Understanding Cyber Threats and Attackers
Understanding Cyber Threats and Attackers
Syllabus
● Types of cyber threats: internal and external threats
● Types of attackers: script kiddies, insiders, hacktivists, cybercriminals
● Malware types: virus, worm, trojan, ransomware, spyware, adware
● Phishing, social engineering, and identity theft
● Denial of Service (DoS) and Distributed DoS (DDoS) attacks
● Man-in-the-middle (MitM) attacks and session hijacking
● Case studies of recent cyberattacks
1. Cyber Threats
A cyber threat is a malicious attempt to disrupt digital life, steal sensitive data, or
damage information systems, networks, or devices. These threats exploit vulnerabilities in
software, hardware, or human behavior. They are a major concern in cybersecurity as they
can cause financial losses, reputational damage, and even national security risks.
In today’s interconnected world, the scale and sophistication of cyber threats are
constantly increasing due to rapid digital transformation, cloud adoption, and the growth of
Internet of Things (IoT) devices. Attackers are leveraging advanced technologies such as
artificial intelligence and automation to launch more targeted and complex attacks. As a
result, organizations and individuals must adopt proactive cybersecurity measures, including
continuous monitoring, threat intelligence, and regular security awareness training, to stay
resilient against evolving cyber risks.
Cyber threats can originate from within an organization or from external sources. They are
broadly classified into internal threats and external threats based on the origin of the attack.
Both of them pose serious risks, but their nature causes, and prevention strategies differ.
1. Internal Threats
Internal threats come from people inside the organization, such as employees,
contractors, or business partners who have legitimate access to systems and networks.
These threats may be intentional (malicious activity) or unintentional (due to negligence or
lack of awareness).
Examples:
o Disgruntled employees stealing sensitive company data.
o Accidental deletion or leakage of confidential files.
o Weak passwords or careless sharing of login credentials.
Impact: Loss of intellectual property, insider fraud, data breaches, reputational
harm.
Prevention: Role-based access control, monitoring employee activity, cybersecurity
awareness training, and enforcing strict policies.
2. External Threats
Examples:
o Phishing emails tricking users into sharing credentials.
o Malware attacks such as viruses, ransomware, or trojans.
o Distributed Denial of Service (DDoS) attacks on websites or servers.
Impact: Service disruption, financial fraud, theft of sensitive information, large-scale
data breaches.
Prevention: Firewalls, intrusion detection/prevention systems (IDS/IPS), regular
patch updates, endpoint protection, and incident response plans.
Types of
Attackers
1. Script Kiddies
Script kiddies are amateur attackers who lack advanced technical skills and rely on
pre-written tools, scripts, or malware created by skilled hackers. They use these tools to
exploit known vulnerabilities in systems without fully understanding how the attack works.
Their motivation is often curiosity, fun, thrill, or to gain recognition among peers.
While script kiddies may not be as sophisticated as professional hackers, they still pose a
significant risk because the tools they use can cause system disruptions, website
defacements, or data breaches. Since these tools are easily available online, script kiddie
attacks are common, unpredictable, and can sometimes unintentionally cause severe
damage.
2. Insiders
Insider attacks are particularly dangerous because they are harder to detect compared to
external threats. The motivation behind insider threats can include personal gain (e.g.,
selling data), revenge due to dissatisfaction, or even unintentional mistakes such as
mishandling confidential information. Effective monitoring, strict access controls, and
employee training are crucial to mitigating insider risks.
3. Hacktivists
Hacktivists are attackers who combine hacking with activism, often targeting
organizations, governments, or corporations to promote political, social, or ideological
causes. Their attacks are not primarily motivated by financial gain but rather by the desire to
spread a message, protest, or embarrass their target.
4. Cybercriminals
Types of
Attacks
1. Network-Based Attacks
Network-based attacks also include IP Spoofing and DNS Poisoning, where attackers
forge IP addresses or corrupt DNS tables to redirect traffic to malicious sites. These
techniques are often precursors to more advanced exploits, enabling hackers to set up
phishing pages or malware injection points. Since networks serve as the backbone of digital
communication, compromising them can have severe consequences.
One of the most common application-based attacks is SQL Injection, where malicious
queries are inserted into input fields, allowing attackers to manipulate or extract data from
backend databases. Similarly, Cross-Site Scripting (XSS) allows attackers to inject malicious
scripts into trusted websites, which then execute in user browsers, stealing session data or
spreading malware.
3. Human-Based Attacks
4. Malware-Based Attacks
Malware (malicious software) is one of the most common and dangerous forms of
cyberattacks. It is designed to infiltrate systems, disrupt operations, steal data, or demand
ransom. Malware can spread through infected files, email attachments, malicious websites,
or removable devices, making it highly versatile and difficult to detect without proper
defense.
Viruses are malware programs that attach themselves to files and spread when the
infected file is executed, while Worms replicate themselves across networks without user
interaction. Trojans disguise themselves as legitimate software but secretly perform
malicious actions, such as stealing data or providing backdoor access to attackers.
1. Virus
A virus is one of the earliest and most well-known forms of malware. Much like a
biological virus, it attaches itself to files, programs, or boot sectors and spreads when the
infected file is executed. Viruses usually require human action (such as running an
application or opening an infected file) to activate and propagate.
Viruses can perform various harmful actions such as corrupting files, deleting data,
or slowing down system performance. Some viruses are relatively harmless, while others
can cause massive destruction by wiping out hard drives or making systems inoperable.
A classic example is the ILOVEYOU virus (2000), which spread via email attachments
and caused billions of dollars in damages worldwide by overwriting files. Modern viruses are
often combined with other malware techniques to increase their effectiveness and stealth.
Prevention measures include updated antivirus software, email scanning tools, and user
training to avoid suspicious attachments.
2. Worm
Unlike viruses, worms are self-replicating malware that do not need user interaction
to spread. They exploit vulnerabilities in operating systems or networks, allowing them to
propagate rapidly across devices once they infect a single system. Worms are particularly
dangerous because of their ability to spread quickly through networks, consuming
bandwidth, and overwhelming servers. This can lead to Denial of Service (DoS)-like
situations even without direct malicious intent. Additionally, worms often carry "payloads"
such as ransomware or spyware, amplifying their damage.
One of the most infamous worms was the Conficker worm (2008), which infected
millions of computers globally and created massive botnets. Another example is the SQL
Slammer worm, which spread worldwide in minutes, disrupting banking, government, and
airline systems. Defense strategies include timely patching of systems, intrusion detection
systems, and network monitoring.
3. Trojan
The term “Trojan” originates from the Greek myth of the Trojan Horse, where
attackers hid inside a seemingly harmless wooden horse to infiltrate Troy. Similarly, cyber
Trojans appear benign but unleash destructive activity once inside. Prevention involves
downloading software only from trusted sources, using endpoint security, and avoiding
cracked/pirated software.
4. Ransomware
Ransomware is one of the most damaging and widely reported forms of malware in
recent years. It encrypts the victim’s files or locks their system, demanding payment (usually
in Cryptocurrency) in exchange for a decryption key or system access. There are two main
types of ransomware:
5. Spyware
Spyware is malware designed to secretly monitor user activities and collect sensitive
information without consent. It can log keystrokes (keyloggers), track browsing habits, steal
credentials, or even record audio and video from devices. Spyware often enters systems
bundled with free software, infected attachments, or malicious websites. Since it operates
in the background, it is difficult to detect without security tools. The stolen information may
be used for identity theft, financial fraud, or corporate espionage.
6. Adware
Adware often comes bundled with freeware or shareware, where users unknowingly agree
to its installation. Once active, it floods browsers with pop-ups, redirects searches, or
collects user data for targeted advertising. Though sometimes dismissed as a nuisance,
adware can compromise privacy and open doors to phishing and spyware.
5. Phishing
The message typically urges the victim to click on a malicious link, download an
infected attachment, or provide personal information directly. Once the victim complies,
attackers can gain access to accounts, steal money, or launch further attacks using the
compromised credentials.
Types of Phishing
1. Email Phishing – Fake emails that appear to come from trusted sources.
2. Spear Phishing – Targeted phishing aimed at specific individuals or organizations.
3. Whaling – A type of spear phishing aimed at high-profile targets such as CEOs or
executives.
4. Smishing – Phishing through SMS messages.
5. Vishing – Phishing through voice calls.
6. Clone Phishing – Attackers resend a legitimate email with a malicious link or
attachment added.
6. Social Engineering
A social engineering attack is a manipulation technique that exploits human
psychology to trick individuals into revealing confidential information, granting
unauthorized access, or performing harmful actions. Unlike technical attacks that target
systems and software, social engineering targets human behavior, making it one of the most
effective forms of cyberattacks.
Social engineering attacks are particularly dangerous because they bypass technical
defense like firewalls and antivirus software by targeting the human factor. Even the most
secure systems can be compromised if an employee is tricked into revealing their password
or clicking on a malicious link. Attackers often exploit emotions such as fear (“your account
will be blocked”), curiosity (“see who viewed your profile”), or urgency (“act now to avoid
penalty”) to pressure victims into quick decisions without verifying authenticity.
Another important aspect of social engineering is that it is not limited to the digital
world—it can also occur in physical environments. For instance, an attacker might dress as a
delivery person or technician to gain physical access to a restricted office space. Once inside,
they can steal sensitive information, install malware, or connect rogue devices to the
network. This shows that social engineering is a blended threat combining psychological
manipulation with both digital and physical tactics, making it one of the most challenging
cyber threats to defend against.
7. Identity Theft
Identity theft is a cybercrime in which an attacker illegally obtains and uses another
person’s personal information, such as name, Social Security number, bank account details,
or credit card numbers, to commit fraud or other crimes. Unlike direct financial theft,
identity theft allows criminals to impersonate victims, making it harder to detect and often
causing long-term consequences. Attackers use various techniques to steal personal
information, such as phishing emails, fake websites, malware infections, data breaches, and
social engineering attacks. For example, a hacker might send a fraudulent email asking the
victim to update their banking information, or breach an organization’s database to steal
thousands of users’ records. Once obtained, this information is sold on the dark web or used
directly for financial gain.
How it Works:
Example:
If a website is flooded with millions of fake login requests, it may crash and prevent genuine
users from accessing their accounts.
Distributed Denial of Service (DDoS) Attack
How it Works:
The attacker infects devices (computers, IoT devices, smartphones) with malware.
These infected devices, known as bots or zombies, form a botnet.
The attacker controls the botnet remotely and commands all infected devices to
send requests to the target.
The target becomes overwhelmed and crashes or becomes unavailable.
Example:
The 2016 Mirai Botnet Attack used infected IoT devices to launch one of the largest DDoS
attacks in history, disrupting services like Twitter, Netflix, and Reddit.
Detection Easier to trace and block Harder to trace due to multiple sources
The purpose of MitM attacks can vary — attackers may want to steal sensitive
information like login credentials, credit card numbers, or personal data, or they may
manipulate the communication for malicious purposes.
How MitM Attacks Work
1. Interception: The attacker first intercepts communication between two systems. This
can be done by exploiting unsecured Wi-Fi networks, DNS spoofing, or ARP spoofing.
2. Decryption/Modification: Once the data is captured, the attacker can read, steal, or
even alter the information being exchanged.
3. Relay: The attacker forwards the modified or original data to the receiver, so neither
party suspects the communication is compromised.
Wi-Fi Eavesdropping: Attackers set up a fake Wi-Fi hotspot in a public place. When
users connect, all data they send (like passwords and credit card details) can be
intercepted.
HTTPS Spoofing: Replacing secure HTTPS websites with fake HTTP sites to steal login
information.
Email Hijacking: Attackers intercept business email exchanges (like financial
transactions) and alter bank details to redirect payments to their own accounts.
1. Session Token Theft: When a user logs into a website or application, the server
issues a unique session ID (token) to maintain the login state. Attackers steal this
token using techniques like packet sniffing, cross-site scripting (XSS), or malware.
2. Session Replay: Attackers reuse the stolen session ID to impersonate the legitimate
user.
3. Full Account Control: Once inside, attackers can access sensitive data, perform
malicious transactions, or change passwords.
