Cybersecurity 101: Types of Cyber Attack October 31, 2023 – Posted in: Cyber Security, IT Support – Tags: cybersecurity, cybersecurity 101, it support
In the most basic sense the broad term malware means mal (bad) ware (software). There are distinctions between a virus that modifies or deletes data and worms that simply self-replicate to overload a system, or trojans that get in and create a back door into a system. We won’t go into too much detail here about the technical differences – it isn’t relevant to most business owners. What is important to consider though is the types of attack and the methods of delivery – that is key to fighting back.
Types of Attack
The key types of attack are:
- Denial-of-service – the aim of this is to send so many queries to a system that it overloads and cannot process legitimate traffic. It may be used to cause inconvenience by taking a key service or website offline. As a cover for a different type of digital attack by taking security services down. Or even to cover a physical theft or attack by taking cameras and security systems offline.
- Ransomware – used to encrypt a person or company’s data then demand a ransom in return for the decryption key (that may, or may not be provided after payment).
- Social engineering and scams – whilst not exclusive to cybercrime, the internet has opened up broad new horizons for the con. Requests for payment for fake goods, editing of invoices to redirect payments, demands for fines to be paid into criminal’s bank accounts can all be made without ever meeting in person.
- Data theft – the methods of data theft are innumerable – from a simple copy and paste on an unlocked computer to sophisticated viruses, but the result is the same. Information is stolen to be sold, published or held to ransom.
Methods of Delivery
The key ways in which a virus or malicious actor can access your systems are:
- Spam – technically phishing is a subset of spam, but the much wider category includes all manner of unwanted or malicious emails including those with infected attachments.
- Phishing – by far the most common method of stealing people’s logins, getting privileged information or delivering a malicious programme, phishing is distinct because it mimics a legitimate email. It is much harder to spot than basic spam, phishing emails are often sent to thousands of people trying to get them to pay a spurious bill, or enter their password in order to download a document. Harder to spot and higher risk are the spear-phishing emails, specifically designed for a single, high level individual in a business and crafted to fool them. If a malicious actor gains access to a mailbox they do not always immediately attempt to make use of it. They may wait, and watch, until they see something worth targeting – a request for a large payment, or a discussion about a significant amount of money. They can then delete the legitimate email, and send through a replica with their own bank details on it at a time when you are expecting a bill. Phishing broadly falls into two categories:
- Spoofed emails – this is where someone will use a different email address than the one they are pretending to email from, often using similar miss-spellings such as adebe.com or microsott.com to make it harder to spot.
- Hacked emails – this is where the malicious actor will breach someone’s mailbox, then use it as a platform to send emails out to their contact list or internal staff. This means that the email will genuinely come from a trusted source.
- Smishing and Vishing – these stand for sms phishing (text messages) and voice phishing (phone). Scammers may call or text asking for payment, or telling you there is a problem with your computer and directing you to open a screen share so they can remote on and ‘fix’ the problem. They will sometimes simply take your account details if you enter them to pay for something – a common scam over the last couple of years was convincing people to pay for their free COVID pass via text. If the malicious actors can gain access to your computer they may install malicious software like keyloggers to gain more information, or leave a back door into your computer for future use.
- Accidental – many viruses will have a delay or ‘incubation’ period before they start making changes to a system. In this time staff members may take home thumb drives with files on them, save files to other business systems, or send emails with attachments, all unwittingly spreading the virus.
- Back-door or Exploit – an exploit is essentially a way of using code that was not intended. At the most benign end exploitable bugs in games might let you bypass a locked door by holding a plate against a wall and running at it very fast. At the other end of the scale someone may be able to exploit a form entry on a piece of software to introduce a virus that encrypts the entire database. Once an exploit is known details of it will often be sold to other malicious actors. These exploits will allow a threat actor to remotely access or impact your systems.
The next article in our Cybersecurity 101 series will cover the legal responsibilities your business has around protecting the data you handle. After that we will be moving on to how to protect yourself and your business. If you’d like to know more about protecting your business in the mean time, give us a call on 01245 265 100 or email us at .