Social Engineering – Part 2 | Computer-Based and Mobile-Based Attack Techniques (Plus Popular Tools)
Explore the most dangerous computer-based and mobile-based social engineering attacks like phishing, smishing, QR-code scams, and more. Learn the top tools hackers use and how SOC teams can defend against these evolving threats.
Quick answer: Computer-based social engineering uses email phishing, spear phishing, whaling, watering-hole sites, malicious links and QR-code phishing. Mobile-based attacks include smishing, malicious apps, fake OS updates and SIM swapping. Defenders and testers use tools like GoPhish and the Social-Engineer Toolkit in authorised simulations to measure how staff respond.
Key takeaways
- Spear phishing uses personal details, whaling targets executives and watering-hole attacks compromise a site the victim already visits.
- QR-code phishing hides the real link, so preview the URL before opening it.
- Smishing and fake apps are the main mobile routes, so install apps only from official stores.
Table of Contents
- Quick‑Glance Overview
- Why Computer‑ and Mobile‑Based Social Engineering Matters
- Computer‑Based Social Engineering Techniques
- Mobile‑Based Social Engineering Techniques
- Real‑World Incident Spotlight
- Defensive Playbook for Computer and Mobile Attacks
- Takeaways
In Part 1 we covered the core ideas and human‑based tricks behind social engineering.
Today, we move to digital territory, how attackers use computers and phones to fool people at scale. You’ll learn the main attack types, see real‑world examples, and get a list of tools defenders (and testers) need to know.
Quick‑Glance Overview
| Category | Key Attacks | Typical Tools | Primary Targets |
|---|---|---|---|
| Computer‑Based | Email phishing, spear phishing, whaling, watering‑hole, malicious links, drive‑by downloads, QR‑code phishing | GoPhish, Social‑Engineer Toolkit (SET), Evilginx2, King Phisher, Zphisher | Office staff, executives, remote workers |
| Mobile‑Based | Smishing (SMS), malicious apps, fake OS updates, SIM swapping, mobile QR scams | SMS‑Spoofing Gateways, APKTool, MobSF, Caller‑ID spoof services | Everyday smartphone users, BYOD employees |
Why Computer‑ and Mobile‑Based Social Engineering Matters
-
Email and SMS remain the #1 initial access vector in data‑breach reports.
-
People check phones 150+ times a day, attackers know your guard is down on mobile.
-
Cloud tools mean one stolen password can unlock multiple applications.
Computer‑Based Social Engineering Techniques
Email Phishing (Spray‑and‑Pray)
Attackers send mass emails with fake invoices, shipping notices, or tax forms.
Goal: trick users into clicking a malicious link or opening a booby‑trapped attachment.
Spear Phishing
A targeted version of phishing. The email is personalized with names, job titles, or recent projects.
Example: An email to HR that references a real job posting and asks them to open a “candidate résumé” (malware).
Whaling
Spear phishing for senior executives (the “big fish”). Often requests wire transfers or confidential reports.
Watering‑Hole Attack
Hackers compromise a website frequently visited by the target group (e.g., an industry forum) and inject malicious code that triggers drive‑by downloads.
QR‑Code Phishing (Quishing)
Victims scan a QR code in a PDF or poster, believing it leads to Microsoft 365 login or an event page, but it redirects to a phishing site.
Malicious Links & Drive‑By Downloads
Hidden links in ads or pop‑ups auto‑download spyware when you visit the page with an outdated browser.
Popular Tools Used (Blue & Red Teams)
| Tool | Purpose | Typical Use Case |
|---|---|---|
| GoPhish | Open‑source phishing framework | Security‑awareness campaigns, red teaming |
| SET (Social‑Engineer Toolkit) | Generates spear‑phish emails, malicious web pages | Pen‑testing, demo attacks |
| Evilginx2 | Reverse‑proxy tool to steal session cookies (bypass MFA) | Advanced phishing kits |
| King Phisher | Simulates phishing for training | Measures click‑rate & credential theft |
| Zphisher | Quick phishing‑page generator | Proof of concept, learning labs |
Mobile‑Based Social Engineering Techniques
Smishing (SMS Phishing)
Fake texts from “delivery companies” or “banks” contain links to credential‑harvesting sites or malicious apps.
Malicious Mobile Apps
Attackers hide spyware or banking trojans inside seemingly harmless apps (flashlight, QR scanner, game mods).
Fake OS or Play‑Store Updates
Pop‑ups urge users to “install urgent security patch,” but the APK is malware.
SIM Swapping
Criminals trick or bribe telecom staff to port your phone number to a SIM they control, intercepting MFA codes.
Mobile QR‑Code Scams
QR codes on posters or emails redirect to fake wallet apps or payment pages.
Key Mobile Toolkits & Services
| Tool / Service | Use | Why It Matters |
|---|---|---|
| SMS Spoof Gateways | Send SMS with fake sender ID | Common in large smishing blasts |
| MobSF (Mobile Security Framework) | Analyze malicious APKs/IPA files | Blue‑team detection |
| APKTool | Reverse‑engineer Android apps | App auditing, malware research |
| Caller‑ID Spoof Services | Fake caller numbers for vishing | Impersonates banks/IT help desk |
Real‑World Incident Spotlight
Case (2025): A global logistics firm was hit by a spear‑phishing email crafted with info from LinkedIn.
-
Payload: Link to an Evilginx2 server that proxied the real Microsoft 365 login.
-
Outcome: MFA bypass via stolen session cookie → attacker accessed SharePoint, exfiltrated invoices → launched ransomware.
-
Lesson: Even MFA isn’t bulletproof without session‑management alerts.
Defensive Playbook for Computer and Mobile Attacks
| Defense Layer | Action Items |
|---|---|
| User Training | Phish‑simulation drills, QR‑scam awareness, “hover over link” habit |
| Email Security | SPF, DKIM, DMARC; attachment sandbox; link‑rewriting gateways |
| Endpoint Protection | Behaviour‑based anti‑malware, browser isolation, mobile EDR |
| MFA Hardening | Use number‑matching push or FIDO2 keys; monitor abnormal session tokens |
| Mobile Policy | Block sideloading, enforce app‑store vetting, disable SMS for password resets |
| Threat Intel | Subscribe to IOC feeds for popular phishing kits and smishing domains |
Takeaways
Computer‑ and mobile‑based social engineering scales globally, one phishing kit can hit millions in minutes.
But simple controls, email filtering, user awareness, MFA best practices, and mobile EDR, cut risk dramatically.
Up Next
In Part 3 of this series we’ll tackle Social Engineering Countermeasures, from technical safeguards to policy‑driven user education that actually sticks.
To take this further with guided labs and an instructor, see our CEH v13 AI training.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0