Cyber Crime, Malware & Types of Hackers: Complete Reference Guide
Evergreen reference on cyber crime, malware types, hacker categories, firewalls, IT Act/BNS/DPDP, CERT-In, Sanchar Saathi, and 1930 golden-hours reporting — Devanagari narrative with English tech terms.
Overview
आज के digital युग में computers, smartphones, IoT gadgets और cloud infrastructure हमारे daily जीवन का अनिवार्य हिस्सा बन चुके हैं। Technology जितनी सुलभ हुई है, cyber security risks और malicious threats भी उसी अनुपात में बढ़े हैं।
यह comprehensive guide Cyber Crime के मूल स्वरूप, Malware की technical classifications, Hackers के distinct categories, Firewall architecture और Indian Cyber Laws के framework को एक structural context में प्रस्तुत करती है।
Related on CyberSathi: What happens if you call 1930?, How to Report a Cyber Crime in India, Ransomware playbook for Indian SMBs.
1. Cyber Crime क्या है? (What is Cyber Crime?)
Cyber Crime किसी भी ऐसे unlawful act या offense को कहते हैं जहाँ computers, communication devices या electronic networks को या तो target (लक्ष्य) या weapon (साधन) की तरह इस्तेमाल किया जाता है। इसका प्राथमिक उद्देश्य unauthorized access हासिल करना, confidential data चुराना, financial gain अर्जित करना या systems को disrupt करना होता है।
Primary Categories of Cyber Offenses
- Unauthorized Access & Hacking: किसी network, server या operating system के security loopholes को exploit करके बिना अनुमति के भीतर घुसना और data manipulate करना।
- Phishing & Social Engineering: Legitimate entities (banks, tax agencies, telecom companies) का disguise बनाकर deceptive emails, links या fake portals के जरिए credentials, OTPs और account details harvest करना। See also spot a phishing email in 30 seconds.
- Identity Theft: किसी व्यक्ति के digital footprints, Aadhaar, PAN या financial records का अनधिकृत इस्तेमाल करके identity compromise करना और fraud को अंजाम देना।
- Cyber Stalking & Blackmail: Social media या digital messaging platforms पर किसी को persistently harass करना, unapproved media morphing करना या personal exposure की threat देकर ransom माँगना।
- DoS (Denial of Service) & DDoS: Targeted server या network bandwidth पर excessive fake automated requests flood कर देना, जिससे legitimate users के लिए system resources unavailable हो जाएँ।
- Cyber Terrorism: Critical national infrastructure (nuclear power grids, defense radar, civil aviation systems) को destabilize करने के इरादे से सुनियोजित coordinated cyber attacks करना।
2. Types of Malware: Technical Classification & Differences
Malware (Malicious Software) वह umbrella term है जो किसी भी हानिकारक computer program या code को describe करता है। Cyber security में malware को उनके infection mechanism, replication behavior और destructive potential के आधार पर classify किया जाता है।
| Malware Type | Core Replication Behavior | Execution Dependency | Operational Impact |
|---|---|---|---|
| Virus | Self-Replicating (अपनी copies बनाता है) | Host File Required (बिना infected host file run हुए active नहीं होता) | Target program code में inject होकर data corrupt करता है; e.g., File Invalidator, Polymorphic, Boot Sector. |
| Worm | Self-Replicating (Network में स्वतंत्र रूप से फैलता है) | Standalone / No Host Needed | Network ports, bandwidth और system memory saturate करता है; background remote access backdoors खोलता है। |
| Trojan Horse | Non-Replicating (स्वयं replicate नहीं करता) | User Interaction / Disguise (Legitimate app या utility बनकर आता है) | System में silently backdoor create करता है, banking credentials log करता है या ransomware payloads drop करता है। |
| Ransomware | Selective propagation | Triggered by malicious link, attachment, or exploit | User files और hard drives को robust cryptographic algorithms से lock कर देता है और decryption key के लिए ransom demand करता है। |
| Spyware | Stealth-mode running | Embedded in downloads or unauthorized apps | User की browsing habits, live camera/mic feeds और account keystrokes (Keylogger) की silent surveillance करके external server पर भेजता है। |
| Rootkit | Advanced evasion code | Infiltrates operating system core/kernel | Deep administrative privileges acquire करता है; standard antivirus scanners और OS utilities से खुद को hide कर लेता है। |
| Logic Bomb | Dormant code within legitimate programs | Predefined Trigger Condition (Date, event, user deletion) | Criteria match होते ही execute होकर database delete कर देता है या system crash trigger करता है। |
| Browser Hijacker & Adware | Profile modifier | Bundled with free utilities / installers | Default search engine, DNS settings और homepages redirect करता है; unclosable intrusive ads inject करता है। |
Virus vs. Worm: The Fundamental Distinction
- Virus: इसे host program (जैसे
.exeया.docfile) की ज़रूरत होती है। जब तक user उस host file को execute नहीं करता, virus dormant (निष्क्रिय) रहता है। - Worm: यह completely standalone software है। यह operating system की vulnerabilities और active internet/LAN connections का लाभ उठाकर खुद को independent machines पर autonomously copy कर लेता है।
3. Types of Hackers: Classification & Motives
Cybersecurity domain में "Hacker" शब्द केवल अपराधी के लिए प्रयुक्त नहीं होता। उनकी intent (मंशा), authorization (वैधानिक अनुमति) और methodology के आधार पर Hackers को निम्न categories में बाँटा गया है:
- White Hat Hackers (Ethical Hackers): Organizations और governments द्वारा legally authorized cybersecurity professionals। ये penetration testing और vulnerability assessment (VAPT) execute करते हैं ताकि system के security flaws को attackers से पहले detect और patch किया जा सके।
- Black Hat Hackers (Malicious Hackers): Unethical attackers जो strictly illegal motives (financial fraud, intellectual property theft, operational sabotage) के लिए unauthorized systems breach करते हैं।
- Grey Hat Hackers: Ethical और malicious boundaries के intermediate zone में काम करते हैं। ये बिना official permission के systems access करते हैं, लेकिन destructive harm करने के बजाय vulnerability को publicize करते हैं या developer से fix के बदले recognition/bug-bounty demand करते हैं।
- Script Kiddies: Low-skilled beginners जो underlying architecture समझे बिना internet पर readily available pre-written scripts, automated exploitation tools और software kits चलाकर attacks initiate करते हैं।
- Hacktivists: Political, ideological या religious campaigns से driven attackers। इनका मुख्य weapon websites को deface करना, confidential internal communications leak करना या public awareness के नाम पर high-profile servers पर DDoS execute करना होता है।
- State-Sponsored Hackers: Nation-states द्वारा directly funded और deployed military-grade cyber units। इनका primary focus international espionage, sovereign infrastructure compromise, defense data infiltration और diplomatic reconnaissance होता है।
- Suicide Hackers / Cyber Terrorists: ऐसे destructive agents जो critical national power grids, automated banking clearing networks या air traffic radars को cripple करने के लिए destructive attacks execute करते हैं।
- Phreakers: Telecom circuits, PSTN exchange protocols और switching networks को manipulate करके unauthorized routing या free access gain करने वाले specialized hackers।
4. Firewall: Architecture & Security Functionality
Cybersecurity examinations और practical implementations में Firewall को लेकर सबसे common misconception यह है कि इसे malware मान लिया जाता है।
Firewall वास्तव में एक Security Barrier (Network Defense Mechanism) है।
[ External Internet / Untrusted Network ]
|
v
+---------------------------+
| FIREWALL FILTERING | <-- Rule-based packet inspection
+---------------------------+
|
(Only Verified Data Allowed)
v
[ Internal LAN / Trusted Enterprise Network ]
Key Functions of a Firewall
- Traffic Inspection: Inbound (आने वाले) और Outbound (बाहर जाने वाले) network traffic को continuously monitor करता है।
- Access Control Lists (ACL): Pre-defined security parameters (IP addresses, protocols, port numbers) के आधार पर malicious packets को drop करता है।
- Types of Firewalls:
- Packet Filtering: Network layer पर headers और routing logic analyze करता है।
