BIT303 Information Security

Information SecurityUnit 814 min read

Malware Types, Cyber Attacks & Defense Strategies

Unit 8 of Information Security explores malicious software (malware) types—viruses, worms, Trojans, ransomware, spyware—and cyber attack methods (phishing, DDoS, MITM), their real-world impacts (e.g., eSewa scams, Ncell SIM hijacking), and defensive strategies like firewalls, encryption, and user training. Includes att

TAKEAWAYS:

  • Malware spreads via exploits (e.g., unpatched software) or social engineering (e.g., fake eSewa links), and is classified by behavior (infecting, stealing, encrypting) rather than by intent.
  • Cyber attacks follow kill chains: reconnaissance → weaponization → delivery → exploitation → installation → command & control → actions on objectives (e.g., Pathao driver data theft).
  • Phishing (e.g., fake NEPSE login pages) and DDoS (e.g., Daraz website crashes) exploit human trust and bandwidth limits, respectively—defenses include multi-factor authentication and rate limiting.
  • Offline dictionary attacks (precomputed hashes) crack weak passwords like "password123" in seconds, while online attacks risk account lockouts but can brute-force longer passwords if attempts aren’t rate-limited.
  • Zero-day exploits (e.g., WhatsApp Pegasus spyware) target unknown vulnerabilities; patch management and sandboxing mitigate them.
  • Incident response follows NIST’s 4 steps: Preparation → Detection & Analysis → Containment → Recovery (e.g., Ncell’s SIM swap fraud response).

1. Malicious Software (Malware): Definitions and Classification

Malware is software designed to damage, disrupt, or gain unauthorized access to computer systems. Unlike legitimate programs, malware hides its true intent and often self-replicates or escalates privileges. The syllabus classifies malware by how it infects, spreads, or damages systems:

classDiagram
    class Malware {
        <<abstract>>
        +spreads_via: vector
        +damage_type: destructive/stealing/encrypting
    }
    class Virus {
        +attaches_to: executable
        +needs_host: true
        +examples: ILOVEYOU, Stuxnet
    }
    class Worm {
        +self_replicating: true
        +no_host_needed: true
        +examples: Morris Worm, WannaCry
    }
    class Trojan {
        +disguised_as: legitimate
        +backdoor: true
        +examples: Emotet, Zeus
    }
    class Ransomware {
        +encrypts_data: true
        +demands_payment: true
        +examples: LockBit, WannaCry
    }
    class Spyware {
        +steals_data: true
        +keyloggers: true
        +examples: Regin, FinFisher
    }
    Malware <|-- Virus
    Malware <|-- Worm
    Malware <|-- Trojan
    Malware <|-- Ransomware
    Malware <|-- Spyware

Key Differences

Type Spreads Via Damage Type Real-World Example Defense
Virus Host file (e.g., .exe) Corrupts files, crashes OS ILOVEYOU (2000) Antivirus (heuristic scanning)
Worm Network (no user action) Consumes bandwidth, spreads WannaCry (2017 NHS attack) Firewall, patch management
Trojan Social engineering Backdoors, data theft Emotet (banking malware) Sandboxing, user training
Ransomware Phishing/Exploits Encrypts files, demands ransom LockBit (targets hospitals) Offline backups, immutable storage
Spyware Bundled software, exploits Steals credentials, logs keystrokes FinFisher (government surveillance) Anti-spyware tools, VPNs

Caption: A ransomware attack on a Kathmandu hospital’s patient records: encryption → ransom note → decryption failure if not paid.

How Malware Infects Systems

  1. Exploit Kits: Target unpatched software (e.g., Adobe Flash, Java).
    • Example: Angler Exploit Kit used in fake Daraz coupon scams.
  2. Social Engineering: Tricks users into running malware (e.g., "Your eSewa account is locked—click here").
  3. Drive-by Downloads: Malicious ads or websites inject code when visited.
    • Example: Malvertising on YouTube redirects to exploit kits.
  4. Supply Chain Attacks: Compromises legitimate software (e.g., SolarWinds hack).

2. Cyber Attacks: Types and Mechanisms

Cyber attacks exploit vulnerabilities in hardware, software, or human behavior. The syllabus categorizes them by target and method:

mindmap
  root((Cyber Attacks))
    Threats
      **Passive**
        Eavesdropping
        Traffic Analysis
      **Active**
        Interruption (DoS/DDoS)
        Masquerade (Spoofing)
        Fabrication (Fake data)
    Attack Vectors
      **Network-Based**
        DDoS (e.g., Mirai botnet)
        MITM (e.g., Evil Twin Wi-Fi)
      **Host-Based**
        Buffer Overflow (e.g., Heartbleed)
        Privilege Escalation
      **Application-Based**
        SQL Injection (e.g., NEPSE website hacks)
        XSS (Cross-Site Scripting)
    Defense Strategies
      **Preventive**
        Firewalls, Encryption
      **Detective**
        IDS/IPS, Log Analysis
      **Corrective**
        Patch Management, Incident Response

A. Phishing and Social Engineering

Phishing tricks users into revealing sensitive data (e.g., eSewa PINs, Ncell passwords). Variants include:

  • Spear Phishing: Targeted at specific individuals (e.g., fake NEPSE CEO emails).
  • Whaling: Targets high-value individuals (e.g., bank CEOs).
  • Vishing: Voice-based phishing (e.g., "Your SIM is blocked—call this number").

