Baiting offers something enticing to trick a victim into compromising themselves. The classic is a USB drive left in a parking lot. Someone picks it up, plugs it in out of curiosity, and the drive installs malware. Researchers have run this experiment many times. A large fraction of dropped drives get plugged in. The payload might be a keylogger, a remote access tool, or a script that steals credentials.
Digital baiting works the same way. Free movie downloads that install malware. Fake software cracks that bundle trojans. Pop-up ads offering a free phone in exchange for filling out a survey. The bait does not need to be plausible to everyone. It only needs to catch a few people. Baiting often pairs with other social engineering techniques. A phishing email offers a free gift card and a link. The link leads to a page that asks for login credentials. The attacker now has both the credentials and the victim's trust. Defense is mostly awareness and policy. Do not plug in unknown devices. Do not download software from unofficial sources. Do not fill out forms promising free rewards.
Common baiting tactics
- Dropped USB drives in parking lots or lobbies
- Free downloads that bundle malware
- Fake prize notifications and surveys
- Peer-to-peer file sharing with infected files
Curiosity is the vulnerability. Attackers exploit it because it is reliable.
Comments
No comments yet. Be the first to share a thought.
Leave a comment