Cyber Security Basics 📂 Slides · 2 of 11 38 min read

Cybersecurity Basics: Malware, Ransomware, Phishing & Social Engineering — Interactive Slides

An interactive 19-slide walkthrough of the four threats behind 82% of every data breach — malware, ransomware, phishing and social engineering. Real cases from AIIMS Delhi, WannaCry, Colonial Pipeline, MGM Resorts and the $121M Facebook–Google invoice fraud. Includes the 5-stage malware infection cycle, ransomware kill chain, 7 phishing red flags, Indian-context scams, defence playbook and 8 non-negotiable golden rules of cyber hygiene.

🛡️

Cybersecurity Basics

Malware, Ransomware, Phishing & Social Engineering — the four threats behind more than 82% of every breach that ever happened.
Malware Ransomware Phishing Social Engineering

Press Next → or use ← → arrow keys

Section 01

The Digital Underworld

Every second, thousands of attacks probe the internet — most never make headlines because they succeed silently. Firewalls and antivirus aren't your first line of defence. You are.

🌐
The Uncomfortable Truth

Over 82% of all data breaches involve a human element — a click, a reply, a reused password, a moment of trust. The strongest firewall can't stop an employee who voluntarily opens the door.

82%Breaches involve humans
36%Start with phishing
99.9%Attacks MFA blocks
45%Plug in found USB drives
🎯
Your Real Goal

You cannot become hack-proof. You can become a harder target than the next person — and that is the entire game.

Section 02

Malware — The Four Faces of Malicious Code

Malware is any program designed to harm, steal, spy, or take over a device — without the owner's consent. It has four classic faces:

🦠
Virus
needs a host
Attaches to a legitimate file (Word doc, .exe). Activates when the host is opened. Spreads by file-sharing.
🪱
Worm
self-replicating
No host needed. No click needed. Crawls networks on its own. WannaCry hit 200,000 machines in 150 countries in 24 hours.
🐴
Trojan
disguised
Poses as legit software — cracked games, "free" PDFs, fake antivirus. You install it yourself. Powers most modern banking malware.
👁️
Spyware
silent watcher
Runs in the background. Steals keystrokes, screenshots, camera, browsing history. Pegasus spied on journalists worldwide.
🔐
Ransomware
digital kidnapping
Encrypts your files with unbreakable crypto and demands Bitcoin for the key. The most profitable cybercrime of the decade.
🕳️
Rootkit
deep infection
Embeds inside the OS kernel — deeper than antivirus can see. Full control for the attacker. Often requires a full OS reinstall.
⚠️
Cracked Software = Malware Lottery

Cybersecurity Ventures found over 1 in 3 cracked apps contains hidden malware. You save ₹5,000 on a licence — and pay with your bank account.

Section 03

How Malware Actually Infects You

Every malware infection follows the same 5-stage lifecycle — from arrival to objective.

01
Delivery
Phishing email, fake app download, or a USB "found" in the car park. The payload is placed within your reach.
02
Execution
You open the attachment, run the installer, plug in the USB. The malware now runs with your permissions.
03
Persistence
It hides in startup entries, scheduled tasks, registry keys — so a reboot doesn't kill it.
04
Command & Control
Your machine phones home to the attacker's server, awaiting orders — steal data, mine crypto, join a botnet, or drop ransomware.
05
Objective
Exfiltrate files, encrypt drives, or weaponise your device to attack others. Payday for the attacker.
Section 04

Real Malware That Changed History

YearMalwareWhat It DidDamage
2000ILOVEYOUEmail worm — destroyed files, mass-mailed itself via Outlook contacts$10B+ / 50M PCs
2010StuxnetNation-state worm that physically destroyed Iranian uranium centrifugesDelayed Iran's nuclear program 2+ years
2016Mirai BotnetInfected internet cameras & routers using default passwords1.2 Tbps peak attack
2020SolarWindsMalicious code slipped into legitimate software updates — 18,000 orgs, incl. US Treasury & Microsoft$100B+ cleanup
2023Pegasus (India)Spyware on phones of journalists, opposition leaders, activistsSC probe ongoing
📌
The Pattern

Every case above had one thing in common — a human weakness: a default password, an unpatched system, a signed update that shouldn't have been trusted.