Session Fixation: Forcing a user to use a known session ID so the attacker can hijack
it later.
Cross-Site Scripting (XSS): Injecting malicious scripts to steal session cookies.
Man-in-the-Browser (MitB): Malware running inside the victim’s browser modifies
session communication.
Network Sniffing: Intercepting unencrypted session data over insecure networks.
In September 2025, Jaguar Land Rover (JLR) was crippled by a ransomware attack
orchestrated by a teenager-led group called Scattered Lapsus$ Hunters, a coalition of
notorious hacking collectives. The attack led to the global shutdown of JLR’s IT systems,
halting vehicle production and service operations. Dealerships were unable to order parts or
provide service quotes, leaving many vehicles undrivable. Recovery efforts forced
employees to stay home and operations remained suspended for days. The attack
underscores how even global enterprises with robust defenses can be paralysed by
ransomware.
In mid-2025, UK retailer Co-op suffered a major cybersecurity breach that leaked personal
data of all 6.5 million members. While financial details weren’t exposed, the breach
included names, addresses, and contact information—course-corrected by the CEO’s public
apology. This incident not only disrupted services and supply chains but also deeply
impacted customer trust, highlighting the emotional and operational burden a data breach
brings.
1.2 Key Reasons for the Need of Cybersecurity
Cybersecurity is built on three key principles, commonly known as the CIA triad:
1. Confidentiality
o Ensures that only authorized users can access information.
o Prevents sensitive data from being disclosed to unauthorized people.
o Example: Using passwords, encryption, and access control to keep personal
bank details private.
2. Integrity
o Ensures that information is accurate, consistent, and not altered without
authorization.
o Protects data from being changed, deleted, or corrupted by malicious actors.
o Example: Digital signatures, hashing, and checksums are used to maintain
data integrity.
3. Availability
o Ensures that information and resources are available when needed.
o Protects against disruptions such as hardware failures, cyberattacks, or
power outages.
o Example: Backups, firewalls, and disaster recovery plans help maintain
availability.
A balanced CIA triad also helps organizations build trust with users and stakeholders.
When confidentiality protects sensitive data, integrity ensures that the information is
accurate and reliable, and availability guarantees timely access, users feel confident in
relying on the system. Any imbalance—such as frequent downtime, data leaks, or
tampering—can damage this trust and lead to financial, legal, and reputational losses.
Hence, maintaining equilibrium among the three principles is not just a technical
requirement but also a business and ethical necessity in cybersecurity.
Vulnerability
A vulnerability is a weakness or flaw in a computer system, software, or network that
can be taken advantage of by attackers. It acts like an open door for cybercriminals to
enter and cause harm. Vulnerabilities may arise due to poor design, lack of security
updates, weak passwords, or misconfigured systems. For example, using outdated
software without patches is a vulnerability that attackers can easily exploit.
Threat
A threat is anything that has the potential to cause harm by exploiting a vulnerability.
Threats can be intentional, like hackers and malware, or unintentional, such as natural
disasters or human errors. For example, a cybercriminal trying to steal login details is a
threat to the system. In simple terms, a threat is a possible danger that puts digital
assets at risk.
Risk
Risk refers to the possibility that a threat will exploit a vulnerability and cause damage to
the organization or individual. It combines the likelihood of an attack happening with the
potential impact of the damage. For instance, if sensitive data is stored without
encryption, there is a high risk of data theft if a hacker gains access. Managing risk is a
key part of cybersecurity, as it helps prioritize which vulnerabilities to fix first.
Exploit
An exploit is the actual method or tool used to take advantage of a vulnerability in order
to carry out an attack. Exploits can be in the form of malicious software, scripts, or
techniques that attackers use to gain unauthorized access. For example, ransomware
can exploit an unpatched security flaw in an operating system to lock files and demand
money from the user. Simply put, while vulnerabilities are weaknesses, exploits are the
weapons used to attack them.
Cybercrime refers to illegal activities carried out using computers, networks, or the
internet. It targets individuals, organizations, or governments with the intention of stealing
data, disrupting systems, or causing harm. Cybercrimes can range from small-scale fraud to
large-scale attacks threatening national security.
