Cyber threats · Learn

What is malware?

Malware is any software built to do harm, and ransomware is the variant that has reshaped every security budget. Here is what the main types do, how they get in, and how to keep them out.

Cyber threats · LearnSecurity services Download PDF
TL;DR

Malware is any software written to cause harm: viruses, worms, trojans, spyware, and ransomware. It usually arrives through a phishing attachment, a malicious download, or an unpatched internet-facing system. Ransomware is the most disruptive variant, encrypting your data and demanding payment, and modern operators steal a copy first to add extortion. The defenses are patching, endpoint detection, least privilege, and tested backups.

By Shubham Kandhare, Delivery Manager, SecureLayer7Updated

How does malware get in?

Malware needs a way onto your systems, and attackers reuse the same handful of doors:

  • A phishing attachment or link that a person opens.
  • A malicious or trojanised download, including fake software and cracked apps.
  • An unpatched, internet-facing service the attacker exploits directly.
  • A supply-chain compromise, where a trusted update or dependency is poisoned.
  • Removable media, still a real path in some environments.

Once it runs, malware typically tries to persist (survive a reboot), escalate privileges, and reach out to a server the attacker controls for instructions.

The main types of malware

Malware is a family, not a single thing:

  • Viruses attach to files and spread when those files run.
  • Worms spread on their own across a network, with no user action.
  • Trojans disguise themselves as something useful to get you to run them.
  • Ransomware encrypts your data and demands payment.
  • Spyware and infostealers quietly harvest passwords, cookies, and data.
  • Rootkits hide deep in the system to evade detection.
  • Loaders and botnets turn an infected machine into a foothold or a resource the attacker rents out.

Ransomware and double extortion

Ransomware encrypts your files and demands payment for the key. Modern operators go further with double extortion: they steal a copy of the data first, so even if you restore from backup, they can threaten to publish it.

For most organisations, a ransomware incident is not an exotic exploit. It is the basics failing in sequence: a phished credential or unpatched service to get in, no multi-factor authentication to slow them, over-broad access to spread, and backups that were never tested to recover. Fix those and ransomware becomes a bad day rather than a business-ending one.

Signs of a malware infection

Malware is not always obvious, but common signs include machines running slow or behaving oddly, unexpected outbound network traffic, security tools being disabled, new accounts or scheduled tasks you did not create, and, in the case of ransomware, files renamed or encrypted with a ransom note. The reliable way to catch what these miss is endpoint detection and response feeding alerts to someone who acts on them.

How to defend against malware

The controls that stop malware are the same ones that stop most attacks:

  • Patch operating systems, software, and internet-facing services promptly.
  • Run endpoint protection (EDR) that detects malicious behaviour, not just known signatures.
  • Enforce least privilege so one infected machine cannot reach everything.
  • Filter email and block risky macros and attachments at the gateway.
  • Keep tested, offline-capable backups as your ransomware safety net.
  • Segment your network so malware cannot spread freely.

A penetration test shows whether, once one machine is compromised, an attacker could actually reach the systems that matter.

References

  1. [1]StopRansomware(CISA)
  2. [2]Malware, Phishing, and Ransomware(CISA)
  3. [3]MITRE ATT&CK(MITRE)
Related terms

Ransomware turned malware from an IT nuisance into a board-level risk. The defenses did not change, though: patch, detect, contain, and keep backups you have actually tested.

Common questions

Malware, asked often

Show all 6 questions

Scope an engagement

Find out whether one infected machine could take down the rest.

We test how far an attacker could spread from a single foothold, across your endpoints, network, and cloud, and hand your team the path and the fix before ransomware finds it.