Information SecurityUnit 814 min read
Malware Types, Cyber Attacks & Defense Strategies
Unit 8 of Information Security explores malicious software (malware) types—viruses, worms, Trojans, ransomware, spyware—and cyber attack methods (phishing, DDoS, MITM), their real-world impacts (e.g., eSewa scams, Ncell SIM hijacking), and defensive strategies like firewalls, encryption, and user training. Includes att
TAKEAWAYS:
- Malware spreads via exploits (e.g., unpatched software) or social engineering (e.g., fake eSewa links), and is classified by behavior (infecting, stealing, encrypting) rather than by intent.
- Cyber attacks follow kill chains: reconnaissance → weaponization → delivery → exploitation → installation → command & control → actions on objectives (e.g., Pathao driver data theft).
- Phishing (e.g., fake NEPSE login pages) and DDoS (e.g., Daraz website crashes) exploit human trust and bandwidth limits, respectively—defenses include multi-factor authentication and rate limiting.
- Offline dictionary attacks (precomputed hashes) crack weak passwords like "password123" in seconds, while online attacks risk account lockouts but can brute-force longer passwords if attempts aren’t rate-limited.
- Zero-day exploits (e.g., WhatsApp Pegasus spyware) target unknown vulnerabilities; patch management and sandboxing mitigate them.
- Incident response follows NIST’s 4 steps: Preparation → Detection & Analysis → Containment → Recovery (e.g., Ncell’s SIM swap fraud response).
1. Malicious Software (Malware): Definitions and Classification
Malware is software designed to damage, disrupt, or gain unauthorized access to computer systems. Unlike legitimate programs, malware hides its true intent and often self-replicates or escalates privileges. The syllabus classifies malware by how it infects, spreads, or damages systems:
classDiagram
class Malware {
<<abstract>>
+spreads_via: vector
+damage_type: destructive/stealing/encrypting
}
class Virus {
+attaches_to: executable
+needs_host: true
+examples: ILOVEYOU, Stuxnet
}
class Worm {
+self_replicating: true
+no_host_needed: true
+examples: Morris Worm, WannaCry
}
class Trojan {
+disguised_as: legitimate
+backdoor: true
+examples: Emotet, Zeus
}
class Ransomware {
+encrypts_data: true
+demands_payment: true
+examples: LockBit, WannaCry
}
class Spyware {
+steals_data: true
+keyloggers: true
+examples: Regin, FinFisher
}
Malware <|-- Virus
Malware <|-- Worm
Malware <|-- Trojan
Malware <|-- Ransomware
Malware <|-- SpywareKey Differences
| Type | Spreads Via | Damage Type | Real-World Example | Defense |
|---|---|---|---|---|
| Virus | Host file (e.g., .exe) |
Corrupts files, crashes OS | ILOVEYOU (2000) | Antivirus (heuristic scanning) |
| Worm | Network (no user action) | Consumes bandwidth, spreads | WannaCry (2017 NHS attack) | Firewall, patch management |
| Trojan | Social engineering | Backdoors, data theft | Emotet (banking malware) | Sandboxing, user training |
| Ransomware | Phishing/Exploits | Encrypts files, demands ransom | LockBit (targets hospitals) | Offline backups, immutable storage |
| Spyware | Bundled software, exploits | Steals credentials, logs keystrokes | FinFisher (government surveillance) | Anti-spyware tools, VPNs |
Caption: A ransomware attack on a Kathmandu hospital’s patient records: encryption → ransom note → decryption failure if not paid.
How Malware Infects Systems
- Exploit Kits: Target unpatched software (e.g., Adobe Flash, Java).
- Example: Angler Exploit Kit used in fake Daraz coupon scams.
- Social Engineering: Tricks users into running malware (e.g., "Your eSewa account is locked—click here").
- Drive-by Downloads: Malicious ads or websites inject code when visited.
- Example: Malvertising on YouTube redirects to exploit kits.
- Supply Chain Attacks: Compromises legitimate software (e.g., SolarWinds hack).
2. Cyber Attacks: Types and Mechanisms
Cyber attacks exploit vulnerabilities in hardware, software, or human behavior. The syllabus categorizes them by target and method:
mindmap
root((Cyber Attacks))
Threats
**Passive**
Eavesdropping
Traffic Analysis
**Active**
Interruption (DoS/DDoS)
Masquerade (Spoofing)
Fabrication (Fake data)
Attack Vectors
**Network-Based**
DDoS (e.g., Mirai botnet)
MITM (e.g., Evil Twin Wi-Fi)
**Host-Based**
Buffer Overflow (e.g., Heartbleed)
Privilege Escalation
**Application-Based**
SQL Injection (e.g., NEPSE website hacks)
XSS (Cross-Site Scripting)
Defense Strategies
**Preventive**
Firewalls, Encryption
**Detective**
IDS/IPS, Log Analysis
**Corrective**
Patch Management, Incident ResponseA. Phishing and Social Engineering
Phishing tricks users into revealing sensitive data (e.g., eSewa PINs, Ncell passwords). Variants include:
- Spear Phishing: Targeted at specific individuals (e.g., fake NEPSE CEO emails).
