation where an attacker pretends

48
00:01:58,470 --> 00:02:01,110
to represent a legitimate company or brand.

49
00:02:01,110 --> 00:02:03,320
This is often seen in phishing attacks or social media

50
00:02:03,320 --> 00:02:06,153
based attacks where attackers send emails

51
00:02:06,153 --> 00:02:07,834
or create a website that appears to be

52
00:02:07,834 --> 00:02:12,120
from a reputable company in order to trick victimized users

53
00:02:12,120 --> 00:02:14,370
into revealing sensitive information.

54
00:02:14,370 --> 00:02:16,632
When conducting brand impersonation, the attacker

55
00:02:16,632 --> 00:02:19,740
will use the brand's logo, marketing language

56
00:02:19,740 --> 00:02:22,404
and other identifiable information to make the fraudulent

57
00:02:22,404 --> 00:02:26,162
communications or websites appear to be more legitimate

58
00:02:26,162 --> 00:02:27,462
than they really are.

59
00:02:27,462 --> 00:02:30,530
To protect against brand impersonation, organizations

60
00:02:30,530 --> 00:02:34,260
should educate their users about these types of threats,

61
00:02:34,260 --> 00:02:37,134
use secure email gateways to filter out phishing emails

62
00:02:37,134 --> 00:02:40,750
and regularly monitor the brand's online presence

63
00:02:41,679 --> 00:02:43,759
to detect any fraudulent activities as soon as they occur.

64
00:02:43,759 --> 00:02:47,940
In November of 2020, a fake Twitter account impersonating

65
00:02:47,940 --> 00:02:51,090
the Eli Lilly and Company brand, a major manufacturer

66
00:02:51,090 --> 00:02:53,850
of insulin in the United States, tweeted that insulin

67
00:02:53,850 --> 00:02:56,460
would now be free for all its customers.

68
00:02:56,460 --> 00:02:59,520
This tweet rapidly went viral and was spread

69
00:02:59,520 --> 00:03:01,710
far and wide across the internet.

70
00:03:01,710 --> 00:03:03,810
Unfortunately, though, this was just a brand

71
00:03:03,810 --> 00:03:05,904
impersonation attack conducted against Eli Lilly

72
00:03:05,904 --> 00:03:08,597
and when the investors of the Eli Lilly stock saw the tweet

73
00:03:08,597 --> 00:03:11,130
which they believed to be true and authentic

74
00:03:11,130 --> 00:03:13,560
they began to sell off their shares of the company

75
00:03:13,560 --> 00:03:15,660
which resulted in a 4% decrease

76
00:03:15,660 --> 00:03:18,072
in the stock price in less than 24 hours.

77
00:03:18,072 --> 00:03:21,504
This resulted in Eli Lilly losing billions of dollars

78
00:03:21,504 --> 00:03:23,670
in market capitalization value

79
00:03:23,670 --> 00:03:25,410
simply because a social engineer

80
00:03:25,410 --> 00:03:27,005
created a brand impersonation account

81
00:03:27,005 --> 00:03:30,541
on Twitter and sent out a single malicious tweet.

82
00:03:30,541 --> 00:03:32,725
Third, we have typosquatting.

83
00:03:32,725 --> 00:03:34,230
Typosquatting,

84
00:03:34,230 --> 00:03:37,470
also known as URL hijacking or cyber-squatting,

85
00:03:37,470 --> 00:03:39,930
a form of cyber attack where an attacker registers a

86
00:03:39,930 --> 00:03:42,930
domain name that is similar to a popular website

87
00:03:42,930 --> 00:03:45,957
but contains some of the common typographical errors.

88
00:03:45,957 --> 00:03:50,010
The goal of typosquatting is to victimize users

89
00:03:50,010 --> 00:03:52,620
who may have accidentally mistyped the URL of a website

90
00:03:52,620 --> 00:03:55,620
and instead it redirects them to a fraudulent website owned

91
00:03:55,620 --> 00:03:57,480
by the attacker that is now attempting

92
00:03:57,480 --> 00:03:58,920
to steal their information

93
00:03:58,920 --> 00:04:01,800
or infect their system with malware.

