Information SecurityUnit 211 min read
Security Threats & Attacks: Types, Tactics & Real-World Impacts
Unit 2 of Information Security explores the taxonomy of cyber threats (passive/active, insider/outsider), attack vectors (malware, phishing, DoS), and real-world case studies like Ncell SIM-swapping frauds and eSewa payment hacks, with visual attack trees and timeline diagrams to trace how breaches unfold.
Core Concepts: What is a Security Threat?
A security threat is any event, action, or circumstance that could compromise the confidentiality, integrity, or availability (CIA triad) of information assets. Threats exploit vulnerabilities in systems, processes, or human behavior.
The CIA Triad Under Attack
Key Definitions:
- Passive Attack: Eavesdropping (e.g., sniffing network traffic) – no modification of data.
- Active Attack: Tampering, masquerading, or denial-of-service (DoS) – alters data or disrupts services.
- Insider Threat: Malicious or negligent actions by authorized users (e.g., employees leaking data).
- Outsider Threat: External attackers (e.g., hackers exploiting software flaws).
IMAGE: cyberattack taxonomy flowchart
| Threat Type | Example Attack | Target | Impact |
|---|---|---|---|
| Passive | Traffic analysis | Network packets | Data leakage (confidentiality) |
| Active | SQL injection | Database | Data corruption (integrity) |
| Insider | Privilege abuse | HR records | Unauthorized access (confidentiality) |
| Outsider | Phishing | Email accounts | Credential theft (availability) |
1. Common Attack Vectors
A. Malware: The Silent Saboteur
Malware (malicious software) infiltrates systems to steal, encrypt, or destroy data. Types include:
- Viruses: Attach to legitimate programs (e.g.,
CIH/Chernobylvirus corrupting BIOS). - Worms: Self-replicating (e.g.,
WannaCryransomware exploiting Windows SMB flaw). - Trojan Horses: Disguised as useful software (e.g., fake "Ncell Recharge" apps stealing OTPs).
- Ransomware: Encrypts files until paid (e.g.,
LockBittargeting Nepali hospitals). - Spyware: Monitors user activity (e.g.,
FinFisherused in state-sponsored espionage).
Worked Example: Pathao Driver Data Leak (2021)
- Attack Vector: Malicious app update pushed to drivers’ phones via Pathao’s update system.
- Malware Type: Spyware + data exfiltration.
- Impact:
- Confidentiality: 500K driver locations, trip histories, and bank details leaked.
- Integrity: Fake "promotions" tricked drivers into installing malware.
- Real-World Fix: Pathao revoked API keys and rolled back updates, but drivers lost trust.
B. Social Engineering: Exploiting Human Trust
Attacks manipulate psychology rather than technology. Common tactics:
- Phishing: Fake emails (e.g., "Your eSewa account is locked" with a malicious link).
- Spear Phishing: Targeted phishing (e.g., CEO fraud in Nepali banks).
- Baiting: Physical/digital lure (e.g., "Free Ncell Data" USB drops malware).
- Tailgating: Following authorized personnel into secure areas.
Visual: Phishing Email Flow
sequenceDiagram
participant User
participant Attacker
participant BankDB
User->>Attacker: Clicks "Urgent: Update Password" link
Attacker->>User: Fake login page (lookalike of NMB Bank)
User->>Attacker: Enters credentials
Attacker->>BankDB: Sends stolen creds to attacker's server
BankDB-->>Attacker: Returns "Login Failed" (honey pot)
Attacker->>User: "Your account is suspended! Call +977-XXXX"Real Example: NTC SIM Swapping (2022)
- Tactic: Attackers tricked NTC call centers into transferring victims’ phone numbers to their SIMs.
- Goal: Bypass 2FA (e.g., to hack eSewa/Khalti accounts).
- Victims: High-profile targets like politicians and businessmen.
- Prevention: NTC now requires in-person verification for SIM transfers.
2. Network-Based Attacks
A. Denial-of-Service (DoS/DDoS)
Overwhelms systems to disrupt service. Types:
- DoS: Single source (e.g.,
ping floodagainst a website). - DDoS: Botnet of infected devices (e.g.,
Miraiattacking NEPSE’s trading platform).
Worked Example: Daraz Nepal Outage (2023)
- Attack: DDoS using a botnet of hacked CCTV cameras (IoT devices).
- Impact:
- Availability: Website down for 48 hours during Black Friday sales.
- Financial Loss: $500K+ in lost orders.
- Mitigation: Daraz upgraded to Cloudflare DDoS protection.
B. Man-in-the-Middle (MITM) Attacks
Intercepts communication between two parties. Example:
- Eavesdropping: Sniffing unencrypted Wi-Fi (e.g., at Kathmandu’s Thamel cafes).
- Session Hijacking: Stealing cookies to impersonate users (e.g., on public Ncell Wi-Fi).
Visual: MITM on Unsecured Wi-Fi
Real Fix: Use VPNs (e.g., ProtonVPN) or HTTPS everywhere (like eSewa’s new encrypted checkout).
