Cyber Security
🔒 Log in to trackMalware types
🔒 Log in to trackMalware = malicious software. The family table:
| Malware | Behaviour | Spread |
|---|---|---|
| Virus | Attaches itself to a host file/program; corrupts data | Only when the infected file is run/shared |
| Worm | Self-replicates across networks without any host file or user action | Automatically over the network |
| Trojan (horse) | Disguises as useful software; opens backdoors, steals data | Does NOT self-replicate; user installs it |
| Ransomware | Encrypts the victim's files and demands ransom (WannaCry, 2017) | Mail attachments, exploits |
| Spyware | Secretly collects user activity/data | Bundled installs, drive-by |
| Keylogger | Records every keystroke (passwords, OTPs) | Often part of spyware/trojans |
| Adware | Forces unwanted advertisements | Freeware bundles |
| Rootkit | Hides deep in the OS with admin rights, concealing other malware | Exploits |
| Botnet | Network of infected 'zombie' machines under a attacker's control (used for DDoS/spam) | Worm/trojan infection |
| Logic bomb | Dormant code that fires on a trigger (date, event) | Planted insider/trojan |
WannaCry (2017) - global ransomware outbreak hitting unpatched Windows via the EternalBlue exploit - is the stock example question.
Malware — hostile software
Malware (MALicious softWARE) is any program written to harm, steal or spy. Exams test one skill: matching the malware's behaviour to its name.
| Malware | Signature behaviour |
|---|---|
| Virus | attaches itself to a file/program and spreads when that file is run — needs a host |
| Worm | self-replicates on its own across networks — needs no host file |
| Trojan horse | hides inside useful-looking software (free game, "update"); does not replicate |
| Ransomware | locks/encrypts your files and demands money (e.g. WannaCry, 2017) |
| Spyware | secretly collects your information and sends it out |
| Keylogger | records every keystroke — passwords typed are captured (a spyware cousin) |
| Adware | floods the screen with unwanted advertisements |
| Botnet | many infected "zombie" machines remotely controlled as one army (for spam/DDoS) |
| Rootkit | buries itself deep in the system, hides its presence, grants attacker admin rights |
The three distinctions exams plant
- Virus vs Worm: a virus rides on a host file and waits for you to run it; a worm needs no host — it crawls through the network by itself.
- Trojan vs Virus: a trojan never replicates — it waits, disguised as legitimate software, and opens the door from inside (backdoor).
- Ransomware vs Spyware: ransomware takes your files hostage for money; spyware takes copies quietly and leaves everything in place.
How malware arrives
Infected email attachments and links, pirated software, infected USB drives, drive-by downloads from unsafe sites, and fake "your PC is infected" pop-ups. Once inside, malware may slow the machine, corrupt or delete files, steal data, or enlist the machine into a botnet without the owner noticing anything beyond sluggishness.
Symptoms of an infected machine
Unexplained slowness, files renamed or missing, programs opening on their own, browser home page changed, sudden pop-ups, the fan and disk working when you do nothing. None of these proves malware alone — but together they are the exam's favourite scenario line.
Question types you will see
Each type: how to recognise it, the method step by step, and one question to try.
Malware identification by behaviour
A behaviour is described ('self-replicates without a host', 'disguises as useful software', 'encrypts files for ransom') and the malware is asked.
Needs a host file = Virus; self-replicates alone over the network = Worm.
Disguised as useful software, does not replicate = Trojan horse.
Locks files and demands money = Ransomware; watches silently = Spyware/Keylogger.
A program that enters a computer disguised as a free game and does not replicate is a:
Show solutionHide solution
Trojan horse — the disguise is its signature; replication belongs to virus/worm.
Ransomware scenarios
'Files are locked and money is demanded', 'WannaCry' or any hostage-style scenario.
Encrypt-and-demand-money = Ransomware — the fastest identification in the topic.
Defence = offline backups; paying the ransom is never advised.
WannaCry (2017) is the named example exams use.
A hospital finds all its patient records encrypted with a demand for money to unlock them. This is:
Show solutionHide solution
Ransomware — data taken hostage; restored from backups, not by paying.
Spyware, keylogger and adware
'Records every keystroke', 'secretly collects browsing data', 'shows endless advertisements' — the quiet watchers.
Records keystrokes = Keylogger (passwords captured as you type).
Secretly gathers and sends your information = Spyware.
Throws unwanted ads = Adware. All three spy or annoy — none of them locks files.
Ravi suspects his typed passwords are being captured as he types them. Which malware fits?
Show solutionHide solution
Keylogger — it records every keystroke, so even a strong password leaks.
Botnet and zombies
'A network of infected computers controlled by an attacker', 'zombie machines used for spam/DDoS'.
Botnet = many infected 'zombie' machines remotely commanded as one — owners usually unaware.
Botnets are the muscle behind DDoS floods and mass spam.
The controller is the 'bot herder'; your slow machine may be someone's soldier.
Thousands of infected home computers are ordered together to flood one server. The infected network is a:
Show solutionHide solution
Botnet — the army of zombies that powers DDoS attacks.
Shortcuts that save time
Virus needs a Vehicle (host file); Worm Wanders alone; Trojan Tricks you into installing. Replication + host = virus; replication without host = worm; disguise without replication = trojan.
Which malware self-replicates without needing a host file?
Show solutionHide solution
Worm.
Encrypts your files, demands money -> ransomware (WannaCry). 'Keystrokes recorded' -> keylogger. 'Hides with admin rights' -> rootkit. 'Zombie army' -> botnet.
WannaCry (2017) was an example of?
Show solutionHide solution
Ransomware.
Mistakes to avoid
Where most students lose marks on this subtopic.
Saying a trojan self-replicates - only viruses and worms replicate; a trojan relies on disguise.
Saying a worm needs a host file - the worm is host-free by definition.
Calling ransomware a 'data thief' - its business model is encryption + extortion.
Quick revision
Read this the night before the exam.
Virus needs a host; Worm needs none; Trojan replicates not.
Ransomware = lock and demand money (WannaCry 2017); Spyware spies; Keylogger records keystrokes.
Botnet = army of zombie machines; Rootkit = hidden admin-level intruder.
Malware spreads by attachments, pirated software, unsafe downloads.
Practice: 17 questions
Sets of 10, mixed across the question types above. Every answer has a step-by-step explanation.
Topic test · 10 questions
Suggested time 5 min · wrong answers go to your mistake notebook automatically.