TechKnowSurge
VideoSecurityFree

Developing Connection and Trust

Social engineering attacks depend not just on emotional manipulation but on establishing trust, and adversaries use specific techniques such as empathy, flattery, social proof, shared similarities, and embedded truths to create that credibility with their targets. Understanding how trust is manufactured is essential to recognizing and resisting these tactics.

Complete this video to capture a CTF flag worth 1 point.

About this video

Social engineering attacks succeed not because they generate fear or urgency alone, but because they first establish a sense of trust between the adversary and the target. Without that trust, a target is likely to question what they're being told and disengage. Adversaries employ several well-documented psychological mechanisms to manufacture credibility quickly, including empathy, flattery, social proof, the appearance of shared similarities, and the strategic use of partial truths. Each of these exploits natural human tendencies — the inclination to trust those who understand us, compliment us, resemble us, or whose claims we can partially verify. Social proof in particular is a powerful lever, whether it appears as fabricated product reviews, inflated purchase counts, or implied endorsements, because people routinely defer to the perceived behavior or judgment of others when assessing trustworthiness. One of the most effective tactics in an attacker's toolkit is embedding verifiable facts within a deceptive message. When a target can confirm one element of a claim — such as looking up a software end-of-life date — they are more likely to accept the surrounding false claims as equally valid. This blending of truth and deception is a deliberate strategy designed to transfer credibility from what is real to what is fabricated. The CrowdStrike 2025 Global Threat Report documents exactly this kind of layered approach through the activities of a threat group known as Curly Spider, which first spam-bombs a target's inbox and then calls posing as IT support offering to resolve the very problem they created. The existence of the spam is real and confirmable, which lends legitimacy to the caller, and that manufactured trust is what ultimately leads the victim to install malware and compromise their own network.

What you'll learn

What's covered

Developing Connection and Trust

Key terms

Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Threat Actor
An individual or group responsible for a security incident or attack.
Vishing
A voice-based social engineering attack in which an attacker uses phone calls or voice messages to manipulate targets into revealing sensitive information or taking a harmful action such as transferring funds or resetting credentials.
Social Proof
A trust-building technique in which adversaries leverage the appearance of widespread approval or endorsement to make fraudulent claims seem credible.
Impersonation
A social engineering tactic in which an adversary poses as a trusted individual or authority figure to gain a victim's confidence and compliance.

Topics

Social Engineering Trust Building Techniques Emotional Manipulation Cybersecurity Awareness Human Factors Security

Transcript

If an adversary is trying to do some social engineering and they are using some emotional manipulation, they still need to couple that with some level of trust. If they are trying to generate fear, maybe they are trying to generate urgency, maybe helpfulness, in all those cases you have to trust what they are saying. But how does an adversary do that?

If somebody is speaking to us and we want to be helpful to them, or they have generated some sort of desire or greed inside ourselves, or maybe they have generated some fear in us, obviously we trust that person somehow, some way. But what have they done to earn our trust? There are some mechanisms that they can use to generate that trust, because as soon as a person really questions, really, is this right, now they are starting to lose that person. And so they are going to have to develop that trust.

There are several different ways that they can develop that trust. Just think about when somebody interacts with you: what develops trust in you? Why do you start trusting somebody? Some of us trust a little bit easier than others, but some of the mechanisms in place are going to be somewhat universal.

If they can generate some sort of empathy or understanding, maybe they are using flattery, maybe they are using social proof, similarities, elements of truth, or impersonation. These are just some ways that they can generate trust very quickly.

Empathy

Oh, I am so sorry to hear about your health condition. Is there anything that I can do to help you out? This is a sign that you are empathizing with someone. And when somebody empathizes with us, we develop this connection with them, a connection that results in some trust of that person.

Flattery

Ooh, I really like that shirt. Where did you get that? When we get complimented on something that we are wearing, or something we have, or something we have done, it feels really good. And this is another thing that can generate that feeling of trust and connection with somebody else.

Social Proof

When I am online shopping, I look at the reviews. And when I see really high reviews like 4.8, I think this is a great product. It develops some sort of trust in that product. And there are a lot of fake reviews that are out there. They can pay other people to write those reviews and that pumps up their reviews. This is problematic, because now it is a form of lying, really, because somebody reviewed the product who really never used that product. But it still works, because it is social proof.

Social proof is when you see that somebody else likes this. It can be shown in, like I say, online shopping. It shows how many people bought a product, and if you see that a product was purchased 43,000 times, you have a certain level of confidence in that product. Or if it gets 4.8 stars, you have a certain level of trust in that product. So social proof is a huge part of how successful these social engineering tactics can be.

Similarities

We tend to trust people who are similar to us. This is actually one of the problems, or one of the hurdles, that we encounter when it comes to diversity, equity and inclusion: that we tend to gravitate towards people who are similar to us. So we need to recognize that and overcome that.

It is the same thing when it comes to social engineering. The other person on the other side might try to find similarities in us. So if they know we like something, then they might end up liking that too, right? They might try to say that they like things that we like, or dislike things that we dislike. Finding those similarities between the adversary and the victim helps create that connection and a level of trust.

Elements Of Truth

Sometimes there is an element of truth in what they say. They say Windows 10 is going to be end of life here real soon, and so now we have something we can go look up and confirm: oh yes, Windows 10 is going to be end of life real soon. But the lies are buried between these elements of truth. And if we verify the truths, then we give some validity to the false parts of this, the lies part of this. So a lot of manipulators will use elements of truth to really stand on for the rest of their argument, for the rest of their lies, to trick you into thinking that the lies are actually truths as well.

An Example: Curly Spider

For this example, I am going to pull up the 2025 global threat report by CrowdStrike. One of their stories is about Curly Spider. Curly Spider is an adversary group, and it talks about how they go through their campaign, their social engineering campaign, against a victim.

What Curly Spider does, which is the adversary, is they start out by spam bombing their victim. They send them a ton of email, and in the process then they will call up. So they start this vishing where they are calling them in person. It is a voice phishing scam, and they are calling them in person and saying, hey, we are the IT department, we are here to help you out with your email issue. And the victim is like, what email issue? So they will open up their email and, oh yeah, I have just been spam bombed with a bunch of spam.

Well, now what this adversary has done is created this connection and this legitimacy of why they are reaching out to this victim. And this victim says, okay, what do I need to do to fix this issue? Now, probably in the process, they are going to have them pull down some sort of malware and install it on their system, and therefore their network is now compromised.

So this is an example of social engineering that starts out with telling a lie and doing some spam bombing. There is some partial truth to it, because they have got a lot of email in their inbox even though it was them who generated it. So it generates this level of trust and this level of urgency to fix this issue. And now the social engineering can continue to take place.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →