TechKnowSurge
VideoSecurityFree

Impersonation

Impersonation is a core social engineering technique in which an attacker poses as a trusted person, authority figure, or recognized brand to bypass victim skepticism and extract information or access. Understanding how these tactics work is essential for recognizing and defending against them.

Complete this video to capture a CTF flag worth 1 point.

About this video

Impersonation is a foundational social engineering technique that works by hijacking trust the victim has already extended to someone or something else. Rather than convincing a target to trust a stranger, an attacker assumes the identity of a person, role, or organization the victim already considers credible — making the deception far more difficult to detect in the moment. The moment doubt is introduced, the attack loses effectiveness, so maintaining a convincing identity is central to the technique's success. Common impersonation scenarios include posing as executives or management figures, whose positional authority discourages pushback, and IT support personnel, whose role implies both legitimacy and a practical reason to request access or information. Beyond individual impersonation, attackers also target brand recognition — fraudulently claiming affiliation with companies like Microsoft to alarm victims into compliance — or create lookalike websites using slight domain misspellings, a practice known as typosquatting. These are not merely theoretical risks. The 2025 CrowdStrike Global Threat Report documents threat actor groups including Curly Spider and Plump Spider using IT support impersonation via vishing — voice-based phishing calls — as an active attack vector. In a notable pattern, Curly Spider first spam-bombs a target, then calls the victim posing as IT support offering to resolve the very problem they created, lending their impersonation a veneer of legitimacy. Understanding how impersonation functions across these different forms is essential groundwork for both identifying social engineering attempts and building organizational defenses against them.

What you'll learn

What's covered

Impersonation in Social Engineering

Key terms

Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Spoofing
An attack where an adversary impersonates a trusted entity by falsifying data such as an IP address or email address.
Typosquatting
A form of impersonation that registers misspelled or look-alike domain names to deceive users into visiting fraudulent websites.
Brand Impersonation
A social engineering technique where an attacker poses as a well-known company or organization to gain a victim's trust and extract information or access.
Vishing
A voice-based social engineering attack in which an attacker uses phone calls or voice messages to manipulate targets into revealing sensitive information or taking a harmful action such as transferring funds or resetting credentials.

Topics

Social Engineering Impersonation Typosquatting Brand Impersonation Cybersecurity Phishing

Transcript

If we're carrying out a social engineering attack, somehow we're going to need to gain trust quickly, and one way to do that is through impersonation.

Why impersonation works

In order to carry out a successful social engineering attack, an adversary is going to need to trick the victim into making whatever they say believable, with a certain amount of trust in it. As soon as the victim starts questioning, really, is this true, is this a scam, at that point in time there's going to be the seed of a doubt that's going to make the social engineering tactic much less successful. If an adversary impersonates another person, maybe a person that the victim already knows, then the victim is going to put the same level of trust in this adversary as they would in this other person. So it can be a very successful technique.

Who gets impersonated

A common impersonation would be some sort of authority figure. Maybe it's a CEO of the company, or an executive, or somewhere in management, somebody that oversees other people. Immediately they have a certain amount of authority, and people are going to listen to that authority within a company. So a good person to emulate is somebody of authority within the company.

Another effective method is to emulate tech support. When you call up and say, "Hey, I'm IT support," then immediately the person on the other side has a certain amount of trust in that IT support.

It doesn't necessarily have to be impersonating another person. For instance, it could be impersonating a brand or a website. When it comes to brand impersonation, maybe you're claiming that you're part of some sort of company that's well recognized, like Microsoft. This is a common one where scammers will say, "This is Microsoft. We've noticed that you've been hacked and we're trying to help you fix that." So brand impersonation can be an effective way to trick the victim into divulging information or getting access into their system. Maybe you're impersonating some sort of website. Maybe the website has some sort of misspelling in it. This is what's called typosquatting, and it's a type of impersonation.

Impersonation in the threat report

Here's the 2025 global threat report by CrowdStrike. In this report it outlines some of the techniques that Curly Spider, Chatty Spider and Plump Spider use to carry out their social engineering attacks. In the case of Curly Spider, they call the victim posing as IT support after spam bombing them. They claim that they are there to fix their spam bombing problem, and so it gives some legitimacy to who they are. In this one, Plump Spider calls the victim posing as IT support. So in both cases it's called vishing, where you're calling in and doing a voice attack. That's called vishing, and in this case they're claiming that they're IT support.

The attack card

Here's our attack card for impersonation. It's when you're pretending to be someone else, or maybe it's another entity like some sort of company. Some examples might be the adversary pretending to be a part of management or an executive within the company, or maybe it's IT support, or maybe it's just claiming some sort of other brand or mimicking a website.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →