All courses

Cyber Threat Awareness

Virus & Malware, Ransomware, Phishing, Deep fake, Adversary in the Middle, Smishing, and Social Engineering, Cyber Crime.

EnglishIS Security30 AED

Price per attendee · VAT added at payment

About this course

1. Virus & Malware

A computer virus or malware is malicious software designed to damage, disrupt, or gain unauthorized access to systems, networks, or data. Malware includes viruses, worms, trojans, spyware, and adware.

Viruses typically attach themselves to legitimate files and spread when the file is opened. Worms can spread independently across networks. Trojans disguise themselves as legitimate software but perform harmful actions once installed. Spyware secretly collects user information, while adware displays unwanted advertisements.

Malware can cause data loss, system slowdown, unauthorized access, or complete system compromise.

Common infection sources include:

  • Email attachments

  • Untrusted downloads

  • Pirated software

  • Removable media (USB drives)

  • Malicious websites

Key practices:

  • Install and update antivirus software

  • Avoid downloading from unknown sources

  • Keep systems and applications updated

  • Do not open suspicious attachments

  • Use security patches regularly

Prevention and awareness are critical to reducing malware risks.


2. Ransomware

Ransomware is a type of malware that encrypts files or locks systems and demands payment (ransom) to restore access. It is one of the most damaging cyber threats affecting individuals and organizations.

Once activated, ransomware can quickly spread across networks, encrypting critical data and disrupting business operations. Attackers often demand payment in cryptocurrency and may threaten to leak stolen data.

Ransomware typically enters systems through phishing emails, malicious downloads, or security vulnerabilities.

Key practices:

  • Regularly back up important data offline or in secure cloud storage

  • Do not open suspicious email attachments or links

  • Keep systems updated with security patches

  • Use endpoint protection tools

  • Restrict user access privileges

Paying ransom does not guarantee data recovery and may encourage further attacks.

Strong prevention and backup strategies are essential defenses against ransomware.


3. Phishing

Phishing is a cyberattack where attackers impersonate trusted entities to trick users into revealing sensitive information such as passwords, financial data, or login credentials.

Phishing messages often appear as urgent emails, SMS messages, or fake websites that closely resemble legitimate organizations.

Common types include:

  • Email phishing

  • Spear phishing (targeted attacks)

  • Whaling (targeting executives)

  • Smishing (SMS-based phishing)

Key practices:

  • Verify sender identity before responding

  • Avoid clicking unknown links

  • Check website URLs carefully

  • Report suspicious messages immediately

  • Use MFA for added protection

Phishing relies heavily on deception and human error, making awareness the strongest defense.


4. Deepfake

Deepfakes are AI-generated audio, video, or images that realistically mimic real people. They are created using machine learning techniques to alter or fabricate content.

Deepfakes can be used for entertainment but are increasingly exploited for fraud, misinformation, identity theft, and reputational damage.

Examples include fake CEO videos instructing money transfers or impersonated voices used in scams.

Risks include:

  • Financial fraud

  • Identity manipulation

  • Misinformation campaigns

  • Social engineering attacks

Key practices:

  • Verify unusual requests through official channels

  • Be cautious of unexpected video/audio instructions

  • Cross-check information from trusted sources

  • Use authentication processes for financial approvals

Awareness is essential as deepfake technology becomes more advanced and accessible.


5. Adversary in the Middle (AiTM)

Adversary in the Middle (AiTM) is a cyberattack where an attacker secretly intercepts communication between two parties to steal data or manipulate information.

Unlike traditional “man-in-the-middle” attacks, AiTM techniques often bypass authentication mechanisms, including MFA, by capturing session cookies or login tokens.

Common targets include email accounts, banking systems, and corporate logins.

Key practices:

  • Always use secure HTTPS connections

  • Avoid logging in through suspicious links

  • Use phishing-resistant MFA methods

  • Monitor account activity regularly

  • Use VPNs on public networks

AiTM attacks are highly deceptive and difficult to detect without strong security controls.


6. Smishing

Smishing (SMS phishing) is a type of phishing attack delivered through text messages. Attackers send messages pretending to be banks, service providers, or government agencies to trick users into clicking malicious links or sharing sensitive information.

Messages often create urgency, such as account suspension alerts, delivery notifications, or prize winnings.

Risks include credential theft, financial fraud, and malware installation.

Key practices:

  • Do not click links in unsolicited SMS messages

  • Verify messages through official apps or websites

  • Do not share OTPs or personal details via SMS

  • Block and report suspicious numbers

  • Enable spam filtering on mobile devices

Smishing exploits trust in mobile communication, making caution essential.


7. Social Engineering

Social engineering is a manipulation technique used by attackers to trick individuals into revealing confidential information or performing actions that compromise security.

Instead of hacking systems directly, attackers exploit human psychology such as trust, fear, urgency, or curiosity.

Common techniques include impersonation, pretexting, baiting, and phishing.

Examples:

  • Fake IT support calls requesting passwords

  • Fraudulent emails requesting urgent payments

  • Fake colleagues asking for sensitive documents

Key practices:

  • Verify identities before sharing information

  • Follow official approval processes

  • Be cautious of urgency-based requests

  • Do not share passwords or sensitive data

  • Report suspicious interactions

Human awareness is the strongest defense against social engineering.


8. Cyber Crime

Cyber crime refers to illegal activities carried out using computers, networks, or digital systems. These crimes target individuals, organizations, or governments for financial gain, disruption, or data theft.

Types of cyber crime include:

  • Identity theft

  • Financial fraud

  • Hacking and unauthorized access

  • Online scams

  • Data breaches

  • Cyber extortion

Cyber criminals use techniques such as malware, phishing, and social engineering to achieve their goals.

Key practices for protection:

  • Use strong security controls (MFA, encryption)

  • Keep systems updated

  • Monitor accounts for suspicious activity

  • Report cyber incidents immediately

  • Follow cybersecurity policies

Cyber crime continues to evolve, making continuous awareness and strong security practices essential.

What you'll learn

  1. 1

    Virus & Malware

    Malicious software that is specifically designed to disrupt, damage, or gain unauthorized access to a computer system is known as malware

  2. 2

    Ransomware

    Ransomware is malicious software designed to block access to a computer system until a sum of money is paid, thus holding your system for “ransom.”

  3. 3

    Phishing

    Phishing is an attempt to steal account information by pretending to be a trustworthy person or company via email.

  4. 4

    Deep Fake

    A deepfake is a realistic but fake video, image, or audio clip created using artificial intelligence (AI) to alter original content,

  5. 5

    Adversary in the Middle

    An Adversary-in-The-Middle (AiTM) attack is when an attacker intercepts communication between two parties who believe they are directly communicating with each other.

  6. 6

    Smishing

    Smishing is a technique in which hackers use a compelling text message to trick their victims into taking an unwanted action.

  7. 7

    Social Engineering

    The act of using human interaction and manipulation to obtain sensitive information about a person, organization, or its computer systems.

  8. 8

    Cyber Crime.

    Cybercrime works like a business, with bad actors buying, selling, and trading tools, access, and stolen data.

Need the full ADHICS compliance lifecycle — governance, risk, audit and training at enterprise scale? Explore GRSCIA