Cyber Attack! From the Eyes of the Attacker


Related to This Topic
Cyberattack in the eyes of the attacker.
This is a work of satire, we do not condone any of the actions of cyber attack described here – it is meant to be a somewhat comical example of the process that an attacker would go through to gain access to business systems.
From this perspective, we can see many points that would disrupt the attacker's ability to successfully compromise a business. We have intentionally left out detail and crucial steps in these processes so that this information is not used for nefarious purposes.
---------------
Alright folks, H@ckmast3r here with a simple new guide. Use these tricks to get whatever you want with a cyberattack.
It doesn’t really matter what you want if you do it right - this will get it for you:
Now, it goes without mentioning that I’d only advise doing these things from somewhere safe – you’ll want to set up your hacker tools before the cyber attack so that you can’t be tracked, otherwise you could get in some serious trouble.
The first thing you have to do to start a cyber attack is to know your target. If you’re going after a specific company you can skip this step, but for everyone else, it’s important to find soft targets. Here’s what we’re looking for:
We want a business that has whatever it is you’re after and looks like it doesn’t have a lot of investment into IT. That’s pretty much it! There are a few shortcuts to finding these, so if you don’t want to go find them yourself feel free to take a shortcut:
The next step is debatable, you might skip around if you’re heavily automating cyber attacks, but we won’t be so we’re going to gather our own information.
Once you have your list of companies, you’ll want to gather some fundamental information about them.
If you can’t get the information above, you can try calling them and just asking – most people will willingly give you this information when asked the right way. For example, if you’re looking for the boss’ information – just call and pretend to be a salesperson looking to talk to him. Make sure you sound as scummy as possible so they don’t pass you on and instead give you his email address, it’d be a waste of time to actually talk to him if you’re only looking for his email address.
Take a quick look in your leaked password database to see if any of those key employees' passwords have been leaked – as of this writing you should have around 450 major breaches loaded in there, so the odds of cyber attacks are good. Go ahead and try those passwords to see if you can get in their email, but if not don’t worry – we can still send email as them in a couple of ways.
If you find out during Recon that they’re not a soft target for a cyber attacks, I’d advise just skipping it entirely. There’s no sense wasting time on people that are either going to catch on too quickly – or have equipment/policies that stop your attack from being successful.
Just one of these won’t stop you, but if you see a lot of them then it might be game over. Here’s what to watch out for:
Ok, now that we have spent about 15 minutes gathering some baseline information we’ll put together the email.
If you got access to one of the key employee's email accounts, but you don’t have what you’re looking for yet – just send the emails from their account.
If not, we’ll send the mail from some other account and just change the display name to theirs. The email might list something else as the from address, but tons of people just read the display name anyways.
Now, I’m not going to write your email template for you – too many people would use it and spam filters would adapt, that’d be useless. Instead, Here’s some guidance on writing your own:
Just remember, there’s no need to be hasty – most people don’t find breaches after a cyber attack for 200+ days. If you get partial access but need to wait for some other event to pull off the phish – don’t worry about it, you have plenty of time! Need to wait for the boss’ big trip so you can ask the finance officer to send a western union – no problem! Need to wait for IT to all be at a convention so you can get free reign over the network and lock them out without a fight, no problem!
Especially if you haven’t gone past the recon stage, you can always just wait and keep them on the back burner – waiting for a vulnerability to pop up.
If you’re going to be taking remote control to accomplish a cyber attack, it’s always a good idea to do it when everyone is going to be asleep or otherwise occupied away from the office.
There’s no need to be doing it in the daytime when someone could see what you’re doing. As long as there’s nothing stopping you from logging in and doing your work at unusual times you might as well not take the extra risk.
Once you’ve pulled off a few of these, you should have enough funds to tide you over while you automate some of your workflows. You might want to start with a bot that crawls the web looking for outdated websites with email addresses just sitting on the contact page – that’s usually a great sign that they’re ripe for the picking. After that, here are some suggestions:
Anyways, there’s way more you can do if you get full remote access – and we haven’t even touched the fun stuff like DeepFake and social engineering. So stay tuned, fellow hackers – til next time *tips fedora*.
//H@ckmast3r out.