Opens in a new tab
vmblog logo 2024 wht (updated)

ZeroFox 2024 Predictions: Social Engineering – The Art of Hacking Humans

Share: 

David Marshall | Published: January 19, 2024

vmblog-predictions-2024 

Industry executives and experts share their predictions for 2024.  Read them in this 16th annual VMblog.com series exclusive.

Social Engineering – The Art of Hacking Humans

By AJ Nash, VP and Distinguished Fellow of Threat Intelligence at ZeroFox

In the ever-changing cybersecurity landscape, a growing concern is the rising prevalence of social engineering attacks. Notably, in 2023, these attacks witnessed a significant upward trajectory – a trend expected to persist into 2024 – as threat actors continue to refine their strategies, capitalizing on human vulnerabilities and deploying sophisticated manipulation techniques to breach defense. 

Specifically, threat actors are evolving beyond the run-of-the-mill phishing techniques, such as the use of malicious attachments delivered by email or popular messaging applications such as Zoom and Slack. Now, an abundance of information is readily accessible on public domains, social media sites, and more that allow hackers to successfully manipulate people and employees. 

As we gear up for the new year, many social engineering methods have caught the eye of cybercriminals, eager to exploit users – but a few stand out as particularly concerning due to their potential impact and elevated threat level. 

Search Engine Optimization (SEO) Poisoning

Attacks associated with search engine optimization (SEO) poisoning are very likely to remain a threat in 2024, as threat actors continue to find success in leveraging SEO cloaking – the manipulation of search engine web crawlers, malicious redirects, and website compromise attacks. 

In conducting look-alike domain and email spoofing attacks, we can expect threat actors to increasingly leverage the perceived authenticity afforded by the use of paid top-level domains (TLDs), such as .com, as opposed to free ones like .tk and .ga.

As SEO poisoning continues to increase across the threat landscape, domain monitoring detection tools for typosquatting and other impersonations are critical for security teams to address these types of social engineering attacks. 

MFA-Bypassing Techniques

Another form of exploitation that will remain prevalent is MFA-bypassing, where threat actors navigate around the widely adopted and rapidly proliferating tools commonly perceived as secure. Building on the success that cybercriminals had last year, they are likely to “rinse and repeat” their tactics that have proven most effective before.

Specifically, MFA fatigue and OAuth consent phishing are likely to remain major threats this upcoming year, with “in-the-Middle” (itM) attacks capable of token theft and session hijacking expected to become increasingly sophisticated and harder to detect. Cybercriminals are leveraging this technology to spam users, creating push-fatigue where employees may be overly quick to approve an alert based on how many they’ve received. Once users grant permission, whether via code redemption or access, hackers have a front-row seat to privileged information. Considering the overwhelming number of notifications bombarding employees through their phones, emails, and messaging applications, it’s easy to see how a user might hit the “approve” button without a second thought.

With the rise and maturation of MFA-bypassing techniques, it’s important for security teams to safeguard remote end-point devices by implementing MFA protocols that comply with recognized standards like FIDO2 or The Public Key Infrastructure (PKI). Additionally, security teams can also implement WebAuth security, which integrates external, physical authenticators to enhance the overall security posture with an additional layer of protection.

Phishing-as-a-Service (PhaaS) Operations

Lastly, Phishing-as-a-Service (PhaaS) operations will remain successful due to their low prices and growing sophistication. These services offer a low entry barrier for threat actors, empowering newcomers to quickly deploy a higher volume of cyber attacks and thus increase their success rates.

New Year, Fresh Start – Upleveling Your Security Approach

Overall, threat actors are likely to continue to harness the tactics associated with social engineering to profit off of unsuspecting victims in 2024.

As 2024 approaches, IT and security teams face the formidable task of navigating the surging volume of social engineering attacks. I recommend embracing a comprehensive, organization-wide, zero-trust cybersecurity architecture. This approach not only continually tests and scrutinizes the legitimacy of established trust, but also ensures access to devices, networks, and information is limited to the bare operational essentials, following the principle of least privilege.  

Above all, ensure your employees are properly educated on evolving social engineering techniques, emerging trends, and how to report suspected phishing attempts. By fostering a cybersecurity-aware culture within the organization, employees become a crucial line of defense against evolving cyber threats. Regularly conduct training sessions and awareness programs to empower individuals with the knowledge and skills needed to recognize and respond effectively to the latest tactics employed by malicious actors. This commitment to ongoing education forms a robust defense strategy, creating a human firewall that complements technological safeguards.

##

ABOUT THE AUTHOR

AJ Nash 

With over 20 years of experience in intelligence, I am a seasoned cyber intelligence strategist, consultant, and public speaker. As the VP & Distinguished Fellow of Intelligence at ZeroFox, I serve as the subject matter expert and evangelist for intelligence across the enterprise, supporting our customers, product, sales, and marketing teams with my expertise and insights.