Towards Continuous Social Engineering

No ratings

Presented at x33fcon 2026 by

Social Engineering sucks. We spend hours crafting the perfect email campaign, only for it to land in junk, be reported, or have the user simply not read their emails. So what do we do? We automate it of course! This talk will demonstrate automating phishing and vishing campaigns, using custom tools "Running a successful social engineering campaign requires a lot of moving parts. We need pretexts, domains, infrastructure, landing pages, email templates, payloads and targets. Clients want metrics, operators want protection against bots and alerts if campaigns are reported. Operators spend hours crafting the perfect campaign, only for users to hit the ""report phish"" button, or just not read their email. Obviously the more emails we send, the better our changes of success, but this also increases the likelihood of a campaign being reported. Vishing can be very successful, but also requires a lot of work to set up and time to execute, especially when your targets are in a different country. In this talk we will introduce the concept of continuous SE, including ways we can leverage voice services to perform automated phone-based campaigns. We will also introduce Reel, a tool used internally at TrustedSec, allowing continuous, automated email and voice SE campaigns. "