Section 05

Ransomware — Digital Kidnapping

AIIMS Delhi — November 2022
India's top hospital woke up to every system encrypted — patient records, MRI scans, billing, appointments. Everything locked.

For 15 days, one of the world's busiest hospitals ran on paper registers. Surgeries were postponed. Admissions delayed. Data of ~40 million patients was accessed by attackers, traced back to a Chinese-origin ransomware group.

Not one line of malware was manually typed inside AIIMS. Someone, somewhere, clicked the wrong link — and India's healthcare crown jewel fell to its knees.
🔒
What Ransomware Actually Does

Locks your files with military-grade encryption and demands crypto (Bitcoin, Monero) for the key. Modern gangs use "double extortion" — they steal your data first, then threaten to leak it if you don't pay.

Section 06

Anatomy of a Ransomware Attack

Most ransomware attacks unfold in six near-identical stages — often over weeks, silently.

⚔️ THE 6-STAGE KILL CHAIN
Stage 1
Initial Access — phishing email, stolen RDP credentials, or unpatched VPN gateway.
Stage 2
Reconnaissance — attackers silently map your network for days or weeks, finding backups and crown-jewel systems.
Stage 3
Privilege Escalation — steal admin credentials, often via unpatched Windows domain controllers.
Stage 4
Data Exfiltration — quietly upload sensitive files to attacker cloud storage. Now they have leverage.
Stage 5
Backup Destruction — locate and wipe shadow copies, cloud backups, offline drives. No recovery path.
Stage 6
Encryption & Ransom Note — every mapped drive encrypted in minutes. A note lands on every desktop with a countdown timer.
Section 07

Ransomware That Made Global News

YearTargetWhat HappenedLoss
2017WannaCry (global)Worm-ransomware hybrid crippled UK's NHS — 19,000 appointments cancelled. Hit FedEx, Renault, Telefónica.$4B+
2021Colonial Pipeline (USA)Largest US East Coast fuel pipeline shut down. Petrol shortages in 17 states.$4.4M paid
2021JBS FoodsWorld's biggest meat processor stopped in US, Canada, Australia. REvil ransomware.$11M in Bitcoin
2022AIIMS DelhiIndia's top hospital paralysed for 2 weeks. 40M patient records at risk.Ransom refused
2023MGM ResortsSlot machines, hotel keys, ATMs disabled across Las Vegas. Cracked via IT help desk.$100M lost
Section 08

Should You Pay the Ransom?

❌ Why You Shouldn't
Only ~60% of payers get working keys
Funds the next attack — on schools, hospitals
You go on a "pays" list. Repeat target.
Doesn't stop leaked data from being sold
In the US (OFAC) and UK, may be illegal
✅ What To Actually Do
Isolate the machine — pull cable, kill Wi-Fi
Report to cybercrime.gov.in / dial 1930
Preserve evidence — don't wipe
Restore from offline, air-gapped backups (3-2-1)
Check nomoreransom.org — free decryptors for 170+ families
💾
The 3-2-1 Backup Rule

3 copies of your data, on 2 different media types, with 1 copy stored offline and off-site. An untested backup is a hope, not a plan — test restore quarterly.

Section 09

Phishing — The Art of Digital Deception

How Facebook & Google lost $121 million to fake invoices
Between 2013–2015, a Lithuanian named Evaldas Rimasauskas set up a fake company mimicking Quanta Computer (a real Taiwan hardware supplier). He sent ordinary-looking invoices to the accounts payable teams at Facebook and Google.

Over two years, they wired $121 million to his accounts. No malware. No zero-day. Just plausible emails and matching bank details. Arrested in 2019 — only half the money was recovered.

Two of the most secure companies on Earth were beaten by paperwork.
🎣
What Phishing Really Is

Impersonating a trusted person or brand — over email, SMS or phone — to trick you into handing over credentials, money, or installing malware. Verizon's 2024 report: 36% of all breaches start with phishing.