Real-World Example: In 2022, a fake eSewa SMS ("Your transaction failed—verify here") led to NPR 50 million in losses. The attack used:

  1. Spoofed sender ID (showed as "eSewa Support").
  2. Phishing link to a cloned eSewa login page.
  3. Keylogger to steal OTPs.

Defense:

  • Multi-Factor Authentication (MFA): Even if credentials are stolen, MFA blocks access.
  • Email Filtering: Tools like Microsoft Defender flag suspicious links.
  • User Training: Simulated phishing tests (e.g., KnowBe4 used by Nepali banks).

Caption: Compare the real NEPSE URL (www.nepse[.]com[.]np) with the phishing clone.

B. Denial-of-Service (DoS) and Distributed DoS (DDoS)

DoS: Overwhelms a system with traffic to crash it (e.g., NTC website during exams). DDoS: Uses botnets (e.g., Mirai) to amplify attacks from thousands of devices.

How DDoS Works (Example: Attack on a Nepali bank’s website):

  1. Botnet Recruitment: Malware infects IoT devices (e.g., cheap routers sold by Daraz).
  2. Command & Control (C2): Attacker sends instructions via IRC or DNS tunnels.
  3. Traffic Flood: Devices send SYN floods or UDP packets to the bank’s server.
  4. Service Disruption: Legitimate users (e.g., trying to transfer money) get timeouts.

Real-World Example: In 2021, Pathao drivers in Kathmandu reported fake "promo codes" that installed malware. The malware then:

  • Joined a DDoS botnet.
  • Participated in attacks on competitor apps (e.g., Yeti) during peak hours.

Defense:

  • Rate Limiting: Blocks excessive requests (e.g., Cloudflare’s DDoS protection).
  • Anycast Routing: Distributes traffic across multiple servers.
  • Sinkholing: Redirects botnet traffic to a controlled server.

3. Password Attacks: Offline vs. Online Dictionary Attacks

Passwords are cracked using brute force or dictionary attacks. The key difference is where the attack happens:

Attack Type Location Speed Risk to Victim Example
Offline Attacker’s machine Faster (no rate limits) Low (no account lockout) Hashcat cracking a leaked database
Online Target system Slower (rate-limited) High (account lockout) Brute-forcing a WhatsApp PIN

A. Offline Dictionary Attack

  1. Obtain Hashes: Attacker steals a password hash database (e.g., from a hacked Daraz vendor account).
  2. Precompute Hashes: Uses tools like Hashcat or John the Ripper to generate hashes for common passwords.
  3. Match Hashes: Compares stolen hashes with precomputed ones to find matches.

Worked Example: Suppose a Ncell employee’s password hash is 5f4dcc3b5aa765d61d8327deb882cf99 (MD5 of "password").

  • Attacker runs:
    hashcat -m 0 -a 0 hashes.txt rockyou.txt
    
  • Result: "password" is cracked in seconds.

Defense:

  • Salting: Adds random data to hashes (e.g., bcrypt).
  • Slow Hashing: Uses Argon2 or PBKDF2 to slow down cracking.
  • Password Policies: Enforce 12+ character passwords with symbols.

B. Online Dictionary Attack

  1. Guess and Check: Attacker submits guesses to the login page.
  2. Rate Limiting: Systems like WhatsApp lock accounts after 5 failed attempts.
  3. Brute Force: If rate limits are bypassed (e.g., via proxies), longer passwords can be cracked.

Worked Example: Cracking a 6-digit WhatsApp PIN with 3 attempts per second:

  • Total tries: 1,000,000 (10^6).
  • Time: ~5.5 hours (if not rate-limited).
  • With rate limiting (5 attempts/min): 33 days.

Defense:

  • Account Lockout: Temporary bans after failed attempts.
  • CAPTCHA: Slows down automated guesses.
  • MFA: Even if PIN is cracked, a second factor (e.g., fingerprint) is needed.

4. Zero-Day Exploits and Advanced Attacks

A zero-day exploit targets an unknown vulnerability before the vendor can patch it.

Real-World Example:

  • WhatsApp Pegasus Spyware (2021): Exploited a buffer overflow in WhatsApp’s voice call feature to install spyware on Nepali journalists’ phones.
  • SolarWinds Hack (2020): Compromised Microsoft’s supply chain to spy on U.S. government agencies.

Defense Strategies:

  1. Sandboxing: Runs untrusted code in isolated environments (e.g., Google Chrome’s site isolation).
  2. Patch Management: Regular updates (e.g., Ncell’s monthly security patches).
  3. Memory Protection: DEP (Data Execution Prevention) stops code from executing in non-executable memory.

