S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T14.4
CATEGORY Social Engineering
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Baiting

Physical / Digital Lure · Curiosity Trap · Common
Red Flag
How It WorksSEC 01

Baiting leaves or offers an enticing item — a physical device, a free download, a “found” file — engineered so your curiosity or desire for reward leads you to take a risky action that grants the attacker access. It inverts the usual social-engineering direction: instead of approaching the target, the attacker leaves an attractive object where a target will find it and lets curiosity do the recruiting.

The classic physical form is the “road apple” — a USB stick dropped in a parking lot, lobby, or restroom, sometimes labeled to increase intrigue (“Payroll Q3,” “Confidential”). Plugged in, it delivers a payload: auto-run code, a device that masquerades as a keyboard to inject commands, or simply a tempting file. The digital form is far larger in volume — fake “cracked” software with a keygen, a movie or game “crack,” a “free” premium app, a required “codec,” or malicious QR codes on flyers and prize notices. The unifying logic is a value-for-nothing offer that lowers your guard, because the object appears to benefit you.

Baiting differs from phishing, which pushes a deceptive message, by its pull structure — you initiate contact with the lure. Its defining feature: the payoff to the attacker depends entirely on your own curiosity or desire for a freebie overriding your security caution.

Warning SignsSEC 02
  • "Found" media. Unsolicited devices appearing in shared spaces — parking lots, lobbies, restrooms.
  • Curiosity-baiting labels. "Confidential," "Salaries," "Private" — labels engineered to make you look.
  • Too-good "free" offers. Paid software or content offered free or far below cost.
  • Unrequested prompts. Install, "update," or "codec" prompts arriving before you sought them.
  • Reward QR codes. Codes on flyers or "you won a prize" notices routing you to a page.
  • No verifiable source. The item has no provenance you can independently check.
Frequently Paired WithSEC 03
  • Phishing · T14.2
    Sibling vector — message-push vs. lure-pull
  • Tailgating · T14.5
    Sibling physical-access vector
  • Malicious-Download Scam · T24.25
    The consumer fake-software variant
  • Vishing · T14.8
    Combines as a multi-channel pretext
How the Attack UnfoldsSEC 04
  • Stage 01 · Stage the Lure
    The attacker leaves an enticing object — a labeled USB, a "free" download, a QR flyer — where a target will find it.
  • Stage 02 · Curiosity Recruits
    The information gap or freebie appeal overrides caution; picking it up adds mild ownership pressure to use it.
  • Stage 03 · Payload Runs
    Plugging in or installing delivers the payload — auto-run code, a keystroke-injecting device, or bundled malware — granting the foothold.
Counter-ProtocolSEC 05
Defense: Never insert found media or install unvetted software — report the object, don't investigate it.
  • Don't plug in. Hand found devices to security or IT unused; never scan or open them.
  • Official sources only. Obtain software and media from verified official sources; treat "free" paid products as presumptively hostile.
  • Ignore unrequested prompts. Update through the app's or OS's own known channel, never a pop-up.
  • Distrust physical QR codes. Treat codes on notices as untrusted links.
  • Enforce controls. Disable auto-run, apply USB device-control and application allow-listing, deploy EDR, and segment networks.