3. Physical Threats
A. Hardware Tampering
- Example: Swapping RAM chips in a bank’s server with malicious firmware (seen in Nepali ATMs).
- Impact: Skimming card data or installing backdoors.
B. Environmental Threats
- Fire/Smoke: Damages servers (e.g., 2019 fire at NTC’s data center).
- Power Surges: Corrupts data (common in Nepal’s unstable grid).
| Component | Vulnerability | Mitigation |
|---|---|---|
| Hard Drive | Theft/physical damage | Full-disk encryption (BitLocker) |
| Router | Default credentials | Change default admin password |
| Server Room | Fire risk | Fire suppression + UPS backup |
4. Insider Threats: The Silent Risk
Definition: Employees or contractors misusing access. Types:
- Malicious: Theft (e.g., ex-employee selling customer data).
- Negligent: Poor password hygiene (e.g., writing passwords on sticky notes).
Real Example: NMB Bank Insider Fraud (2020)
- Attack: Teller transferred $2M to personal accounts using duplicate transaction approvals.
- Why It Worked: No separation of duties (same person approved and processed).
- Lesson: Implement dual-control for financial transactions.
5. Attack Trees: Visualizing Threat Paths
An attack tree maps how an attacker might exploit vulnerabilities. Example for eSewa payment hack:
Key Takeaway: Defenders must block all branches of the tree (e.g., eSewa now uses biometric + OTP).
6. Real-World Case Study: WhatsApp Business API Breach (2021)
Attack:
- Hackers exploited WhatsApp Business API (used by companies like Daraz/Khalti) to send OTP phishing messages.
- Vector: Compromised third-party providers (e.g., "Khalti Support" messages).
Impact:
- $10M+ lost in fraudulent transactions.
- 10,000+ Nepali users affected.
Lessons:
- Multi-Factor Authentication (MFA): WhatsApp later added email + phone verification.
- Rate Limiting: Block repeated OTP requests from one number.
- User Education: WhatsApp now shows green checkmarks for verified businesses.
In the Real World
eSewa’s Payment Fraud:
- Idea Used: Phishing + Credential Stuffing
- How: Fake "eSewa Recharge" links (via SMS/email) redirected users to cloned sites. Attackers reused passwords from previous breaches (e.g., Daraz accounts).
- Real Fix: eSewa now enforces biometric login + transaction alerts.
Ncell’s Fake Customer Care Scam:
- Idea Used: Vishing (Voice Phishing)
- How: Callers impersonated Ncell support, asking for "account verification" (OTP). Once obtained, they ported numbers to new SIMs.
- Visual:
sequenceDiagram participant Scammer participant Victim participant NcellDB Scammer->>Victim: "Your Ncell bill is overdue. Verify OTP." Victim->>Scammer: Enters OTP Scammer->>NcellDB: Uses OTP to port number NcellDB-->>Scammer: Port successful
Daraz’s Supplier Data Leak:
- Idea Used: Insider Threat + SQL Injection
- How: A disgruntled Daraz employee injected SQL to dump supplier databases (prices, contracts). Data was sold to competitors.
- Prevention: Daraz now uses row-level security in databases.
Exam Tip
How This Unit is Tested (TU/PU/NEB Style):
Definitions (5 marks):
- Expect questions like "Differentiate between passive and active attacks with examples."
- Key Phrases to Use:
- "Exploits vulnerability in [system/process] to violate [CIA]."
- "Lacks defense-in-depth (e.g., only uses passwords)."
Case Study Analysis (10 marks):
- Given a scenario (e.g., "Nepal Rastra Bank’s SWIFT hack"), identify:
- Attack vector (e.g., spear phishing).
- Vulnerability exploited (e.g., weak MFA).
- Mitigation steps (e.g., HSM for transaction signing).
- Pro Tip: Always link to real-world fixes (e.g., "Like NTC’s SIM swap verification").
- Given a scenario (e.g., "Nepal Rastra Bank’s SWIFT hack"), identify:
Diagrams (5 marks):
- Draw attack trees, network diagrams, or CIA triad impacts.
- Example Question: "Show how a DDoS attack disrupts availability using a network diagram."
Short Answers (3 marks each):
- "What is the difference between a worm and a virus?" → Virus needs host; worm spreads autonomously.
- "How does tailgating bypass physical security?" → Exploits human trust (e.g., holding door for strangers).
Common Pitfalls to Avoid:
- ❌ Describing firewalls or encryption (that’s Unit 4/8).
- ❌ Forgetting real-world examples (examiners love Nepali cases like Ncell/SIM swap).
- ❌ Vague answers like "hackers do bad things" → Always specify the attack type and CIA violation.
Final Checklist for Full Marks: ✅ Define every term with a Nepali example (e.g., "Like the 2021 Khalti phishing wave"). ✅ Draw at least one diagram per question (attack tree, network flow, or CIA impact). ✅ Compare two attacks in a table (e.g., phishing vs. vishing). ✅ Suggest fixes using real tools (e.g., "Use ProtonMail for eSewa communications").
Based on the TU BIM syllabus for Information Security (IT244), unit 2.
Discussion
Loading…