Attack Techniques · 2.3
🎬 Pretexting & Baiting
A believable story, or an irresistible offer — both designed to bypass suspicion⏱ ~2 min
Pretexting
Pretexting is the use of a fabricated scenario (a 'pretext') to obtain information. This often involves impersonating someone trustworthy — a colleague, a bank representative, a new hire, an auditor — and building an elaborate, plausible backstory before making the actual request.
A Realistic Pretexting Scenario
- 1.Attacker researches the target company on LinkedIn, finds the name of the IT manager and a recently hired employee
- 2.Attacker calls the help desk, impersonating the new employee, citing the IT manager's name for credibility ('John said to call you')
- 3.Claims to be locked out and 'in a rush for a client call' — creating urgency
- 4.Help desk, wanting to be helpful and seeing a plausible story, resets the password and reads out a temporary one
- 5.Attacker now has account access — the entire interaction felt completely normal to the help desk employee
Baiting
Attackers offer something enticing — free software downloads, a discount, a free USB drive — in exchange for personal information or system access. The bait exploits curiosity or the desire for something free, and often involves infected files or links.
★ FactThe classic 'USB drop' baiting attack: an attacker leaves USB drives labeled 'Salary Information' or 'Confidential' in a company parking lot or lobby. Curiosity drives an employee to plug it into a work computer to see what's on it — instantly installing malware. In a well-known university study, nearly half of dropped USB drives were plugged in — the first within six minutes of being dropped.
⚠ WarningNever plug in an unknown USB drive, even one that looks official or was 'left behind' by someone. If you find one, hand it to IT/security — don't insert it yourself, even out of curiosity to find the owner.
🧠Quick Checkfirst try = +5 XP
You find a USB drive labeled 'Salaries 2026' in the parking lot. You…
🎮 Practice what you learned
⭐ 0 XP🔥 0 days