- Whaling: Targets high-value individuals (e.g., bank CEOs).
- Vishing: Voice-based phishing (e.g., "Your SIM is blocked—call this number").
Real-World Example: In 2022, a fake eSewa SMS ("Your transaction failed—verify here") led to NPR 50 million in losses. The attack used:
- Spoofed sender ID (showed as "eSewa Support").
- Phishing link to a cloned eSewa login page.
- Keylogger to steal OTPs.
Defense:
- Multi-Factor Authentication (MFA): Even if credentials are stolen, MFA blocks access.
- Email Filtering: Tools like Microsoft Defender flag suspicious links.
- User Training: Simulated phishing tests (e.g., KnowBe4 used by Nepali banks).
Caption: Compare the real NEPSE URL (www.nepse[.]com[.]np) with the phishing clone.
B. Denial-of-Service (DoS) and Distributed DoS (DDoS)
DoS: Overwhelms a system with traffic to crash it (e.g., NTC website during exams). DDoS: Uses botnets (e.g., Mirai) to amplify attacks from thousands of devices.
How DDoS Works (Example: Attack on a Nepali bank’s website):
- Botnet Recruitment: Malware infects IoT devices (e.g., cheap routers sold by Daraz).
- Command & Control (C2): Attacker sends instructions via IRC or DNS tunnels.
- Traffic Flood: Devices send SYN floods or UDP packets to the bank’s server.
- Service Disruption: Legitimate users (e.g., trying to transfer money) get timeouts.
Real-World Example: In 2021, Pathao drivers in Kathmandu reported fake "promo codes" that installed malware. The malware then:
- Joined a DDoS botnet.
- Participated in attacks on competitor apps (e.g., Yeti) during peak hours.
Defense:
- Rate Limiting: Blocks excessive requests (e.g., Cloudflare’s DDoS protection).
- Anycast Routing: Distributes traffic across multiple servers.
- Sinkholing: Redirects botnet traffic to a controlled server.
3. Password Attacks: Offline vs. Online Dictionary Attacks
Passwords are cracked using brute force or dictionary attacks. The key difference is where the attack happens:
| Attack Type | Location | Speed | Risk to Victim | Example |
|---|---|---|---|---|
| Offline | Attacker’s machine | Faster (no rate limits) | Low (no account lockout) | Hashcat cracking a leaked database |
| Online | Target system | Slower (rate-limited) | High (account lockout) | Brute-forcing a WhatsApp PIN |
A. Offline Dictionary Attack
- Obtain Hashes: Attacker steals a password hash database (e.g., from a hacked Daraz vendor account).
- Precompute Hashes: Uses tools like Hashcat or John the Ripper to generate hashes for common passwords.
- Match Hashes: Compares stolen hashes with precomputed ones to find matches.
Worked Example:
Suppose a Ncell employee’s password hash is 5f4dcc3b5aa765d61d8327deb882cf99 (MD5 of "password").
- Attacker runs:
hashcat -m 0 -a 0 hashes.txt rockyou.txt - Result: "password" is cracked in seconds.
Defense:
- Salting: Adds random data to hashes (e.g.,
bcrypt). - Slow Hashing: Uses Argon2 or PBKDF2 to slow down cracking.
- Password Policies: Enforce 12+ character passwords with symbols.
B. Online Dictionary Attack
- Guess and Check: Attacker submits guesses to the login page.
- Rate Limiting: Systems like WhatsApp lock accounts after 5 failed attempts.
- Brute Force: If rate limits are bypassed (e.g., via proxies), longer passwords can be cracked.
Worked Example: Cracking a 6-digit WhatsApp PIN with 3 attempts per second:
- Total tries: 1,000,000 (10^6).
- Time: ~5.5 hours (if not rate-limited).
- With rate limiting (5 attempts/min): 33 days.
Defense:
- Account Lockout: Temporary bans after failed attempts.
- CAPTCHA: Slows down automated guesses.
- MFA: Even if PIN is cracked, a second factor (e.g., fingerprint) is needed.
4. Zero-Day Exploits and Advanced Attacks
A zero-day exploit targets an unknown vulnerability before the vendor can patch it.
Real-World Example:
- WhatsApp Pegasus Spyware (2021): Exploited a buffer overflow in WhatsApp’s voice call feature to install spyware on Nepali journalists’ phones.
- SolarWinds Hack (2020): Compromised Microsoft’s supply chain to spy on U.S. government agencies.
Defense Strategies:
- Sandboxing: Runs untrusted code in isolated environments (e.g., Google Chrome’s site isolation).
- Patch Management: Regular updates (e.g., Ncell’s monthly security patches).
- Memory Protection: DEP (Data Execution Prevention) stops code from executing in non-executable memory.
