Skip to content
Back to WikiDefinitions

Malware

Malware (malicious software) is any software intentionally designed to cause damage to computers, servers, networks, or users. It encompasses a wide range of threats including viruses, trojans, spyware, adware, and rootkits.

Common types of malware

Viruses attach to legitimate programs and spread when the infected program runs. Trojans disguise themselves as legitimate software to trick users into installation. Worms self-replicate and spread across networks without user interaction. Spyware secretly monitors user activity and collects sensitive information. Rootkits hide deep in the operating system to provide persistent, undetected access. Keyloggers record keystrokes to capture passwords and sensitive data. Fileless malware operates entirely in memory, leaving no traces on disk.

Infection vectors

Email attachments remain the most common delivery method. Drive-by downloads from compromised or malicious websites. Infected USB drives and removable media. Software supply chain compromises: legitimate software updates containing malware. Exploiting unpatched software vulnerabilities. Social engineering to trick users into running malicious code. Malicious advertisements (malvertising) on legitimate websites.

Detection and response

Deploy endpoint detection and response (EDR) for continuous behavioural monitoring and kernel-level telemetry. Keep detections updated and run scheduled scans. Monitor for indicators of compromise (IoCs): unusual outbound traffic (LOLBins calling attacker infrastructure), unexpected processes, persistence artefacts (Scheduled Tasks, Run keys, services), and file modifications. Enforce application allowlisting (AppLocker, WDAC) on high-risk endpoints. When malware is detected: isolate the host from the network (do not power off, to preserve volatile memory), capture a memory image for offline analysis, identify the malware family via EDR telemetry or a YARA scan against known rules, determine infection scope across the estate, preserve disk and registry artefacts, and perform remediation only after the initial access vector is confirmed.

Discuss this with a senior responder.

Discuss this with a senior responder
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now