Black Hat USA 2018 - Every ROSE has its Thorn The Dark Art of Remote Online Social Engineering @HackersOnBoard
Black Hat USA 2018 - Every ROSE has its Thorn The Dark Art of Remote Online Social Engineering  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 4 days ago
Traditional phishing and social engineering attack techniques are typically well-documented and understood. While such attacks often still succeed, a combination of psychology, awareness campaigns, and technical or physical controls has made significant progress in limiting their effectiveness.

In response, attackers are turning to increasingly sophisticated and longer-term efforts involving self-referencing synthetic networks, multiple credible false personae, and highly targeted and detailed reconnaissance. This approach, which I call ROSE (Remote Online Social Engineering), is a variant of catfishing, and is performed with the specific aim of compromising an organisation's network. By building rapport with targeted victims, attackers are able to elicit sensitive information, gather material for extortion, and persuade users to take actions leading to compromises.

In this talk, I place ROSE within the context of other false personae activities – trolling, sockpuppetry, bots, catfishing, and others – using detailed case studies, and provide a comprehensive and in-depth methodology of an example ROSE campaign, from target selection and profile building, through to first contact and priming victims, and finally to the pay-off and exit strategies, based on experiences from red team campaigns.

I'll discuss three case studies of ROSE attacks in the wild, comparing them to the methodology I developed, and will then discuss the ethical, social, and legal issues involved in ROSE attacks. I'll proceed to cover ROSE from a defender's perspective, examining ways in which specific techniques can be detected and prevented, through technical controls, attribution, linguistic analysis, and responses to specific enquiries. To take this approach one step further, I'll also explore ways in which ROSE techniques could be used for 'offensive defence'.

Finally, I'll wrap up by examining future techniques which could be of use during ROSE campaigns or for their detection, and will invite the audience to suggest other ways in which ROSE techniques could be combatted.
Black Hat USA 2018 - Every ROSE has its Thorn The Dark Art of Remote Online Social EngineeringDEF CON 27 - albinowax - HTTP Desync Attacks Smashing into the Cell Next DoorDEF CON 27 - Jesse Michael - Get Off the Kernel if You Cant DriveDEF CON 27 - Joe Grand Kingpin - Behind the Scenes of the DEFCON 27 BadgeBlack Hat USA 2018 - A Brief History of Mitigation The Path to EL1 in iOS 11Black Hat USA 2018 - Reconstruct the World from Vanished Shadow Recovering Deleted VSS SnapshotsDEF CON 27 - Intro to Embedded Hacking-How you can find a decade old bug in widely deployed devicesBlack Hat USA 2018 - WireGuard Next Generation Secure Network TunnelBlack Hat USA 2018 - A Dive in to Hyper V Architecture & VulnerabilitiesBlack Hat USA 2018 - Its a PHP Unserialization Vulnerability Jim, but Not as We Know ItBlack Hat USA 2018 - Measuring the Speed of the Red Queens Race - Adaption and Evasion in MalwareDEF CON 27 - Mike Spicer - I Know What You Did Last Summer 3 Years of Wireless Monitoring at DEF CON
HackersOnBoard |

Black Hat USA 2018 - Every ROSE has its Thorn The Dark Art of Remote Online Social Engineering

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER