Cyber Security Basics
📂 Cyber for Students
· 2 of 6
36 min read
Malware, Ransomware, Phishing & Social Engineering
A practical guide to the four biggest digital threats — malware, ransomware, phishing, and social engineering. Learn how attackers actually break in through real cases like the AIIMS Delhi ransomware attack, the $121 million Facebook–Google invoice scam, WannaCry, MGM Resorts, and Jamtara vishing. Includes visual diagrams of shoulder surfing and dumpster diving, a cyber-cinema syllabus, and 8 golden rules to keep your data and money safe.
Section 01
The Digital Underworld — Why Cybercrime Wins
📖 Real World Analogy
The Bank That Never Closes — And Never Locks Its Doors
Imagine a bank vault that holds not gold, but every private message you have ever sent,
every photo of your children, every password to your life. Now imagine that vault has
no walls — only a thin sheet of glass called a password, and the guards go home
at night. That is your digital life in 2026.
Cybercriminals do not need to pick locks, wear masks, or dodge bullets. They send a
single email, and thousands hand over the keys willingly. Understanding how
they do it is the only real defence — because your antivirus cannot save you from
your own click.
This tutorial covers the four horsemen of modern cybercrime — Malware,
Ransomware, Phishing, and Social Engineering.
You will see real headlines, real losses, and the exact tricks attackers use every single day.
By the end you will read a suspicious email the way a bomb-disposal expert reads a package.
🛡️
The Core Truth of Cyber Defence
Over 82% of all data breaches involve a human element — a click, a reply,
a reused password, a moment of trust. The strongest firewall in the world cannot stop
an employee who chooses to open the door. Awareness is not one control among
many — it is the perimeter.
Section 02
Malware — The Four Faces of Malicious Code
Malware (short for malicious software) is any program written to
harm, steal, spy on, or take control of a device without the owner's consent. It is not one
thing — it is a family of weapons, each designed for a different job.
🦠
Virus
Needs a host file
Attaches itself to a legitimate file (a Word document, an .exe). Runs only when
the host is opened. Spreads when you share the infected file. Like a biological
virus — dormant until activated.
🐛
Worm
Self-replicating
Needs no host and no user action. Crawls through networks on its own by exploiting
software bugs. The 2017 WannaCry worm infected 200,000 machines in
150 countries in under 24 hours.
🏇
Trojan
Disguised as safe
Looks like a useful app — a cracked game, a "free" invoice PDF, a fake antivirus.
You install it yourself. Named after the Trojan Horse of Greek myth. Most banking
malware today is a Trojan.
👁️
Spyware
Silent watcher
Records keystrokes, screenshots, camera feeds, and browsing history — then sends
it home. Pegasus spyware, made by NSO Group, has been used against
journalists, activists, and heads of state worldwide.
Two More You Must Know
🔒
Ransomware
Encrypts & extorts
Locks your files with unbreakable encryption and demands payment in cryptocurrency.
Covered in depth in Sections 05–08. The single most profitable cybercrime of the decade.
🤖
Adware & PUPs
Potentially Unwanted
Floods your browser with ads and hijacks searches. Usually bundled with free software.
Not always destructive but always resource-hungry and privacy-invasive.
👻
Rootkit
Deepest, hardest to remove
Buries itself in the operating system kernel — deeper than your antivirus can see.
Once installed, the attacker owns the machine. Often requires a full OS reinstall
to remove.
⚠️
Cracked Software Is a Trap
Never install cracked versions of paid software. Studies by Cybersecurity
Ventures show over 1 in 3 cracked apps contains hidden malware.
You saved £120 on Photoshop and gave attackers your bank passwords. Bad trade.
Section 03
How Malware Actually Infects You
01
Delivery — The Lure
An attacker sends a phishing email, uploads a fake app to a download site, or plants a malicious USB drive in a car park. The bait waits.
02
Execution — The Click
You open the attachment, run the installer, or plug in the USB. The malicious code runs with your permissions. Antivirus may miss it if the malware is brand-new (a "zero-day" variant).
03
Persistence — The Foothold
Malware writes itself into startup entries, scheduled tasks, and registry keys so it survives every reboot. Even if you notice something odd, it comes back.
04
Command & Control (C2)
The infected machine "phones home" to a server the attacker controls, waiting for instructions — steal files, mine cryptocurrency, join a botnet, or launch ransomware.
05
Objective — The Payoff
Data is exfiltrated, files are encrypted, or your device becomes a weapon used to attack others. The attacker cashes out. You find out weeks — sometimes years — later.