- Stateful Inspection: Open connections के state, handshakes और contextual context को verify करता है।
- Proxy Firewall: Internal client और internet destination के बीच intermediary shield बनकर identity hide करता है।
- Next-Generation Firewall (NGFW): Deep packet inspection (DPI), built-in intrusion prevention systems (IPS) और live threat intelligence capabilities provide करता है।
5. India's Legal & Institutional Cybersecurity Framework
डिजिटल इकोसिस्टम की सुरक्षा और electronic crime investigation के लिए भारत में multi-layered institutional architecture क्रियान्वित है:
Legal Frameworks
- Information Technology (IT) Act, 2000: Electronic records की legal validity, digital signatures, unapproved system hacking (Section 66), privacy breach और data theft offenses के लिए foundational act।
- Bharatiya Nyaya Sanhita (BNS), 2023: Modern digital extortion, organized online fraud, electronic identity counterfeiting और cyber scams को comprehensively define करता है।
- Digital Personal Data Protection (DPDP) Act, 2023: Citizen data consent architecture, corporate handling compliance और unauthorized data exposure पर rigorous penalties establish करता है।
National Security & Response Agencies (Under MHA & MeitY)
- I4C (Indian Cyber Crime Coordination Centre): Cyber crimes से संबंधित inter-state police coordination, real-time threat intelligence analytics और national centralized action की nodal body।
- CERT-In (Indian Computer Emergency Response Team): National incident response authority जो zero-day vulnerabilities, widespread malware alerts, systemic hacking breaches और critical patch notifications oversee करती है।
- NCIIPC (National Critical Information Infrastructure Protection Centre): Strategic critical assets—banking systems, atomic installations, telecommunication backbones और defense systems—के digital shielding के लिए dedicated unit।
6. Official Citizen Protection Systems & Practical Protocols
- Sanchar Saathi Initiative:
- CEIR Module: Lost या stolen smartphones के IMEI को centrally blacklist/block और locate करने का portal।
- TAFCOP Module: Citizen के नाम/Aadhaar पर कितने active telecom SIM connections जारी हैं, इसकी live verification और redundant connections deactivate करने का tool।
- M-Kavach 2: C-DAC द्वारा developed indigenous Android security framework, जो background suspicious permissions, dormant trojans और hidden malware apps scan करता है।
- National Reporting Mechanism (The Golden Hours Protocol):
- Toll-Free Helpline: 1930
- Online Portal: cybercrime.gov.in
- The 2-Hour Window: Financial fraud होते ही initial 2 hours (Golden Hours) के भीतर 1930 पर transaction IDs और UPI details के साथ incident report करने पर inter-bank settlement freeze trigger होता है, जिससे funds recover होने की probability maximum रहती है। More: 1930 FAQ.
Essential Best Practices for Everyday Security
- Hardware / Software 2FA: SMS OTP के स्थान पर authenticator apps या hardware security keys prioritize करें।
- Immediate App Updates: Play Store / App Store पर patch notes आते ही apps और OS versions update करें ताकि known exploits patch हो सकें।
- Zero-Trust for Unsolicited Media: WhatsApp या messaging apps पर आने वाली unknown
.apk,.zipया macro-enabled.pdffiles को कभी open न करें। - Regular Credential Rotation: Core banking passwords, corporate portals और master accounts के credentials हर 60–90 days में update करें।
Frequently asked questions
Is a firewall a type of malware?
No. A firewall is a security barrier that filters network traffic — it is not malware.
What is the difference between a virus and a worm?
A virus needs a host file and stays dormant until that file is executed. A worm is standalone and can spread across networks without a host file.
What should I do in the first two hours after a financial cyber fraud?
Dial 1930 and/or file on cybercrime.gov.in, share UTR/UPI details, and alert your bank immediately so freeze/recovery chances stay highest.
Official resources
- National Cyber Crime Reporting Portal · Helpline 1930
- CERT-In
- Sanchar Saathi
- MeitY
- RBI