Section 10

The Phishing Family Tree

📧
Bulk Phishing
wide net
"Your parcel could not be delivered." Sent to millions. A 0.1% success rate = thousands of victims.
🎯
Spear Phishing
targeted
Handcrafted for one person. Attacker mines LinkedIn & Instagram to build a believable pretext.
🐋
Whaling
CEO fraud
Targets CEOs, CFOs, their EAs — to authorise wire transfers or leak M&A data.
📱
Smishing
SMS-based
"Your KYC has expired — update at bit.ly/xxx." SBI, HDFC, ICICI customers are prime targets in India.
📞
Vishing
voice call
"Amazon Customer Support" or "Delhi Police" calls with fake urgency. Demand UPI or gift-card payment.
👥
Clone Phishing
near-perfect copy
Attacker copies a real email you've received before, replaces the link. Almost impossible to spot.
Section 11

Spot a Phishing Email in 30 Seconds

1️⃣
Sender's real address — hover the name. support@arnazon-in.com is not Amazon. Extra letters, hyphens, weird domains.
2️⃣
Urgency & fear — "Account closes in 24 hours!" Real banks never rush you. Panic is the phishing signature.
3️⃣
Generic greetings — "Dear Customer" from a service that knows your name = suspicious.
4️⃣
Hover before clicking — the real URL shows at the bottom. If it doesn't match, delete.
5️⃣
Unexpected attachments.zip .exe .iso .html or Office files asking "Enable Content" (macros). Never open.
6️⃣
Bad grammar or layout — odd spacing, mixed fonts, blurry logos. Big brands hire copywriters; scammers use Google Translate.
7️⃣
Requests for secrets — no legitimate org ever asks for your password, OTP, CVV or PIN. Ever.
⏱️
The 30-Second Rule

When in doubt, pause for 30 seconds and call the company on a number you already trust — not the one in the suspicious email. Scammers survive on urgency. Slowness kills them.

Section 12

Phishing in the Indian Context

ScamMethodReal Example
Fake KYC UpdateSMS/WhatsApp — "Bank/PAN/Aadhaar KYC expired"; link steals credentialsRBI issued 6+ warnings on SBI & HDFC KYC scams (2022–24)
Electricity Bill ScamSMS threatening disconnection; fake payment portalMillions hit in Delhi, Mumbai, Bengaluru in 2023
Courier / CustomsVishing — "parcel contains contraband, transfer to clear"Bengaluru software engineer lost ₹1.2 crore in one day
Digital ArrestFake CBI/police video calls — "Aadhaar misused for money laundering"PM Modi warned citizens in Oct 2024 Mann Ki Baat
Job Offer ScamWhatsApp part-time work (like YouTube videos for ₹150). Small payouts build trust, then "invest" for big returnsEst. ₹1,000 crore+ lost by Indians in 2023
🚨
If it Already Happened

Dial 1930 or file at cybercrime.gov.in within the "Golden Hour". Banks can freeze fraudulent transfers if reported fast. Delays caused by shame lose the money.

Section 13

Social Engineering — Hacking the Human

Frank Abagnale Jr. — the man who cashed $2.5M in fake cheques
Between 1963–69, Frank Abagnale impersonated airline pilots, pediatricians, lawyers and professors. He cashed over $2.5 million in forged cheques across 26 countries — never picking a lock or writing a virus.

He wore the right uniform. Spoke with confidence. People handed him access. Spielberg's Catch Me If You Can (2002) tells the story.

Modern hackers do exactly the same thing — with digital uniforms.
📞
MGM Resorts, 2023

Attackers found an MGM IT employee on LinkedIn, then called the help desk pretending to be that person and asked for a password reset. 10 minutes on the phone → access to a $100M infrastructure. No malware. No exploit. Just a phone call.

Social engineering hacks psychology, not technology. It exploits trust, authority, fear, urgency, curiosity, greed. A $10M firewall can be walked around with a $1 phone call.

