The Social Graph of Malware

Social Engineering – gets automated

Social engineering got automated with the early software viruses.

These early viruses infected a computer, opened the user’s address book, and then mailed themselves to everyone in the address book. The virus made use of the connections of the infected person to spread its own DNA around the world. This was in effect an “automated” form of social engineering.

Once this began, nothing was ever the same again.

Not only does this make it easy for the virus to obtain target email addresses, but it also takes advantage of the trust of the recipient of the infected message. That’s important! That word trust. The recipient knows the person the virus came from, and thus has his or her defenses “down” and is more likely to open the infected attachment than if it arrived from a stranger. This exploitation of trust is going to come up again and again, and is the core of both the way the virus works, and the way you defend yourself against viruses.

More recently this address-book harvesting technique has become unnecessary because there are huge lists of automatically-harvested email addresses that can be used for these mailings.

Post to Twitter

Looking for something?

Use the form below to search the site:

Still not finding what you're looking for? Drop a comment on a post or contact us so we can take care of it!

 

Related sites