Cyber Security
🔒 Log in to trackMalware types
🔒 Log in to trackMalware = malicious software. The family table:
| Malware | Behaviour | Spread |
|---|---|---|
| Virus | Attaches itself to a host file/program; corrupts data | Only when the infected file is run/shared |
| Worm | Self-replicates across networks without any host file or user action | Automatically over the network |
| Trojan (horse) | Disguises as useful software; opens backdoors, steals data | Does NOT self-replicate; user installs it |
| Ransomware | Encrypts the victim's files and demands ransom (WannaCry, 2017) | Mail attachments, exploits |
| Spyware | Secretly collects user activity/data | Bundled installs, drive-by |
| Keylogger | Records every keystroke (passwords, OTPs) | Often part of spyware/trojans |
| Adware | Forces unwanted advertisements | Freeware bundles |
| Rootkit | Hides deep in the OS with admin rights, concealing other malware | Exploits |
| Botnet | Network of infected 'zombie' machines under a attacker's control (used for DDoS/spam) | Worm/trojan infection |
| Logic bomb | Dormant code that fires on a trigger (date, event) | Planted insider/trojan |
WannaCry (2017) - global ransomware outbreak hitting unpatched Windows via the EternalBlue exploit - is the stock example question.
Detailed notes
Malware — hostile software
Malware (MALicious softWARE) is any program written to harm, steal or spy. Exams test one skill: matching the malware's behaviour to its name.
| Malware | Signature behaviour |
|---|---|
| Virus | attaches itself to a file/program and spreads when that file is run — needs a host |
| Worm | self-replicates on its own across networks — needs no host file |
| Trojan horse | hides inside useful-looking software (free game, "update"); does not replicate |
| Ransomware | locks/encrypts your files and demands money (e.g. WannaCry, 2017) |
| Spyware | secretly collects your information and sends it out |
| Keylogger | records every keystroke — passwords typed are captured (a spyware cousin) |
| Adware | floods the screen with unwanted advertisements |
| Botnet | many infected "zombie" machines remotely controlled as one army (for spam/DDoS) |
| Rootkit | buries itself deep in the system, hides its presence, grants attacker admin rights |
The three distinctions exams plant
- Virus vs Worm: a virus rides on a host file and waits for you to run it; a worm needs no host — it crawls through the network by itself.
- Trojan vs Virus: a trojan never replicates — it waits, disguised as legitimate software, and opens the door from inside (backdoor).
- Ransomware vs Spyware: ransomware takes your files hostage for money; spyware takes copies quietly and leaves everything in place.
How malware arrives
Infected email attachments and links, pirated software, infected USB drives, drive-by downloads from unsafe sites, and fake "your PC is infected" pop-ups. Once inside, malware may slow the machine, corrupt or delete files, steal data, or enlist the machine into a botnet without the owner noticing anything beyond sluggishness.
Symptoms of an infected machine
Unexplained slowness, files renamed or missing, programs opening on their own, browser home page changed, sudden pop-ups, the fan and disk working when you do nothing. None of these proves malware alone — but together they are the exam's favourite scenario line.
Quick revision
- Virus needs a host; Worm needs none; Trojan replicates not.
- Ransomware = lock and demand money (WannaCry 2017); Spyware spies; Keylogger records keystrokes.
- Botnet = army of zombie machines; Rootkit = hidden admin-level intruder.
- Malware spreads by attachments, pirated software, unsafe downloads.
Types of questions asked
Every way this subtopic shows up in exams — how to recognise it, the formula or logic to use, and a solved example.
Type 1: Malware identification by behaviourvery common4 practice Q
A behaviour is described ('self-replicates without a host', 'disguises as useful software', 'encrypts files for ransom') and the malware is asked.
- Needs a host file = Virus; self-replicates alone over the network = Worm.
- Disguised as useful software, does not replicate = Trojan horse.
- Locks files and demands money = Ransomware; watches silently = Spyware/Keylogger.
Example: A program that enters a computer disguised as a free game and does not replicate is a:
Trojan horse — the disguise is its signature; replication belongs to virus/worm.
Type 2: Ransomware scenarioscommon3 practice Q
'Files are locked and money is demanded', 'WannaCry' or any hostage-style scenario.
- Encrypt-and-demand-money = Ransomware — the fastest identification in the topic.
- Defence = offline backups; paying the ransom is never advised.
- WannaCry (2017) is the named example exams use.
Example: A hospital finds all its patient records encrypted with a demand for money to unlock them. This is:
Ransomware — data taken hostage; restored from backups, not by paying.
Type 3: Spyware, keylogger and adwarecommon3 practice Q
'Records every keystroke', 'secretly collects browsing data', 'shows endless advertisements' — the quiet watchers.
- Records keystrokes = Keylogger (passwords captured as you type).
- Secretly gathers and sends your information = Spyware.
- Throws unwanted ads = Adware. All three spy or annoy — none of them locks files.
Example: Ravi suspects his typed passwords are being captured as he types them. Which malware fits?
Keylogger — it records every keystroke, so even a strong password leaks.
Type 4: Botnet and zombiesoccasional3 practice Q
'A network of infected computers controlled by an attacker', 'zombie machines used for spam/DDoS'.
- Botnet = many infected 'zombie' machines remotely commanded as one — owners usually unaware.
- Botnets are the muscle behind DDoS floods and mass spam.
- The controller is the 'bot herder'; your slow machine may be someone's soldier.
Example: Thousands of infected home computers are ordered together to flood one server. The infected network is a:
Botnet — the army of zombies that powers DDoS attacks.
Shortcut tricks
⚡ V-W-T triangle
Virus needs a Vehicle (host file); Worm Wanders alone; Trojan Tricks you into installing. Replication + host = virus; replication without host = worm; disguise without replication = trojan.
Example: Which malware self-replicates without needing a host file?
Worm.
⚡ Ransom = Ransomware
Encrypts your files, demands money -> ransomware (WannaCry). 'Keystrokes recorded' -> keylogger. 'Hides with admin rights' -> rootkit. 'Zombie army' -> botnet.
Example: WannaCry (2017) was an example of?
Ransomware.
Where students lose marks
Saying a trojan self-replicates - only viruses and worms replicate; a trojan relies on disguise.
Saying a worm needs a host file - the worm is host-free by definition.
Calling ransomware a 'data thief' - its business model is encryption + extortion.
Practice sets — 17 questions
Sets of 10, mixed across the question types above. Each answer comes with a step-by-step explanation.
Topic test · 10 questions
Suggested time 5 min · wrong answers go to your mistake notebook automatically.