EMZETT.
Login

Malware

Malware Image: Malware_statics_2011-03-16-es.svg: Kizar derivative work: Kizar (talk), CC BY-SA 3.0, Wikimedia Commons

In short: Umbrella term (“malicious software”) for any kind of software that deliberately causes damage, steals data or compromises systems.

In more detail: Malware is the umbrella term for specific subtypes such as viruses (spread by attaching themselves to other programs), worms (spread on their own via networks), trojans (disguise themselves as useful software) and ransomware (encrypts data and extorts a ransom). Protective measures include antivirus software, regular patches (much malware exploits known security holes), firewalls and user awareness (most malware gets into the system via social engineering).

In Depth

An overview of the most important malware categories and how they differ:

Virus       - attaches itself to other programs/files, needs human
              action (e.g. running an infected file) to spread
Worm        - spreads ON ITS OWN via networks, without anyone
              having to open a file (often exploits security holes)
Trojan      - disguises itself as useful/harmless software, doesn't
              spread by itself but is installed deliberately
Ransomware  - encrypts/locks data and extorts a ransom
Spyware     - secretly collects information about the user
Rootkit     - hides itself and other malware deep in the system, often
              with admin/kernel rights, hard to detect

These categories aren’t mutually exclusive — modern malware often combines several properties (a trojan can, for example, download ransomware that then spreads like a worm in the local network). The spreading route also differs greatly: classic viruses need an executed file, worms often exploit unpatched security holes in network services, and by far the most common entry route today is social engineering — phishing emails that get users to open a malicious attachment themselves or click a prepared link.

Multi-layered protection (“defence in depth”) is considered standard: antivirus software recognises known signatures, regular security updates close exploitable holes, a firewall blocks unwanted network connections, and backups (separate from the main system) ensure that even a successful attack doesn’t mean permanent data loss.

Signature-based vs. behaviour-based detection

Antivirus software traditionally recognises malware via signatures — unique hash values or characteristic byte patterns of already known malware, similar to a digital fingerprint. The problem: new, previously unknown malware (or even just a slightly modified version of known malware) is missed by purely signature-based scanners. Modern security solutions therefore supplement this with behaviour-based detection (heuristics): instead of looking for known patterns, they monitor SUSPICIOUS BEHAVIOUR (e.g. a program that suddenly starts encrypting thousands of files in a short time, or one that tries to manipulate system files) — this also detects previously unknown (“zero-day”) malware, but tends to produce more false alarms.

Fileless malware

A growing challenge is “fileless malware”: malicious software that isn’t stored as a classic file on the hard disk, but runs exclusively in memory and misuses legitimate tools already present in the operating system (e.g. PowerShell scripts run directly from a phishing email without ever saving a file). Because classic antivirus scanners primarily check files on the hard disk, fileless malware is considerably harder to detect — defence here requires monitoring unusual PROCESS ACTIVITY rather than classic file scanning.

Advanced persistent threats (APT)

At the other end of the spectrum are “advanced persistent threats”: highly sophisticated, often state-sponsored attacks that don’t aim for quick, visible damage but for long-term, unnoticed access — sometimes over months or years. Such attacks often combine several of the malware categories mentioned with targeted social engineering and tailor-made zero-day exploits (see also Pegasus as a well-known example of commercial, highly sophisticated spyware) — the effort bears no relation to ordinary, widely spread malware, and they’re typically directed at high-value targets such as governments, critical infrastructure or large companies.

See also: Virus, Ransomware, Firewall