Cyber Security Basics 📂 Cyber for Students · 2 of 6 36 min read

Malware, Ransomware, Phishing & Social Engineering

A practical guide to the four biggest digital threats — malware, ransomware, phishing, and social engineering. Learn how attackers actually break in through real cases like the AIIMS Delhi ransomware attack, the $121 million Facebook–Google invoice scam, WannaCry, MGM Resorts, and Jamtara vishing. Includes visual diagrams of shoulder surfing and dumpster diving, a cyber-cinema syllabus, and 8 golden rules to keep your data and money safe.

Section 01

The Digital Underworld — Why Cybercrime Wins

The Bank That Never Closes — And Never Locks Its Doors
Imagine a bank vault that holds not gold, but every private message you have ever sent, every photo of your children, every password to your life. Now imagine that vault has no walls — only a thin sheet of glass called a password, and the guards go home at night. That is your digital life in 2026.

Cybercriminals do not need to pick locks, wear masks, or dodge bullets. They send a single email, and thousands hand over the keys willingly. Understanding how they do it is the only real defence — because your antivirus cannot save you from your own click.

This tutorial covers the four horsemen of modern cybercrime — Malware, Ransomware, Phishing, and Social Engineering. You will see real headlines, real losses, and the exact tricks attackers use every single day. By the end you will read a suspicious email the way a bomb-disposal expert reads a package.

🛡️
The Core Truth of Cyber Defence

Over 82% of all data breaches involve a human element — a click, a reply, a reused password, a moment of trust. The strongest firewall in the world cannot stop an employee who chooses to open the door. Awareness is not one control among many — it is the perimeter.


Section 02

Malware — The Four Faces of Malicious Code

Malware (short for malicious software) is any program written to harm, steal, spy on, or take control of a device without the owner's consent. It is not one thing — it is a family of weapons, each designed for a different job.

🦠
Virus
Needs a host file
Attaches itself to a legitimate file (a Word document, an .exe). Runs only when the host is opened. Spreads when you share the infected file. Like a biological virus — dormant until activated.
🐛
Worm
Self-replicating
Needs no host and no user action. Crawls through networks on its own by exploiting software bugs. The 2017 WannaCry worm infected 200,000 machines in 150 countries in under 24 hours.
🏇
Trojan
Disguised as safe
Looks like a useful app — a cracked game, a "free" invoice PDF, a fake antivirus. You install it yourself. Named after the Trojan Horse of Greek myth. Most banking malware today is a Trojan.
👁️
Spyware
Silent watcher
Records keystrokes, screenshots, camera feeds, and browsing history — then sends it home. Pegasus spyware, made by NSO Group, has been used against journalists, activists, and heads of state worldwide.

Two More You Must Know

🔒
Ransomware
Encrypts & extorts
Locks your files with unbreakable encryption and demands payment in cryptocurrency. Covered in depth in Sections 05–08. The single most profitable cybercrime of the decade.
🤖
Adware & PUPs
Potentially Unwanted
Floods your browser with ads and hijacks searches. Usually bundled with free software. Not always destructive but always resource-hungry and privacy-invasive.
👻
Rootkit
Deepest, hardest to remove
Buries itself in the operating system kernel — deeper than your antivirus can see. Once installed, the attacker owns the machine. Often requires a full OS reinstall to remove.
⚠️
Cracked Software Is a Trap

Never install cracked versions of paid software. Studies by Cybersecurity Ventures show over 1 in 3 cracked apps contains hidden malware. You saved £120 on Photoshop and gave attackers your bank passwords. Bad trade.


Section 03

How Malware Actually Infects You

01
Delivery — The Lure
An attacker sends a phishing email, uploads a fake app to a download site, or plants a malicious USB drive in a car park. The bait waits.
02
Execution — The Click
You open the attachment, run the installer, or plug in the USB. The malicious code runs with your permissions. Antivirus may miss it if the malware is brand-new (a "zero-day" variant).
03
Persistence — The Foothold
Malware writes itself into startup entries, scheduled tasks, and registry keys so it survives every reboot. Even if you notice something odd, it comes back.
04
Command & Control (C2)
The infected machine "phones home" to a server the attacker controls, waiting for instructions — steal files, mine cryptocurrency, join a botnet, or launch ransomware.
05
Objective — The Payoff
Data is exfiltrated, files are encrypted, or your device becomes a weapon used to attack others. The attacker cashes out. You find out weeks — sometimes years — later.