94
00:04:01,800 --> 00:04:02,700
For instance

95
00:04:02,700 --> 00:04:06,480
an attacker might register a domain like gnail.com

96
00:04:06,480 --> 00:04:10,440
hoping to catch users who misspelled gmail.com.

97
00:04:10,440 --> 00:04:13,680
These fraudulent domains are often called cousins,

98
00:04:13,680 --> 00:04:17,190
lookalikes, or doppelganger domains.

99
00:04:17,190 --> 00:04:18,120
Another good example

100
00:04:18,120 --> 00:04:20,410
of this is when an attacker buys a domain

101
00:04:21,415 --> 00:04:23,949
like Di0ntraining.com instead of Diontraining.com

102
00:04:23,949 --> 00:04:28,560
but the first one has a zero instead of a O.

103
00:04:28,560 --> 00:04:30,113
It's hard to see and can be used

104
00:04:30,113 --> 00:04:33,000
to trick users pretty easily

105
00:04:33,000 --> 00:04:36,938
if they're not looking carefully at the URL or web link.

106
00:04:36,938 --> 00:04:39,150
Another way that typosquatting is used

107
00:04:39,150 --> 00:04:41,760
is by registering a hijacked sub-domain

108
00:04:41,760 --> 00:04:43,072
using the primary domain

109
00:04:43,072 --> 00:04:46,740
of a trusted cloud provider such as Azure.com.

110
00:04:46,740 --> 00:04:49,680
Then the attacker can send out phishing emails

111
00:04:49,680 --> 00:04:54,030
that appear to come from Diontraining.Azure.com

112
00:04:54,030 --> 00:04:56,640
which looks legitimate, but the company may not

113
00:04:56,640 --> 00:04:59,034
use that cloud service provider at all.

114
00:04:59,034 --> 00:05:02,370
In the case of Dion Training, at the time of this recording

115
00:05:02,370 --> 00:05:04,680
we don't use Azure for our cloud services

116
00:05:04,680 --> 00:05:06,900
and we instead use Amazon Web Services.

117
00:05:06,900 --> 00:05:08,670
So if you're receiving an email

118
00:05:08,670 --> 00:05:12,270
from Diontraining.Azure.com, then you would know it is

119
00:05:12,270 --> 00:05:15,600
a form of typosquatting or impersonation.

120
00:05:15,600 --> 00:05:17,128
To combat typosquatting,

121
00:05:17,128 --> 00:05:19,052
organizations will often register common

122
00:05:19,052 --> 00:05:23,039
misspellings of their own domain names, use services

123
00:05:23,039 --> 00:05:25,798
that monitor for similar domain registrations

124
00:05:25,798 --> 00:05:29,100
and conduct user security awareness training

125
00:05:29,100 --> 00:05:32,580
to educate users about the risk of typosquatting.

126
00:05:32,580 --> 00:05:35,400
For example, the certification company Accolade

127
00:05:35,400 --> 00:05:38,238
owns the website, Accolade.com, but also owns the

128
00:05:38,238 --> 00:05:42,390
misspelling of their name as acclade.com

129
00:05:42,390 --> 00:05:45,094
which redirects users to their legitimate website

130
00:05:45,094 --> 00:05:48,210
to prevent someone from buying the misspelled domain

131
00:05:48,210 --> 00:05:51,090
in order to trick any Accolade users.

132
00:05:51,090 --> 00:05:53,577
Fourth, we have watering hole attacks.

133
00:05:53,577 --> 00:05:56,550
Watering hole attacks are a targeted form

134
00:05:56,550 --> 00:05:58,890
of cyber attacks where attackers compromise

135
00:05:58,890 --> 00:06:00,032
a specific website or service

136
00:06:00,032 --> 00:06:03,030
that their target is known to use.

137
00:06:03,030 --> 00:06:04,046
Once the site is compromised

138
00:06:04,046 --> 00:06:06,840
the attacker can use it to deliver malware

139
00:06:06,840 --> 00:06:09,570
or launch other attacks against the target

140
00:06:09,570 --> 00:06:12,540
through the watering hole that they have established.

