New ‘facial recognition’ tool could help white hat hackers harvest social media profiles

Security company claims software creates a level playing field for white hats and pen testers

Surveillance, machine learning, facial recognition

A new facial recognition tool has been released that could help automatically identify and harvest the social media profiles of thousands of targets with very little effort. The tool is primarily aimed at white hat hackers.

The tool - dubbed Social Mapper - was developed by security company Trustwave, who has released it on Github under an open source license. The company, which specialises in ethical hacking services, says that Social Mapper is intended for use by white-hat hackers, penetration testers and 'red teams' - internal security staff who are tasked with simulating cyber attacks on the organisation.

Social Mapper only needs a list of targets with the individuals' names and photographs. Users can also input the LinkedIn ID of a specific company, and it will automatically create a list of targets based on all the people who are registered as employees of said company on LinkedIn.

From there, Social Mapper logs into a range of social media sites - including Facebook, Twitter, LinkedIn, Google+ and Instagram, as well as regional platforms like VKontakte and Weibo - and searches the targets' names, using facial recognition to match their profile picture to the given photo.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

The software will then output a report containing all of the available social media profiles for each target, available in a variety of formats. It can also generate the target's work email, if you tell the software what format to use.

Any security expert worth their salt will tell you that a complete list of a target's social media profiles is an incredibly useful tool when conducting a cyber attack, and gathering such data is often the first step when conducting reconnaissance before an attack.

"Once social mapper has finished running and you've collected the reports, what you do then is only limited by your imagination, but here are a few ideas:

  • Create fake social media profiles to 'friend' the targets and send them links to credential capturing landing pages or downloadable malware. Recent statistics show social media users are more than twice as likely to click on links and open documents compared to those delivered via email.
  • Trick users into disclosing their emails and phone numbers with vouchers and offers to make the pivot into phishing, vishing or smishing.
  • Create custom phishing campaigns for each social media site, knowing that the target has an account. Make these more realistic by including their profile picture in the email. Capture the passwords for password reuse.
  • View target photos looking for employee access card badges and familiarise yourself with building interiors."

However, Trustwave's Jacob Wilkin (who created the tool) noted that "While this is an easy task for a few, it can become incredibly tedious when done at scale". This, he said, is the primary idea behind Social Mapper: to speed up intelligence gathering that pen testers previously had to do manually.

"Its primary benefit comes from the automation of matching profiles and the report generation capabilities. As the security industry continues to struggle with talent shortages and rapidly evolving adversaries, it is imperative that a penetration tester's time is utilized in the most efficient means possible."

Advertisement - Article continues below

While Trustwave has stated that Social Mapper is intended to be used by ethical white hat hackers, concerns have been raised that because the tool can be freely downloaded and used by anyone, it could easily be deployed by criminals.

Tim Helming, director of product management at DomainTools said that threat actors using open source components for phishing attacks show that available tools on the internet have "enormous potential to be used for both helpful and nefarious purposes".

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/business-strategy/public-sector/354608/uk-gov-launches-ps300000-sen-edtech-initiative
public sector

UK gov launches £300,000 SEN EdTech initiative

22 Jan 2020
Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
Visit/business-strategy/mergers-and-acquisitions/354602/xerox-to-nominate-directors-to-hps-board-reports
mergers and acquisitions

Xerox to nominate directors to HP's board – reports

22 Jan 2020
Visit/network-internet/web-browser/354614/microsoft-developer-declares-its-time-to-ditch-ie-for-edge
web browser

Microsoft developer declares it's time to ditch IE for Edge

23 Jan 2020