Section 04

Real Malware in the Headlines

Year Malware What Happened Damage
2000 ILOVEYOU Email attachment "LOVE-LETTER-FOR-YOU.txt.vbs" — a worm that overwrote files and mailed itself to every contact in Outlook. $10 billion+ globally, 50 million PCs infected
2010 Stuxnet Nation-state worm that physically destroyed centrifuges at Iran's Natanz uranium enrichment facility. First malware to cause real-world industrial damage. Delayed Iran's nuclear program by 2+ years
2016 Mirai Botnet Infected internet-connected cameras and routers using default passwords, then used them to knock major sites (Twitter, Netflix, Reddit) offline. Peak attack: 1.2 Tbps — largest of its era
2020 SolarWinds / SUNBURST Attackers slipped malicious code into a legitimate software update from SolarWinds. 18,000 organisations installed the backdoor — including US Treasury, DHS, and Microsoft. Cleanup cost: $100 billion+ estimated
2023 Pegasus (India) Reports in The Wire and The Washington Post revealed Pegasus spyware on phones of Indian journalists, opposition leaders, and activists. Ongoing Supreme Court probe in India
📰
Newspaper Reference

The Times of India, The Hindu, and BBC News have all extensively covered the Pegasus spyware investigations. Search "Pegasus Project" for the coordinated 2021 investigation by 17 media outlets that exposed the global scale.


Section 05

Ransomware — Digital Kidnapping

The Hospital That Went Back to Pen and Paper
November 2022, New Delhi. Doctors at AIIMS — India's premier hospital — arrive for their morning shift and find every computer screen locked. Patient records, MRI scans, billing systems, appointment schedules — all encrypted. A note demands payment in cryptocurrency to unlock the files.

For 15 days, AIIMS ran a 2,300-bed super-specialty hospital on paper registers. Surgeries were delayed. Patients waited hours to be admitted. The attack was later linked to a Chinese-origin ransomware group. The stolen data of 4 crore patients remains a national security concern.

— reported extensively by The Hindu, Times of India, and Indian Express, Nov–Dec 2022.

Ransomware is malware with one goal: encrypt every file it can reach with military-grade cryptography, then demand payment (usually in Bitcoin or Monero) for the decryption key. Modern ransomware also steals the files first — so even if you refuse to pay, the attacker threatens to leak your data publicly. This is called double extortion.


Section 06

Anatomy of a Ransomware Attack

🌕 The 6-Stage Ransomware Kill Chain
Stage 1
Initial Access — A phishing email with a malicious Word/Excel attachment, a compromised RDP password, or an unpatched VPN gateway lets the attacker in.
Stage 2
Reconnaissance — The attacker quietly maps the network for days or weeks. What's here? Where are the backups? Which server holds the crown jewels?
Stage 3
Privilege Escalation — They steal admin credentials, often from an unpatched Windows domain controller.
Stage 4
Data Exfiltration — Sensitive files are silently uploaded to attacker-controlled cloud storage. This is the "double extortion" leverage.
Stage 5
Backup Destruction — Shadow copies, cloud backups, and offline drives are located and deleted. You cannot restore what does not exist.
Stage 6
Encryption & Ransom Note — Files across every mapped drive are encrypted in minutes. A ransom note appears on every desktop with a countdown timer and payment instructions.

Section 07

Ransomware Headlines That Shook the World

Year Target Attack & Impact Ransom / Loss
2017 WannaCry (Global) Worm-ransomware hybrid crippled the UK's NHS — 19,000 appointments cancelled, ambulances diverted. Also hit FedEx, Renault, and Telefónica. $4 billion+ global losses
2021 Colonial Pipeline (USA) DarkSide ransomware shut down the largest fuel pipeline on the US East Coast. Petrol shortages and panic buying across 17 states. $4.4 million paid (partially recovered by FBI)
2021 JBS Foods World's largest meat processor forced to halt operations across the US, Canada, and Australia. REvil ransomware. $11 million paid in Bitcoin
2022 AIIMS Delhi India's top hospital paralysed for 2 weeks. Patient records of 4 crore people compromised. Manual operations for surgeries. Ransom refused; recovery cost crores of rupees
2023 MGM Resorts Slot machines, hotel key cards, and ATMs went dead across Las Vegas. Attackers used social engineering on the IT help desk (see Section 13). $100 million in lost revenue

Section 08

Should You Pay the Ransom?