Section 04
Real Malware in the Headlines
Year
Malware
What Happened
Damage
2000
ILOVEYOU
Email attachment "LOVE-LETTER-FOR-YOU.txt.vbs" — a worm that overwrote files and mailed itself to every contact in Outlook.
$10 billion+ globally, 50 million PCs infected
2010
Stuxnet
Nation-state worm that physically destroyed centrifuges at Iran's Natanz uranium enrichment facility. First malware to cause real-world industrial damage.
Delayed Iran's nuclear program by 2+ years
2016
Mirai Botnet
Infected internet-connected cameras and routers using default passwords, then used them to knock major sites (Twitter, Netflix, Reddit) offline.
Peak attack: 1.2 Tbps — largest of its era
2020
SolarWinds / SUNBURST
Attackers slipped malicious code into a legitimate software update from SolarWinds. 18,000 organisations installed the backdoor — including US Treasury, DHS, and Microsoft.
Cleanup cost: $100 billion+ estimated
2023
Pegasus (India)
Reports in The Wire and The Washington Post revealed Pegasus spyware on phones of Indian journalists, opposition leaders, and activists.
Ongoing Supreme Court probe in India
📰
Newspaper Reference
The Times of India, The Hindu, and BBC News have all extensively
covered the Pegasus spyware investigations. Search "Pegasus Project" for the coordinated
2021 investigation by 17 media outlets that exposed the global scale.
Section 05
Ransomware — Digital Kidnapping
📖 Real Story
The Hospital That Went Back to Pen and Paper
November 2022, New Delhi. Doctors at AIIMS — India's premier hospital —
arrive for their morning shift and find every computer screen locked. Patient records,
MRI scans, billing systems, appointment schedules — all encrypted. A note demands
payment in cryptocurrency to unlock the files.
For 15 days, AIIMS ran a 2,300-bed super-specialty hospital on paper
registers. Surgeries were delayed. Patients waited hours to be admitted. The attack was
later linked to a Chinese-origin ransomware group. The stolen data of 4 crore patients
remains a national security concern.
— reported extensively by The Hindu, Times of India, and Indian Express, Nov–Dec 2022.
Ransomware is malware with one goal: encrypt every file it can reach with
military-grade cryptography, then demand payment (usually in Bitcoin or Monero) for the
decryption key. Modern ransomware also steals the files first — so even if you
refuse to pay, the attacker threatens to leak your data publicly. This is called
double extortion.
Section 06
Anatomy of a Ransomware Attack
🌕 The 6-Stage Ransomware Kill Chain
Stage 1
Initial Access — A phishing email with a malicious Word/Excel attachment, a compromised RDP password, or an unpatched VPN gateway lets the attacker in.
Stage 2
Reconnaissance — The attacker quietly maps the network for days or weeks. What's here? Where are the backups? Which server holds the crown jewels?
Stage 3
Privilege Escalation — They steal admin credentials, often from an unpatched Windows domain controller.
Stage 4
Data Exfiltration — Sensitive files are silently uploaded to attacker-controlled cloud storage. This is the "double extortion" leverage.
Stage 5
Backup Destruction — Shadow copies, cloud backups, and offline drives are located and deleted. You cannot restore what does not exist.
Stage 6
Encryption & Ransom Note — Files across every mapped drive are encrypted in minutes. A ransom note appears on every desktop with a countdown timer and payment instructions.
Section 07
Ransomware Headlines That Shook the World
Year
Target
Attack & Impact
Ransom / Loss
2017
WannaCry (Global)
Worm-ransomware hybrid crippled the UK's NHS — 19,000 appointments cancelled, ambulances diverted. Also hit FedEx, Renault, and Telefónica.
$4 billion+ global losses
2021
Colonial Pipeline (USA)
DarkSide ransomware shut down the largest fuel pipeline on the US East Coast. Petrol shortages and panic buying across 17 states.
$4.4 million paid (partially recovered by FBI)
2021
JBS Foods
World's largest meat processor forced to halt operations across the US, Canada, and Australia. REvil ransomware.
$11 million paid in Bitcoin
2022
AIIMS Delhi
India's top hospital paralysed for 2 weeks. Patient records of 4 crore people compromised. Manual operations for surgeries.
Ransom refused; recovery cost crores of rupees
2023
MGM Resorts
Slot machines, hotel key cards, and ATMs went dead across Las Vegas. Attackers used social engineering on the IT help desk (see Section 13).