5. Incident Response: NIST Framework

When an attack occurs, organizations follow NIST’s 4-step model:

stateDiagram-v2
    [*] --> Preparation
    Preparation --> Detection
    Detection --> Analysis
    Analysis --> Containment
    Containment --> Eradication
    Eradication --> Recovery
    Recovery --> [*]

    state Preparation {
        [*] --> Policy Development
        Policy Development --> Training
        Training --> [*]
    }

    state Containment {
        [*] --> Isolate Systems
        Isolate Systems --> Limit Damage
        Limit Damage --> [*]
    }

Real-World Example: Ncell SIM Swap Fraud Response (2023)

  1. Detection: Ncell’s fraud team noticed unusual SIM re-registration spikes.
  2. Analysis: Found attackers used stolen KYC documents to swap SIMs.
  3. Containment:
    • Temporarily suspended SIM swaps.
    • Added biometric verification for high-risk users.
  4. Recovery:
    • Compensated affected users.
    • Strengthened KYC checks (e.g., video verification).

## In the Real World

  1. eSewa Scams (Phishing + Malware)

    • Idea Used: Phishing emails/SMS with keyloggers (spyware).
    • How It Works:
      • Fake "eSewa transaction failed" SMS → user clicks link → malware steals OTP.
      • Real Example: In 2022, NPR 200 million lost via this method.
    • Defense: eSewa now enforces SMS OTP + App PIN for high-value transactions.
  2. Pathao Driver Data Theft (MITM Attack)

    • Idea Used: Man-in-the-Middle (MITM) on public Wi-Fi.
    • How It Works:
      • Attacker sets up a fake "Pathao Wi-Fi" hotspot at a café.
      • Drivers log in → attacker sniffs credentials via Wireshark.
    • Real Example: 10,000+ Pathao drivers in Pokhara had accounts hacked in 2021.
    • Defense: Pathao now warns users about unsecured networks and uses HTTPS everywhere.
  3. NEPSE Website DDoS (Botnet Attack)

    • Idea Used: DDoS using Mirai botnet.
    • How It Works:
      • Hackers rented a botnet (infected CCTV cameras sold by Daraz).
      • Launched SYN flood during trading hours → website crashed for 2 hours.
    • Real Example: June 2023 NEPSE outage caused NPR 1 billion in trading losses.
    • Defense: NEPSE now uses Cloudflare DDoS protection.

## Exam Tip

  1. Definitions Matter:

    • Threat: Potential danger (e.g., "SQL injection is a threat to NEPSE’s website").
    • Attack: Actual execution (e.g., "Hackers exploited SQLi to leak NEPSE shareholder data").
    • Vulnerability: Weakness (e.g., "Unpatched WordPress plugins are vulnerabilities").
  2. Compare Offline vs. Online Attacks:

    • Offline: Faster, no rate limits, needs stolen hashes.
    • Online: Slower, risks account lockout, needs live system access.
  3. Real-World Scenarios:

    • Phishing: Always tie to eSewa/Khalti/Ncell (e.g., "Describe how a fake eSewa SMS leads to malware installation").
    • DDoS: Relate to NEPSE/Daraz outages (e.g., "How would you mitigate a DDoS on nepse[.]com[.]np?").
    • Malware: Use ILOVEYOU (virus), WannaCry (ransomware), Emotet (Trojan) as examples.
  4. Diagrams in Exams:

    • Draw a kill chain for a phishing attack (e.g., email → exploit → C2 → data theft).
    • Compare malware types in a table (as shown above).
    • Show a DDoS attack flow (botnet → victim → traffic flood).
  5. Short Notes Questions:

    • Phishing Attack:
      • Definition: Fraudulent attempt to obtain sensitive data via disguise.
      • Types: Spear phishing, vishing, smishing.
      • Example: Fake NEPSE login page.
      • Defense: MFA, email filtering.
    • Two-Factor Authentication (2FA):
      • Definition: Two-step verification (e.g., password + OTP).
      • Types: SMS, app-based (Google Authenticator), biometric.
      • Example: eSewa uses OTP + App PIN for transactions.
  6. Numerical Questions:

    • If asked about password cracking time, always:
      1. State the password length and character set (e.g., 6-digit PIN = 10^6 possibilities).
      2. Assume a guessing rate (e.g., 3 attempts/second).
      3. Calculate total time (e.g., 10^6 / 3 = 333,333 seconds ≈ 3.8 days).
      4. Add rate limiting (e.g., "With 5 attempts/min, this takes 33 days").

## Summary Checklist

Before the exam, ensure you can: ✅ Define malware types (virus, worm, Trojan, ransomware, spyware) and give Nepali examples. ✅ Explain phishing, DDoS, MITM, and zero-day attacks with real-world cases. ✅ Compare offline vs. online password attacks and calculate cracking times. ✅ Draw a kill chain diagram for a cyber attack (e.g., phishing → malware → data theft). ✅ Describe NIST’s incident response steps and apply them to Ncell/SIM swap fraud. ✅ List defenses for each attack type (e.g., firewalls for DDoS, MFA for phishing).

Based on the TU BIT syllabus for Information Security (BIT303), unit 8.

Discussion

Loading…