❌ Reasons NOT to Pay
Only ~60% of victims who pay actually get working decryption keys.
Paying funds the next attack — including attacks on hospitals and schools.
You are now marked as a "payer" — attackers share this list and re-target you.
Payment does not stop the leak of already-stolen data.
In many jurisdictions (US OFAC, UK), paying certain sanctioned groups is illegal.
✅ The Right Response
Isolate — pull network cables and disable Wi-Fi on infected machines immediately.
Report — in India, file at cybercrime.gov.in and dial 1930.
Preserve evidence — do NOT wipe machines; forensics need them.
Restore from offline, air-gapped backups (the 3-2-1 rule — Section 16).
Check nomoreransom.org — a free EU project with decryptors for 170+ ransomware families.

Section 09

Phishing — The Art of Digital Deception

The Facebook & Google $121 Million "Invoice"
Between 2013 and 2015, a Lithuanian man named Evaldas Rimasauskas did something almost comically simple. He set up a fake company with the same name as Quanta Computer — a real Taiwan-based hardware supplier used by both Facebook and Google. Then he emailed invoices to accounts payable teams at both giants.

They paid. Repeatedly. Over two years, Facebook and Google wired $121 million to bank accounts controlled by a scammer in Lithuania — all through ordinary-looking invoice emails. He was eventually arrested and sentenced in 2019, but only about half the money was recovered.

— reported by Reuters, BBC, and The New York Times, March 2019.

Phishing is the act of impersonating a trusted person or brand — usually by email, SMS, or phone call — to trick you into handing over credentials, money, or installing malware. It is the most common cyberattack on earth. Verizon's 2024 Data Breach Investigations Report attributes over 36% of breaches to phishing as the initial vector.


Section 10

The Phishing Family Tree

📧
Bulk Phishing
Spray & pray
Millions of generic emails — "Your parcel could not be delivered," "Your Netflix account is suspended." Even a 0.1% success rate means thousands of victims.
🏹
Spear Phishing
Targeted attack
Highly customised email aimed at one person. The attacker knows your name, boss, recent project, and lunch spot — often researched from LinkedIn and Instagram.
🐇
Whaling
CEO fraud
Spear phishing aimed at the top — CEOs, CFOs, executive assistants. The prize: wire transfer authorisation or access to sensitive M&A data.
📱
Smishing
SMS phishing
"Your KYC has expired — update now at bit.ly/xxx." Fake bank SMS is a plague in India — SBI, HDFC, and ICICI users are prime targets.
📞
Vishing
Voice phishing
A phone call from "Amazon Customer Support" or "Delhi Police" about a suspicious package or arrest warrant. Payment is demanded urgently via UPI or gift cards.
📁
Clone Phishing
Legit email, malicious link
Attacker copies a real email you already received (e.g. a company newsletter) and re-sends it with the links swapped to malicious ones. Almost impossible to spot.

Section 11

How to Spot a Phishing Email in 30 Seconds

🔍 The 7 Red Flags — Check Every One
Check 1
Sender's real address — Hover over the name. support@arnazon-in.com is not Amazon. Look for extra letters, hyphens, and foreign domains.
Check 2
Urgency & fear — "Your account will be closed in 24 hours." Real banks and Google never write like that. Panic is a phishing signature.
Check 3
Generic greeting — "Dear Customer" or "Dear User" from a service that knows your name. Suspicious.
Check 4
Hover before you click — On desktop, hover the link (don't click). The real URL appears at the bottom. If it doesn't match, delete the email.
Check 5
Unexpected attachments — .zip, .exe, .iso, .html files, or Office docs asking you to "Enable Content" (macros). Never open without verification.
Check 6
Grammar & layout — Odd spacing, mixed fonts, low-res logos, awkward phrasing. Big brands hire copywriters; scammers use translation apps.
Check 7
Requests for secrets — Passwords, OTPs, CVV, PIN. No legitimate organisation ever asks for these. Ever.
💡
The 30-Second Rule

When in doubt, pause for 30 seconds and call the organisation back on a number you look up yourself (not the number in the email). Scammers rely on speed and panic — deliberate slowness is your armour.


