SaveMyCert
Cloud basics

What is malware? Types, how it spreads and how to defend

Malware, short for malicious software, is any program written to harm, exploit or gain unauthorised access to a system. It is an umbrella term: viruses, worms, trojans, ransomware and spyware are all kinds of malware, each with a different way of spreading and a different goal. This article explains the main types in plain terms, how malware typically reaches a system, and the defences that cut the risk.

What malware is and what it does

Malware is defined by intent, not technique: if software was built to damage systems, steal data, spy on users or take control without permission, it is malware. The damage varies enormously — from slowing a machine to stealing credentials, locking files for ransom or giving an attacker a hidden way back in.

Because it is such a broad category, it helps to learn the main types and what separates them.

The main types of malware

These are the types a beginner is most likely to meet, with the key difference in each:

  • Virus — attaches itself to a legitimate file or program and spreads when that file is run or shared.
  • Worm — spreads on its own across networks without needing anyone to run anything.
  • Trojan — disguises itself as something useful or harmless to get the user to install it.
  • Ransomware — encrypts your data and demands payment for the key. Our what is ransomware article covers it in depth.
  • Spyware — secretly watches activity and collects information such as passwords or browsing habits.

How malware spreads

Malware reaches systems through a handful of recurring routes: malicious email attachments and links, software downloaded from untrustworthy sources, infected removable drives, and vulnerabilities in software that has not been patched. Many of these start with a person being tricked, which is why phishing and other social engineering tactics are so closely tied to malware. See our what is phishing explainer for how that first step works.

How to defend against malware

Good defence is layered rather than a single product:

  • Patch promptly so known vulnerabilities cannot be exploited.
  • Apply least privilege, so malware that runs inherits as little access as possible.
  • Use endpoint protection that detects and blocks malicious software.
  • Filter network traffic with a firewall. Our what is a firewall explainer covers the basics.
  • Train people to recognise suspicious messages and downloads, and keep tested backups.

Malware and cloud security

Malware is not only a problem for laptops: servers and cloud workloads can be infected too, and the shared responsibility model means securing them is largely your job. Our what is cloud security article sets that context out. For structured study, ISC2 Certified in Cybersecurity and the AWS Certified Security – Specialty both cover the topic, and our /revision library covers that syllabus lesson by lesson.

Ready to start studying — free?

Original practice questions, timed mock exams and revision notes. No card, nothing to pay.

Jump straight into an exam
SCS-C03CC

Questions, answered

Malware is any software designed to harm a system, steal data or gain unauthorised access. The name is short for malicious software, and it covers many kinds of threat.

Sources

Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.

Keep reading

Cloud basics
What is penetration testing? Ethical hacking explained
Cloud basics
What is phishing? How it works and how to spot it
Cloud basics
What is public key infrastructure (PKI)?
Cloud basics
What is ransomware? How it works and how to protect against it