Attack Techniques · 2.3

🎬 Pretexting & Baiting

A believable story, or an irresistible offer — both designed to bypass suspicion⏱ ~2 min

Pretexting

Pretexting is the use of a fabricated scenario (a 'pretext') to obtain information. This often involves impersonating someone trustworthy — a colleague, a bank representative, a new hire, an auditor — and building an elaborate, plausible backstory before making the actual request.

A Realistic Pretexting Scenario

  1. 1.Attacker researches the target company on LinkedIn, finds the name of the IT manager and a recently hired employee
  2. 2.Attacker calls the help desk, impersonating the new employee, citing the IT manager's name for credibility ('John said to call you')
  3. 3.Claims to be locked out and 'in a rush for a client call' — creating urgency
  4. 4.Help desk, wanting to be helpful and seeing a plausible story, resets the password and reads out a temporary one
  5. 5.Attacker now has account access — the entire interaction felt completely normal to the help desk employee

Baiting

Attackers offer something enticing — free software downloads, a discount, a free USB drive — in exchange for personal information or system access. The bait exploits curiosity or the desire for something free, and often involves infected files or links.

★ FactThe classic 'USB drop' baiting attack: an attacker leaves USB drives labeled 'Salary Information' or 'Confidential' in a company parking lot or lobby. Curiosity drives an employee to plug it into a work computer to see what's on it — instantly installing malware. In a well-known university study, nearly half of dropped USB drives were plugged in — the first within six minutes of being dropped.
⚠ WarningNever plug in an unknown USB drive, even one that looks official or was 'left behind' by someone. If you find one, hand it to IT/security — don't insert it yourself, even out of curiosity to find the owner.
🧠Quick Checkfirst try = +5 XP

You find a USB drive labeled 'Salaries 2026' in the parking lot. You…

0 XP🔥 0 days