Section 12

Phishing in the Indian Context

Scam Type How It Works Real Case
Fake KYC update SMS or WhatsApp claiming your bank/PAN/Aadhaar KYC has lapsed. Link leads to a fake login page that steals credentials. RBI issued 6+ public warnings between 2022–2024 about SBI & HDFC KYC scams (Livemint, Economic Times).
Electricity bill scam SMS: "Your power will be disconnected tonight. Pay pending bill immediately." Link opens a fake bill portal. Millions targeted across Delhi, Mumbai, Bengaluru in 2023 (Times of India and Delhi Police advisories).
Courier / customs scam Vishing call: "Your FedEx parcel contains contraband. Cooperate or face arrest." Victim is coerced into transferring lakhs. Bengaluru software engineer lost ₹1.2 crore in a single day (The Hindu, July 2023).
Digital arrest Video call from fake "CBI/police officer" claiming your Aadhaar was used for money laundering. Victim is "held under digital arrest" until payment. PM Modi warned citizens in his October 2024 Mann Ki Baat broadcast (covered by Indian Express, NDTV).
Job offer scam WhatsApp offer for "part-time work-from-home" — like/rate YouTube videos for ₹150 each. Small payouts to build trust, then huge "investment" demands. Estimated ₹1,000 crore+ lost by Indians in 2023 (Ministry of Home Affairs report).

Section 13

Social Engineering — Hacking the Human

Catch Me If You Can — The Original Social Engineer
Between 1963 and 1969, teenager Frank Abagnale Jr. impersonated a Pan Am airline pilot, a paediatrician, a lawyer, and a university professor — cashing over $2.5 million in forged cheques across 26 countries. He never picked a lock, never wrote a virus. He wore the right uniform, spoke with the right confidence, and people handed him the keys.

Steven Spielberg turned his story into the 2002 film "Catch Me If You Can" (starring Leonardo DiCaprio and Tom Hanks). Every cyber-security student should watch it — because every modern hacker uses the exact same playbook. The uniforms are just digital now.

Social engineering is the art of manipulating people into breaking normal security procedures. It exploits psychology — trust, authority, fear, urgency, curiosity, greed — not technology. It is the reason a $10 million firewall can be bypassed by a $1 phone call.

🔒
The MGM Resorts Attack, 2023

Attackers looked up an MGM IT employee on LinkedIn, then called the company's help desk pretending to be that employee needing a password reset. Ten minutes of conversation gave them keys to a $100 million kingdom. No malware, no exploit — just a phone call.


Section 14

The Classic Social Engineering Techniques

👀
Shoulder Surfing
Physical observation
Watching someone type a password, PIN, or OTP over their shoulder — at an ATM, a café, an airport lounge, or on public transport. High-resolution phone cameras make this trivially easy from metres away.
🗑️
Dumpster Diving
Trash intelligence
Rummaging through discarded printouts, sticky notes, courier receipts, and old hard drives. Bank statements, credit card offers, and internal memos are gold to attackers — and most people throw them out whole.
👨‍💼
Pretexting
Fabricated scenario
"Hi, this is Rahul from IT — we detected suspicious activity on your account, can you confirm your login?" A convincing story that makes handing over information feel routine, even helpful.
🍭
Baiting
Curiosity trap
A USB drive labelled "Salary Review 2026 — CONFIDENTIAL" left in a company car park. Studies show ~45% of people plug in a found USB. It installs malware in seconds.
🚪
Tailgating
Physical intrusion
Following an employee through a secure door — hands full of coffee, a friendly "Hold the door?" Politeness bypasses badge readers every day.
🎁
Quid Pro Quo
Something for something
"Free tech support" calls or fake surveys offering gift cards in exchange for a few "quick questions" — that just happen to include your date of birth and mother's maiden name.

Visual Diagram — Shoulder Surfing at an ATM

SHOULDER SURFING — HOW IT LOOKS IN REAL LIFE
**** ATM VICTIM entering PIN ATTACKER records PIN with phone camera line of sight DEFENCE Cover keypad Check mirror & area Ask others to step back

The attacker doesn't need to steal your card — a clear view of your PIN combined with a skimmer or later card cloning is enough.

Visual Diagram — Dumpster Diving

DUMPSTER DIVING — WHAT ATTACKERS FIND IN YOUR TRASH
Bank statement Old employee list Password sticky note Old HDD ATTACKER harvesting intel DEFENCE Shred paper Wipe drives Lock bins

Kevin Mitnick — famed reformed hacker — said dumpster diving was one of his most productive reconnaissance tools before the internet made it optional.


Section 15

Watch These Movies — Cyber Cinema Syllabus

Fiction sometimes teaches security better than textbooks. These films dramatise real attack techniques and get most of the psychology dead right.