141
00:06:12,540 --> 00:06:15,240
Watering hole attacks are considered to be passive attacks

142
00:06:15,240 --> 00:06:18,150
since the threat actor does not communicate directly

143
00:06:18,150 --> 00:06:19,842
with the target and instead attacks them

144
00:06:19,842 --> 00:06:23,640
through the use of third party websites or services.

145
00:06:23,640 --> 00:06:26,820
Now, the term watering hole is a metaphor

146
00:06:26,820 --> 00:06:28,434
for a naturally occurring phenomenon

147
00:06:28,434 --> 00:06:32,220
in the African plains, predators will often wait

148
00:06:32,220 --> 00:06:35,100
at a watering source like river or a lake

149
00:06:35,100 --> 00:06:37,170
that they often see other animals returning

150
00:06:37,170 --> 00:06:40,015
to in order to drink water and hydrate themselves.

151
00:06:40,015 --> 00:06:43,860
Since the animals go to the same watering hole each day

152
00:06:43,860 --> 00:06:45,960
the predators can wait near the watering hole

153
00:06:45,960 --> 00:06:47,910
and attack the unsuspecting animal

154
00:06:47,910 --> 00:06:51,330
as they approach the watering source to quench the thirst.

155
00:06:51,330 --> 00:06:52,890
In the world of cybersecurity,

156
00:06:52,890 --> 00:06:55,262
the quote unquote "Watering hole" the attacker

157
00:06:55,262 --> 00:06:59,010
chooses to use will usually be a trusted website

158
00:06:59,010 --> 00:07:00,870
or online service.

159
00:07:00,870 --> 00:07:03,270
To mitigate watering hole attacks

160
00:07:03,270 --> 00:07:05,160
organizations should keep their systems and software

161
00:07:05,160 --> 00:07:07,590
up to date, use threat intelligence services

162
00:07:07,590 --> 00:07:09,330
to stay informed about new threats

163
00:07:09,330 --> 00:07:13,980
and employ advanced malware detection and prevention tools.

164
00:07:13,980 --> 00:07:17,238
So remember, there are four basic forms

165
00:07:17,238 --> 00:07:19,134
of impersonation attacks, including impersonation

166
00:07:19,134 --> 00:07:21,828
brand impersonation, typosquatting

167
00:07:21,828 --> 00:07:23,883
and watering hole attacks.

168
00:07:23,883 --> 00:07:25,194
Impersonation refers

169
00:07:25,194 --> 00:07:28,106
to an attack where an adversary assumes the identity

170
00:07:28,106 --> 00:07:31,200
of another person to gain unauthorized access

171
00:07:31,200 --> 00:07:33,035
to resources or sensitive data.

172
00:07:33,035 --> 00:07:35,635
Brand impersonation is a more specific form

173
00:07:35,635 --> 00:07:36,468
of impersonation where an attacker pretends

174
00:07:36,468 --> 00:07:41,400
to represent a legitimate company or brand.

175
00:07:41,400 --> 00:07:44,010
Typosquatting also known as URL Hijacking

176
00:07:44,010 --> 00:07:47,160
or cyber-squatting is a form of a cyber attack where

177
00:07:47,160 --> 00:07:49,831
an attacker will register a domain name that is similar

178
00:07:49,831 --> 00:07:51,420
to a popular website

179
00:07:51,420 --> 00:07:54,993
but contains some type of common typographical errors.

180
00:07:54,993 --> 00:07:57,097
Watering hole attacks are a targeted form of

181
00:07:57,097 --> 00:08:01,219
a cyber attack where attackers compromise a specific website

182
00:08:01,219 --> 00:08:05,183
or service that their target is known to use.

183
00:08:05,183 --> 00:08:08,220
It is important to understand these threats so

184
00:08:08,220 --> 00:08:10,440
that you can implement the appropriate countermeasures

185
00:08:10,440 --> 00:08:11,917
required to maintain a safe

186
00:08:11,917 --> 00:08:14,073
and secure computing environment.

