Dangers of the information era
In my previous post I wrote about the details of Cyber Threat Intelligence, what intelligence and threats are and the key for a proper usage of CTI. In this post I want to explain who attackers are, what they do and how they do it.
As I already mentioned in my first blog, a hacker doesn�t have to be someone who is trying to cause harm. The media and the public are misusing the word. A computer hacker is just someone who is really good (or tries to be good) with computers and understands how a computer system or network works. For describing a malicious hacker whose main goal is sabotaging a computer system or infiltrating a network I will switch from the term hacker to attacker.
Though there is a great number of ways to scam, deceive and attack users on the Internet, I will explain a few:
1. Computer fraud
Computer fraud is an act of stealing money or information using the Internet, e.g. when you get a suspicious email or a pop-up containing an appealing offer, or tricks you into sharing your personal or bank information (your password, bank account number, etc.). Today online shopping is very common, and you should keep in mind to check if the web-site you are visiting has a certificate and a figure of a lock at the beginning of the address bar (Figure 1). If something is wrong with the certificate, your browser will probably give you a warning.
An example of computer fraud is identity theft, where the attacker uses phishing or spam to retrieve information required to impersonate you on the Internet.
![]() |
| Figure 1. Sign that the web-site is secure |
2. Kidnappers
A kidnapper uses malware programs to take control of your computer. Once he has control the attacker can overlook your web activities, slow down your computer or Internet connection or even use your computer to send spam and attack other Internet users. Ransomware is a type of malware where the attacker demands ransom for decrypting your data or ransom for not sharing your data online. This kind of attack is sometimes hard to recognize because your computer doesnt appear infected at first glance.
3. Viruses and worms
A computer virus is a self-replicating code that lives inside a host�s body, e.g. word documents. A computer worm is a self-replicating program that transfers from computer to computer. Viruses and worms often contain a dangerous payload that can take over your computer, destroy files or steal information.
4. Identity theft
Illegally obtaining personal information like bank account numbers, passwords or social security numbers used for online and offline fraud is called identity theft.
Phishing is used for identity theft and relies on e-mails. You can get an e-mail from your �bank� that asks you to give your personal information so they can confirm your account. Now the attacker has your personal information and he can steal money from you or sell that information to someone else.
5. Spyware
Spyware is a type of malware that collects information without your knowledge. For example, it can collect information about your keystrokes, internet interactions or can redirect your browser to unwanted web-sites. There are four types of spyware: adware, system monitors, tracking cookies and trojan horses.
Adware collects information about your browsing habits so that it can deliver targeted ads inside your browser, redirect you to suspicious sites and change your browser settings.
Adware and spyware aren�t replicating themselves on your computer; they inhabit it without you even realizing it, which can happen by visiting a web-site that secretly downloads the software on your computer or they can be installed alongside a desired program.
Trojan horses can give the attacker total control of your computer. The attacker can then read, change or delete your data; install or remove software from your computer and leave you no control what so ever. Like the name suggests, the trojan horse appears harmless until it is installed.
6. Spoofing
Spoofing is creating a fake version of something the user is interested in, like a web-site or an e-mail address. For example, many identity thieves create web-sites that are lookalikes of the original web-site and users are redirected to those copies instead to the original web-site in a seamless fashion.
7. Spam
Although spam isnt as dangerous as the previously mentioned examples, it is very annoying. While there are many types of spam the most known is e-mail spam in which you constantly receive e-mails with advertisements or offensive content. Identity thieves often use spam for sending fake e-mails.
download file now