🎥
Catch Me If You Can (2002)
True story of Frank Abagnale Jr., master social engineer. Impersonates a pilot, doctor, and lawyer with nothing but confidence and observation. The blueprint for every pretexting attack ever written.
social engineering, pretexting
🎥
The Italian Job (2003)
A gold heist built on hacking traffic lights, jamming CCTV, and manipulating people inside the system. A masterclass in how physical and digital security intersect.
system exploitation, insider threat
🎥
Mr. Robot (TV, 2015–19)
The most technically accurate hacking show ever made — real Kali Linux commands, real social engineering, real exploits. Elliot's monologues on human vulnerability are essentially security lectures.
malware, phishing, insider
🎥
Sneakers (1992)
A team of "penetration testers" break into secure buildings for hire. Includes the classic tailgating scene and voice-impersonation attack that still work in 2026.
tailgating, physical security
🎥
Blackhat (2015)
Depicts real-world critical-infrastructure attacks (power grids, financial markets). Loosely inspired by Stuxnet. Great for understanding nation-state cyber warfare.
malware, critical infrastructure
🎥
Jamtara — Sabka Number Ayega (Netflix India)
Hindi web series based on the real Jamtara phishing gang of Jharkhand — the small town that ran India's largest vishing operation. Uncomfortably realistic.
vishing, Indian cybercrime

Section 16

Defence Playbook — What Actually Protects You

🔑
Multi-Factor Authentication (MFA)
Non-negotiable
Even if your password leaks, MFA blocks 99.9% of automated account takeovers (Microsoft data). Use an authenticator app (Google, Microsoft, Authy) — SMS OTP is better than nothing but can be SIM-swapped.
💽
The 3-2-1 Backup Rule
Ransomware antidote
Keep 3 copies of every important file, on 2 different media, with 1 copy stored offline/off-site. Test restores every quarter — an untested backup is a hope, not a plan.
🔧
Patch Ruthlessly
Close the doors
Enable automatic updates on OS, browsers, and apps. WannaCry only worked because a patch existed for 2 months and admins hadn't applied it. Zero-day exploits are rare; unpatched systems are everywhere.
👤
Password Manager
Bitwarden, 1Password
One strong master password unlocks a vault of unique, complex passwords for every site. Never reuse a password. Never write one on a sticky note. Ever.
📡
Email Filtering & DMARC
Kill phishing at the gate
Enable SPF, DKIM, and DMARC on your organisation's domain to stop attackers spoofing your brand. On the receiving side, use advanced filtering (Microsoft Defender, Google Workspace, Proofpoint).
👥
Awareness Training
Human firewall
Quarterly phishing simulations reduce click-through rates from ~30% to <5% within a year. Culture beats controls — train, don't blame.

Section 17

Golden Rules — Non-Negotiable Cyber Hygiene

🛡️ The 8 Commandments of Personal Cybersecurity
1
Assume every unexpected message is a scam until proven otherwise. Banks, courts, and courier companies do not send you WhatsApp messages demanding instant action. When your gut says "something's off," trust it.
2
Never share OTPs, PINs, CVVs, or passwords — with anyone, ever. No legitimate bank, police officer, or tech-support agent will ever ask. Anyone who does is a criminal, full stop.
3
Turn on Multi-Factor Authentication on email, banking, WhatsApp, Instagram, and every account that offers it. Your email is the master key — protect it like your passport.
4
Update everything, always. Phones, laptops, browsers, apps, routers. That "Update available" notification is not a nuisance — it is a closed door keeping attackers out.
5
Back up important files offline. An external drive kept unplugged is immune to ransomware. Cloud-only backups can be encrypted along with your main files if the attacker gets in.
6
Shred sensitive paper. Wipe old drives. Dumpster diving is not Hollywood fiction. Shred bank statements, courier labels, and payslips. Physically destroy or securely wipe hard drives before disposal.
7
Cover your keypad at ATMs and when typing passwords in public. Assume there is always a camera or a curious eye. Two seconds of caution beats two months of fraud recovery.
8
If you fall for a scam, report it fast. In India, dial 1930 or report at cybercrime.gov.in within the "Golden Hour" — banks can freeze fraudulent transfers if reported quickly. Shame delays reports; delays lose money.
🏆
Final Thought

There is no such thing as being "hack-proof" — only being harder to hack than the next target. Attackers are opportunists. Every one of the rules above raises the cost of attacking you so that they move on to easier prey. That is the whole game. Stay curious, stay sceptical, and never stop learning.