$100 million in lost revenue
Section 08
Should You Pay the Ransom?
❌ Reasons NOT to Pay
Only ~60% of victims who pay actually get working decryption keys.
Paying funds the next attack — including attacks on hospitals and schools.
You are now marked as a "payer" — attackers share this list and re-target you.
Payment does not stop the leak of already-stolen data.
In many jurisdictions (US OFAC, UK), paying certain sanctioned groups is illegal.
✅ The Right Response
Isolate — pull network cables and disable Wi-Fi on infected machines immediately.
Report — in India, file at cybercrime.gov.in and dial 1930.
Preserve evidence — do NOT wipe machines; forensics need them.
Restore from offline, air-gapped backups (the 3-2-1 rule — Section 16).
Check nomoreransom.org — a free EU project with decryptors for 170+ ransomware families.
Section 09
Phishing — The Art of Digital Deception
📖 Real Story
The Facebook & Google $121 Million "Invoice"
Between 2013 and 2015, a Lithuanian man named Evaldas Rimasauskas did
something almost comically simple. He set up a fake company with the same name as
Quanta Computer — a real Taiwan-based hardware supplier used by both Facebook
and Google. Then he emailed invoices to accounts payable teams at both giants.
They paid. Repeatedly. Over two years, Facebook and Google wired
$121 million to bank accounts controlled by a scammer in Lithuania —
all through ordinary-looking invoice emails. He was eventually arrested and
sentenced in 2019, but only about half the money was recovered.
— reported by Reuters, BBC, and The New York Times, March 2019.
Phishing is the act of impersonating a trusted person or brand — usually
by email, SMS, or phone call — to trick you into handing over credentials, money, or
installing malware. It is the most common cyberattack on earth. Verizon's 2024
Data Breach Investigations Report attributes over 36% of breaches to
phishing as the initial vector.
Section 10
The Phishing Family Tree
📧
Bulk Phishing
Spray & pray
Millions of generic emails — "Your parcel could not be delivered," "Your Netflix
account is suspended." Even a 0.1% success rate means thousands of victims.
🏹
Spear Phishing
Targeted attack
Highly customised email aimed at one person. The attacker knows your name, boss,
recent project, and lunch spot — often researched from LinkedIn and Instagram.
🐇
Whaling
CEO fraud
Spear phishing aimed at the top — CEOs, CFOs, executive assistants. The prize:
wire transfer authorisation or access to sensitive M&A data.
📱
Smishing
SMS phishing
"Your KYC has expired — update now at bit.ly/xxx." Fake bank SMS is a plague in
India — SBI, HDFC, and ICICI users are prime targets.
📞
Vishing
Voice phishing
A phone call from "Amazon Customer Support" or "Delhi Police" about a suspicious
package or arrest warrant. Payment is demanded urgently via UPI or gift cards.
📁
Clone Phishing
Legit email, malicious link
Attacker copies a real email you already received (e.g. a company newsletter) and
re-sends it with the links swapped to malicious ones. Almost impossible to spot.
Section 11
How to Spot a Phishing Email in 30 Seconds
🔍 The 7 Red Flags — Check Every One
Check 1
Sender's real address — Hover over the name. support@arnazon-in.com is not Amazon. Look for extra letters, hyphens, and foreign domains.
Check 2
Urgency & fear — "Your account will be closed in 24 hours." Real banks and Google never write like that. Panic is a phishing signature.
Check 3
Generic greeting — "Dear Customer" or "Dear User" from a service that knows your name. Suspicious.
Check 4
Hover before you click — On desktop, hover the link (don't click). The real URL appears at the bottom. If it doesn't match, delete the email.
Check 5
Unexpected attachments — .zip, .exe, .iso, .html files, or Office docs asking you to "Enable Content" (macros). Never open without verification.
Check 6
Grammar & layout — Odd spacing, mixed fonts, low-res logos, awkward phrasing. Big brands hire copywriters; scammers use translation apps.
Check 7
Requests for secrets — Passwords, OTPs, CVV, PIN. No legitimate organisation ever asks for these. Ever.
💡
The 30-Second Rule
When in doubt, pause for 30 seconds and call the organisation back
on a number you look up yourself (not the number in the email). Scammers rely on
speed and panic — deliberate slowness is your armour.
Section 12
Phishing in the Indian Context
Scam Type
How It Works
Real Case
Fake KYC update
SMS or WhatsApp claiming your bank/PAN/Aadhaar KYC has lapsed. Link leads to a fake login page that steals credentials.
