Skip to content

Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security

Cyber Threats and Types of Cyber Attacks Explained

Updated 11 October 2026 · Fact-checked

A cyber threat is any possible event that can harm a system, network or data. A cyber attack is the actual attempt to do that harm. Common types are malware, phishing, ransomware, DDoS, social engineering and insider threats. To answer a question, define the attack, explain how it works, give an example, and state its impact and control.

Understand Cyber Threats and Types of Cyber Attacks

Start with three words. A threat is something that could cause harm. A vulnerability is a weakness that the threat can use. An attack is the threat acting on the vulnerability. Security aims at protecting confidentiality, integrity and availability of information. Every attack hits at least one of these three.

Malware is malicious software. A virus attaches itself to a file or program and spreads when a user runs that file. A worm spreads on its own across networks, without any user action. A trojan looks like useful software but carries a hidden harmful function; it does not replicate by itself. Spyware secretly collects information. Ransomware locks or encrypts data and demands payment to restore access.

Phishing is a fraudulent message, usually email or SMS, that pretends to come from a trusted source to steal credentials or money. Spear phishing is targeted: the attacker studies one person or organisation and writes a personal message. Ordinary phishing is sent in bulk to many people. Social engineering is the wider idea: tricking people instead of breaking technology. It includes phishing, pretexting, baiting and impersonation.

A DDoS (distributed denial of service) attack floods a server or network with traffic from many compromised devices, so genuine users cannot reach the service. It attacks availability. A typical ransomware attack runs in stages: entry through a phishing email or weak remote access, spread inside the network, encryption of files, then a ransom note. Backups and prompt isolation reduce the damage.

An insider threat comes from a person with legitimate access, such as an employee or contractor. It may be malicious or accidental. Because the person is already trusted, firewalls alone do not stop it. Controls are least-privilege access, activity logging, and awareness training.

Key rules to remember

CIA triad
Confidentiality + Integrity + Availability
Name the property each attack hits: ransomware and DDoS hit availability, data theft hits confidentiality, tampering hits integrity.
Threat–attack link
Threat + Vulnerability → Attack
Use this to separate the three terms in definition questions.
Virus vs worm vs trojan
Virus = needs host file and user action; Worm = self-spreading; Trojan = disguised, no self-replication
The most asked comparison.
Phishing vs spear phishing
Phishing = bulk, generic; Spear phishing = targeted, personalised
Mention research on the victim as the key difference.

How to solve Cyber Threats and Types of Cyber Attacks questions

Use one structure for any question on threats and attacks. It works for definitions, comparisons and case-based questions.

  1. 1Read the question and mark the keyword: define, differentiate, explain, or advise on a given case.
  2. 2Define the attack in one or two plain lines.
  3. 3Explain how it works, in stages if possible: entry, action, impact.
  4. 4Give a short Indian or realistic example, such as a fake bank SMS or a ransomware hit on a company's servers.
  5. 5State which part of the CIA triad is affected.
  6. 6List preventive and corrective controls: patching, backups, filtering, training, access control, incident response.
  7. 7For a case, link the facts to the attack type and conclude with clear advice. You may add that offences may attract the Information Technology Act, 2000, without quoting a section unless sure.

Quickest way: Define–Work–Example–Control

When to use it: Use when time is short, especially for 5-mark or comparison questions.

  1. Write the definition in one line.
  2. Write two or three lines on how it works.
  3. Add one example.
  4. Close with two controls.
  5. For comparisons, write three or four points side by side in bullets: spread, host needed, user action, purpose.

Common mistakes in Cyber Threats and Types of Cyber Attacks

  • Treating virus, worm and trojan as the same thing.

    All three are called malware and the terms are used loosely in daily talk.

    Fix: Remember: virus needs a host and user action, worm spreads alone, trojan disguises itself and does not self-replicate.

  • Saying phishing and spear phishing differ only in the medium.

    Students focus on email versus message.

    Fix: The difference is targeting. Spear phishing is personalised after research on the victim.

  • Describing DDoS as hacking into a system to steal data.

    DDoS is confused with a data breach.

    Fix: DDoS floods a service to deny access. It attacks availability and need not steal anything.

  • Ignoring insider threats or assuming they are always malicious.

    Attention goes to outside hackers.

    Fix: State that insiders can be malicious or careless, and give access control and monitoring as controls.

  • Giving definitions with no example or control.

    Students memorise theory and skip application.

    Fix: Add an example and at least two controls to every answer, as the paper is case-based.

Worked examples

Example 1

Differentiate between a virus, a worm and a trojan. (5 marks)

Show the solution
  1. Define each one briefly: a virus attaches to a host file, a worm is a standalone self-spreading program, a trojan is harmful software disguised as useful software.
  2. Compare spread: a virus spreads when the infected file is run by a user; a worm spreads across networks by itself; a trojan relies on the user installing it and does not replicate.
  3. Compare dependence: a virus needs a host; a worm and a trojan do not.
  4. Give examples: an infected document macro, a worm that scans the network for unpatched systems, a fake free tool that opens a backdoor.
  5. Conclude with controls: updated antivirus, patching, downloading from trusted sources, and network segmentation.

Answer: A virus needs a host file and user action, a worm spreads on its own through networks, and a trojan hides inside apparently useful software and does not self-replicate. All are malware and are controlled by patching, antivirus and cautious downloads.

Example 2

An accounts executive at an Indian company receives an email, apparently from the CFO, asking for an urgent transfer to a new vendor account. The email uses the executive's name and refers to a real project. She pays ₹4,50,000 and later finds the email was fake. Identify the attack and advise the company.

Show the solution
  1. Identify the attack: the email imitates a trusted person and is personalised with her name and project details. This is spear phishing, a form of social engineering.
  2. Explain why it worked: the attacker researched the target and created urgency and authority, so she skipped verification.
  3. State the impact: financial loss of ₹4,50,000 and a breach of the integrity of the payment process.
  4. Immediate action: inform the bank at once to try to hold the transfer, preserve the email with headers, report internally and to the cyber crime portal or police.
  5. Preventive controls: call-back verification for changed bank details, dual approval for payments, email filtering, and regular awareness training.

Answer: The attack is spear phishing, a social engineering fraud. The company should report promptly, preserve evidence, and adopt dual approval, call-back verification and staff training to prevent a repeat.

Exam tips

  • Comparison questions are common. Use bullet points with clear parameters such as spread, host, purpose and example.
  • In case-based questions, name the attack first, then give facts, impact and advice. Do not just list theory.
  • Always tie the attack to the CIA triad. It shows analysis.
  • Add practical controls and reporting steps. Examiners look for compliance and drafting points.
  • Do not quote section numbers of the IT Act unless you are sure of them. A correct general reference is safer.

Practice questions from Cyber Security

Cyber Threats and Types of Cyber Attacks: frequently asked questions

What is the difference between a virus, worm and trojan?

A virus attaches to a host file and needs a user to run it. A worm spreads by itself across networks. A trojan pretends to be useful software and does not replicate on its own.

What is the difference between phishing and spear phishing?

Phishing is a generic message sent to many people. Spear phishing is aimed at one person or organisation and uses personal details to look genuine.

How does a ransomware attack work?

The attacker gets in, often through a phishing email or weak remote access, spreads in the network, and encrypts files. A ransom note then demands payment for the key. Offline backups and quick isolation limit the harm.

Is social engineering a technical attack?

No. It targets people instead of software. Phishing, impersonation and baiting are examples.

Which security property does a DDoS attack affect?

It affects availability, because genuine users cannot access the service while it is flooded with traffic.