Traditional crimes usually occur in the physical world, such as theft, robbery, assault, or
fraud. They require the criminal to be physically present at the location of the crime and
often leave behind physical evidence. The impact is generally limited to a particular person,
group, or place.
On the other hand, cybercrimes take place in the digital world using computers, networks,
or the internet. The criminal can act remotely without being physically present, often
remaining anonymous. Cybercrimes can affect thousands of people across different
countries simultaneously, making them more widespread and harder to trace. Unlike
traditional crimes, evidence in cybercrime is digital in nature (logs, emails, malicious code),
requiring special forensic techniques to investigate.
1) Cyberterrorism
Cyberterrorism refers to the use of the internet and digital tools to launch politically
or ideologically motivated attacks that cause fear, disruption, or damage. Targets often
include critical infrastructures such as power grids, water supplies, transportation systems,
and government databases. Unlike traditional terrorism, cyberterrorism can be executed
remotely, making it harder to detect and prevent. For example, attackers may hack into
defense networks to steal sensitive information or disrupt communication systems during
emergencies, which can paralyze a nation’s functioning.
The impact of cyberterrorism goes beyond technical disruption. It creates psychological fear
among citizens, undermines trust in public institutions, and may even destabilize national
security. Countries must invest in advanced cybersecurity strategies and international
cooperation to prevent and mitigate such threats. Governments also need to train
cybersecurity professionals who can detect early warning signals and respond quickly to
safeguard critical infrastructures.
2) Cyberbullying
Another concerning aspect of cyberbullying is its long-lasting digital footprint. Once harmful
content is shared online, it can spread rapidly and be difficult to remove completely. This
amplifies the victim’s distress and damage to reputation. Educational institutions, parents,
and law enforcement agencies need to work together to create awareness and establish
strong reporting mechanisms. Promoting responsible digital behavior and empathy among
young users is equally important to curb the rise of cyberbullying.
3) Financial Frauds
The consequences of financial frauds are severe, causing both monetary losses and a decline
in public trust in digital systems. Victims may lose their savings, while businesses can face
reputational damage and legal issues. To counter this, financial institutions implement
security measures like two-factor authentication, encryption, and fraud detection systems.
However, user awareness is equally critical—people must learn to recognize suspicious links,
avoid sharing personal details, and verify the authenticity of websites before making
transactions.
In simple terms, IT security is the umbrella, ensuring the protection of all forms of
information, while cybersecurity is a focused branch that deals only with internet-based and
digital threats. Both are interdependent: a strong IT security framework must include
cybersecurity measures to ensure complete protection in today’s digital world. As
organizations and individuals increasingly rely on digital technologies, the distinction
between IT security and cybersecurity becomes critical. While IT security ensures the overall
safeguarding of information assets, cybersecurity acts as a specialized defense against
modern cyberattacks. Together, they form a comprehensive security strategy, making it
essential for professionals to understand both concepts and apply them in an integrated
manner.
16. Current trends in cybersecurity
1. Ransomware Attacks
Ransomware continues to be one of the biggest cyber threats. Attackers encrypt the
victim’s data and demand money for its release. Organizations are now focusing on
backup strategies, endpoint protection, and incident response to deal with such
attacks.
3. Cloud Security
As businesses move their data and applications to cloud platforms, ensuring cloud
security has become critical. Cloud providers and users implement encryption, multi-
factor authentication, and continuous monitoring to secure data stored online.
Security Analyst – Monitors systems and networks for threats, investigates alerts, and
improves defences.
Penetration Tester (Ethical Hacker) – Simulates attacks to identify system
vulnerabilities before real attackers exploit them.
Incident Responder – Detects, analyzes, and responds to security incidents such as
breaches or malware attacks.
Security Engineer – Designs and implements secure network architectures, firewalls,
and encryption mechanisms.
Security Consultant – Advises organizations on best practices, policies, and
compliance with security standards.
Forensic Analyst – Investigates cybercrimes, collects digital evidence, and supports
law enforcement.
Chief Information Security Officer (CISO) – Leads the cybersecurity strategy, manages
teams, and aligns security with organizational goals.