RBI issued 6+ public warnings between 2022–2024 about SBI & HDFC KYC scams (Livemint, Economic Times).
Electricity bill scam
SMS: "Your power will be disconnected tonight. Pay pending bill immediately." Link opens a fake bill portal.
Millions targeted across Delhi, Mumbai, Bengaluru in 2023 (Times of India and Delhi Police advisories).
Courier / customs scam
Vishing call: "Your FedEx parcel contains contraband. Cooperate or face arrest." Victim is coerced into transferring lakhs.
Bengaluru software engineer lost ₹1.2 crore in a single day (The Hindu, July 2023).
Digital arrest
Video call from fake "CBI/police officer" claiming your Aadhaar was used for money laundering. Victim is "held under digital arrest" until payment.
PM Modi warned citizens in his October 2024 Mann Ki Baat broadcast (covered by Indian Express, NDTV).
Job offer scam
WhatsApp offer for "part-time work-from-home" — like/rate YouTube videos for ₹150 each. Small payouts to build trust, then huge "investment" demands.
Estimated ₹1,000 crore+ lost by Indians in 2023 (Ministry of Home Affairs report).
Section 13
Social Engineering — Hacking the Human
🎬 Movie & True Story
Catch Me If You Can — The Original Social Engineer
Between 1963 and 1969, teenager Frank Abagnale Jr. impersonated a
Pan Am airline pilot, a paediatrician, a lawyer, and a university professor —
cashing over $2.5 million in forged cheques across 26 countries.
He never picked a lock, never wrote a virus. He wore the right uniform, spoke with the
right confidence, and people handed him the keys.
Steven Spielberg turned his story into the 2002 film "Catch Me If You Can"
(starring Leonardo DiCaprio and Tom Hanks). Every cyber-security student should watch it —
because every modern hacker uses the exact same playbook. The uniforms are just digital now.
Social engineering is the art of manipulating people into breaking normal
security procedures. It exploits psychology — trust, authority, fear, urgency, curiosity,
greed — not technology. It is the reason a $10 million firewall can be bypassed by a
$1 phone call.
🔒
The MGM Resorts Attack, 2023
Attackers looked up an MGM IT employee on LinkedIn, then called the company's help
desk pretending to be that employee needing a password reset. Ten minutes of
conversation gave them keys to a $100 million kingdom. No malware, no exploit —
just a phone call.
Section 14
The Classic Social Engineering Techniques
👀
Shoulder Surfing
Physical observation
Watching someone type a password, PIN, or OTP over their shoulder — at an ATM, a café,
an airport lounge, or on public transport. High-resolution phone cameras make this
trivially easy from metres away.
🗑️
Dumpster Diving
Trash intelligence
Rummaging through discarded printouts, sticky notes, courier receipts, and old
hard drives. Bank statements, credit card offers, and internal memos are gold to
attackers — and most people throw them out whole.
👨💼
Pretexting
Fabricated scenario
"Hi, this is Rahul from IT — we detected suspicious activity on your account, can
you confirm your login?" A convincing story that makes handing over information
feel routine, even helpful.
🍭
Baiting
Curiosity trap
A USB drive labelled "Salary Review 2026 — CONFIDENTIAL" left in a company car park.
Studies show ~45% of people plug in a found USB. It installs
malware in seconds.
🚪
Tailgating
Physical intrusion
Following an employee through a secure door — hands full of coffee, a friendly
"Hold the door?" Politeness bypasses badge readers every day.
🎁
Quid Pro Quo
Something for something
"Free tech support" calls or fake surveys offering gift cards in exchange for a
few "quick questions" — that just happen to include your date of birth and
mother's maiden name.
Visual Diagram — Shoulder Surfing at an ATM
SHOULDER SURFING — HOW IT LOOKS IN REAL LIFE
The attacker doesn't need to steal your card — a clear view of your PIN combined with a skimmer or later card cloning is enough.
Visual Diagram — Dumpster Diving
DUMPSTER DIVING — WHAT ATTACKERS FIND IN YOUR TRASH
Kevin Mitnick — famed reformed hacker — said dumpster diving was one of his most productive reconnaissance tools before the internet made it optional.
Section 15
Watch These Movies — Cyber Cinema Syllabus
Fiction sometimes teaches security better than textbooks. These films dramatise real
attack techniques and get most of the psychology dead right.