Section 14

Classic Social Engineering Techniques

👀
Shoulder Surfing
Watching you type PINs, passwords or OTPs — at ATMs, cafés, airport lounges. HD phone cameras make it trivial from metres away.
🗑️
Dumpster Diving
Rifling through discarded printouts, sticky notes, courier receipts. Bank statements are gold and most people throw them away as-is.
🎪
Pretexting
"Hi, this is Rahul from IT — we saw suspicious activity, can you confirm your login?" A believable story makes handing over credentials feel helpful.
🎁
Baiting
A USB labelled "Salary Review 2026 — CONFIDENTIAL" dropped in the car park. Studies show ~45% of people plug it in. Malware in seconds.
🚪
Tailgating
Following an employee through a secure door, arms full of coffee — "Hold the door?" Politeness bypasses badge readers every day.
🤝
Quid Pro Quo
"Free tech support!" or "Win a gift card — just answer these quick questions" — including your DOB and mother's maiden name.
🎬
Cyber Cinema Syllabus

Watch: Catch Me If You Can (2002), Mr. Robot (2015), Sneakers (1992), Blackhat (2015), and India's Jamtara — Sabka Number Ayega on Netflix. Better cybersecurity training than most corporate courses.

Section 15

Defence Playbook — What Actually Protects You

🔐
Multi-Factor Auth
MFA everywhere
Even if your password leaks, MFA blocks 99.9% of account takeovers (Microsoft). Prefer authenticator apps over SMS — SMS is vulnerable to SIM-swapping.
💾
3-2-1 Backups
tested restores
3 copies, 2 media types, 1 offline & off-site. Test restore quarterly. Backups you've never restored from are hope, not plans.
🩹
Patch Ruthlessly
auto-update
WannaCry only worked because a patch existed for 2 months and admins hadn't applied it. Zero-days are rare — unpatched systems are everywhere.
🗝️
Password Manager
Bitwarden, 1Password
Unique, complex password for every site behind one strong master. Never reuse. Never write on a sticky note.
📬
Email Filtering
SPF · DKIM · DMARC
Enable on your domain to stop brand spoofing. On receiving side, use Defender / Google Workspace / Proofpoint for advanced filtering.
🎓
Awareness Training
quarterly sims
Simulated phishing drops click rates from ~30% to under 5% in one year. Culture beats controls. Train, don't blame.
Section 16 · Part 1

Golden Rules — Non-Negotiable Cyber Hygiene

🛡️ THE 8 COMMANDMENTS · RULES 1–4
1
Assume every unexpected message is a scam. Banks, courts, courier companies do not WhatsApp you demanding instant action. Trust the gut feeling when something feels off.
2
Never share OTPs, PINs, CVVs, or passwords. No legitimate bank, police officer, or tech-support agent will ever ask. Anyone who does is a criminal.
3
Turn on multi-factor authentication. Email, banking, WhatsApp, Instagram — all of them. Email is the master key; protect it like a passport.
4
Update everything, always. Phones, laptops, browsers, apps, routers. Every update notification is a door being closed on an attacker — not a nuisance.
Section 16 · Part 2

Golden Rules — Rules 5 to 8

🛡️ THE 8 COMMANDMENTS · RULES 5–8
5
Back up important files offline. An external drive kept unplugged is immune to ransomware. Cloud-only backups can be encrypted along with everything else if an attacker gets in.
6
Shred sensitive paper. Wipe old drives. Dumpster diving is not fiction. Bank statements, courier labels, payslips — shred them. Physically destroy or securely wipe hard drives before disposal.
7
Cover your keypad. At ATMs and public keyboards, assume a camera or a curious neighbour. Two seconds of caution > two months of fraud recovery.
8
Report scams immediately. In India: dial 1930 or file at cybercrime.gov.in within the "Golden Hour". Banks can freeze money if you're fast. Shame is expensive.
FINAL

Stay Curious. Stay Skeptical. Stay Safe.

82%Breaches involve humans
99.9%Attacks MFA blocks
<5%Click-rate after training
60%Ransom payers who get keys
36%Breaches start with phishing
1930India's cyber-crime helpline
🎯
The Real Goal

You will never be "hack-proof". Aim to be a harder target than the next person. Attackers are opportunists — raise the cost of attacking you, and they'll move on. That is the entire game.

📚
Keep Learning

Read Verizon DBIR yearly. Follow Krebs on Security and The Hacker News. Watch Mr. Robot. The threat landscape changes every quarter — your defences should too.

🛡️ End of tutorial · Press to review, or click Restart