5. Incident Response: NIST Framework
When an attack occurs, organizations follow NIST’s 4-step model:
stateDiagram-v2
[*] --> Preparation
Preparation --> Detection
Detection --> Analysis
Analysis --> Containment
Containment --> Eradication
Eradication --> Recovery
Recovery --> [*]
state Preparation {
[*] --> Policy Development
Policy Development --> Training
Training --> [*]
}
state Containment {
[*] --> Isolate Systems
Isolate Systems --> Limit Damage
Limit Damage --> [*]
}Real-World Example: Ncell SIM Swap Fraud Response (2023)
- Detection: Ncell’s fraud team noticed unusual SIM re-registration spikes.
- Analysis: Found attackers used stolen KYC documents to swap SIMs.
- Containment:
- Temporarily suspended SIM swaps.
- Added biometric verification for high-risk users.
- Recovery:
- Compensated affected users.
- Strengthened KYC checks (e.g., video verification).
## In the Real World
eSewa Scams (Phishing + Malware)
- Idea Used: Phishing emails/SMS with keyloggers (spyware).
- How It Works:
- Fake "eSewa transaction failed" SMS → user clicks link → malware steals OTP.
- Real Example: In 2022, NPR 200 million lost via this method.
- Defense: eSewa now enforces SMS OTP + App PIN for high-value transactions.
Pathao Driver Data Theft (MITM Attack)
- Idea Used: Man-in-the-Middle (MITM) on public Wi-Fi.
- How It Works:
- Attacker sets up a fake "Pathao Wi-Fi" hotspot at a café.
- Drivers log in → attacker sniffs credentials via Wireshark.
- Real Example: 10,000+ Pathao drivers in Pokhara had accounts hacked in 2021.
- Defense: Pathao now warns users about unsecured networks and uses HTTPS everywhere.
NEPSE Website DDoS (Botnet Attack)
- Idea Used: DDoS using Mirai botnet.
- How It Works:
- Hackers rented a botnet (infected CCTV cameras sold by Daraz).
- Launched SYN flood during trading hours → website crashed for 2 hours.
- Real Example: June 2023 NEPSE outage caused NPR 1 billion in trading losses.
- Defense: NEPSE now uses Cloudflare DDoS protection.
## Exam Tip
Definitions Matter:
- Threat: Potential danger (e.g., "SQL injection is a threat to NEPSE’s website").
- Attack: Actual execution (e.g., "Hackers exploited SQLi to leak NEPSE shareholder data").
- Vulnerability: Weakness (e.g., "Unpatched WordPress plugins are vulnerabilities").
Compare Offline vs. Online Attacks:
- Offline: Faster, no rate limits, needs stolen hashes.
- Online: Slower, risks account lockout, needs live system access.
Real-World Scenarios:
- Phishing: Always tie to eSewa/Khalti/Ncell (e.g., "Describe how a fake eSewa SMS leads to malware installation").
- DDoS: Relate to NEPSE/Daraz outages (e.g., "How would you mitigate a DDoS on nepse[.]com[.]np?").
- Malware: Use ILOVEYOU (virus), WannaCry (ransomware), Emotet (Trojan) as examples.
Diagrams in Exams:
- Draw a kill chain for a phishing attack (e.g., email → exploit → C2 → data theft).
- Compare malware types in a table (as shown above).
- Show a DDoS attack flow (botnet → victim → traffic flood).
Short Notes Questions:
- Phishing Attack:
- Definition: Fraudulent attempt to obtain sensitive data via disguise.
- Types: Spear phishing, vishing, smishing.
- Example: Fake NEPSE login page.
- Defense: MFA, email filtering.
- Two-Factor Authentication (2FA):
- Definition: Two-step verification (e.g., password + OTP).
- Types: SMS, app-based (Google Authenticator), biometric.
- Example: eSewa uses OTP + App PIN for transactions.
- Phishing Attack:
Numerical Questions:
- If asked about password cracking time, always:
- State the password length and character set (e.g., 6-digit PIN = 10^6 possibilities).
- Assume a guessing rate (e.g., 3 attempts/second).
- Calculate total time (e.g., 10^6 / 3 = 333,333 seconds ≈ 3.8 days).
- Add rate limiting (e.g., "With 5 attempts/min, this takes 33 days").
- If asked about password cracking time, always:
## Summary Checklist
Before the exam, ensure you can: ✅ Define malware types (virus, worm, Trojan, ransomware, spyware) and give Nepali examples. ✅ Explain phishing, DDoS, MITM, and zero-day attacks with real-world cases. ✅ Compare offline vs. online password attacks and calculate cracking times. ✅ Draw a kill chain diagram for a cyber attack (e.g., phishing → malware → data theft). ✅ Describe NIST’s incident response steps and apply them to Ncell/SIM swap fraud. ✅ List defenses for each attack type (e.g., firewalls for DDoS, MFA for phishing).
Based on the TU BIT syllabus for Information Security (BIT303), unit 8.
Discussion
Loading…