🎥
Catch Me If You Can (2002)
True story of Frank Abagnale Jr., master social engineer. Impersonates a pilot, doctor,
and lawyer with nothing but confidence and observation. The blueprint for every
pretexting attack ever written.
social engineering, pretexting
🎥
The Italian Job (2003)
A gold heist built on hacking traffic lights, jamming CCTV, and manipulating people
inside the system. A masterclass in how physical and digital security intersect.
system exploitation, insider threat
🎥
Mr. Robot (TV, 2015–19)
The most technically accurate hacking show ever made — real Kali Linux commands,
real social engineering, real exploits. Elliot's monologues on human vulnerability
are essentially security lectures.
malware, phishing, insider
🎥
Sneakers (1992)
A team of "penetration testers" break into secure buildings for hire. Includes the
classic tailgating scene and voice-impersonation attack that still work in 2026.
tailgating, physical security
🎥
Blackhat (2015)
Depicts real-world critical-infrastructure attacks (power grids, financial markets).
Loosely inspired by Stuxnet. Great for understanding nation-state cyber warfare.
malware, critical infrastructure
🎥
Jamtara — Sabka Number Ayega (Netflix India)
Hindi web series based on the real Jamtara phishing gang of Jharkhand — the small
town that ran India's largest vishing operation. Uncomfortably realistic.
vishing, Indian cybercrime
Section 16
Defence Playbook — What Actually Protects You
🔑
Multi-Factor Authentication (MFA)
Non-negotiable
Even if your password leaks, MFA blocks 99.9% of automated account
takeovers (Microsoft data). Use an authenticator app (Google, Microsoft, Authy) —
SMS OTP is better than nothing but can be SIM-swapped.
💽
The 3-2-1 Backup Rule
Ransomware antidote
Keep 3 copies of every important file, on 2
different media, with 1 copy stored offline/off-site. Test
restores every quarter — an untested backup is a hope, not a plan.
🔧
Patch Ruthlessly
Close the doors
Enable automatic updates on OS, browsers, and apps. WannaCry only worked
because a patch existed for 2 months and admins hadn't applied it.
Zero-day exploits are rare; unpatched systems are everywhere.
👤
Password Manager
Bitwarden, 1Password
One strong master password unlocks a vault of unique, complex passwords for every
site. Never reuse a password. Never write one on a sticky note. Ever.
📡
Email Filtering & DMARC
Kill phishing at the gate
Enable SPF, DKIM, and DMARC on your organisation's domain to stop attackers spoofing
your brand. On the receiving side, use advanced filtering (Microsoft Defender,
Google Workspace, Proofpoint).
👥
Awareness Training
Human firewall
Quarterly phishing simulations reduce click-through rates from ~30%
to <5% within a year. Culture beats controls — train, don't blame.
Section 17
Golden Rules — Non-Negotiable Cyber Hygiene
🛡️ The 8 Commandments of Personal Cybersecurity
1
Assume every unexpected message is a scam until proven otherwise.
Banks, courts, and courier companies do not send you WhatsApp messages demanding
instant action. When your gut says "something's off," trust it.
2
Never share OTPs, PINs, CVVs, or passwords — with anyone, ever.
No legitimate bank, police officer, or tech-support agent will ever ask. Anyone
who does is a criminal, full stop.
3
Turn on Multi-Factor Authentication on email, banking, WhatsApp,
Instagram, and every account that offers it. Your email is the master key — protect
it like your passport.
4
Update everything, always. Phones, laptops, browsers, apps, routers.
That "Update available" notification is not a nuisance — it is a closed door
keeping attackers out.
5
Back up important files offline. An external drive kept unplugged
is immune to ransomware. Cloud-only backups can be encrypted along with your
main files if the attacker gets in.
6
Shred sensitive paper. Wipe old drives. Dumpster diving is not
Hollywood fiction. Shred bank statements, courier labels, and payslips. Physically
destroy or securely wipe hard drives before disposal.
7
Cover your keypad at ATMs and when typing passwords in public.
Assume there is always a camera or a curious eye. Two seconds of caution beats
two months of fraud recovery.
8
If you fall for a scam, report it fast. In India, dial
1930 or report at cybercrime.gov.in within the
"Golden Hour" — banks can freeze fraudulent transfers if reported quickly.
Shame delays reports; delays lose money.
🏆
Final Thought
There is no such thing as being "hack-proof" — only being harder to hack than the
next target. Attackers are opportunists. Every one of the rules above raises the
cost of attacking you so that they move on to easier prey. That is the
whole game. Stay curious, stay sceptical, and never stop learning.