ExamShortcut

Cyber Security

🔒 Log in to track
high importance⚡ 9 shortcuts4 subtopics

Malware = malicious software. The family table:

MalwareBehaviourSpread
VirusAttaches itself to a host file/program; corrupts dataOnly when the infected file is run/shared
WormSelf-replicates across networks without any host file or user actionAutomatically over the network
Trojan (horse)Disguises as useful software; opens backdoors, steals dataDoes NOT self-replicate; user installs it
RansomwareEncrypts the victim's files and demands ransom (WannaCry, 2017)Mail attachments, exploits
SpywareSecretly collects user activity/dataBundled installs, drive-by
KeyloggerRecords every keystroke (passwords, OTPs)Often part of spyware/trojans
AdwareForces unwanted advertisementsFreeware bundles
RootkitHides deep in the OS with admin rights, concealing other malwareExploits
BotnetNetwork of infected 'zombie' machines under a attacker's control (used for DDoS/spam)Worm/trojan infection
Logic bombDormant code that fires on a trigger (date, event)Planted insider/trojan

WannaCry (2017) - global ransomware outbreak hitting unpatched Windows via the EternalBlue exploit - is the stock example question.

Detailed notes

Malware — hostile software

Malware (MALicious softWARE) is any program written to harm, steal or spy. Exams test one skill: matching the malware's behaviour to its name.

MalwareSignature behaviour
Virusattaches itself to a file/program and spreads when that file is run — needs a host
Wormself-replicates on its own across networks — needs no host file
Trojan horsehides inside useful-looking software (free game, "update"); does not replicate
Ransomwarelocks/encrypts your files and demands money (e.g. WannaCry, 2017)
Spywaresecretly collects your information and sends it out
Keyloggerrecords every keystroke — passwords typed are captured (a spyware cousin)
Adwarefloods the screen with unwanted advertisements
Botnetmany infected "zombie" machines remotely controlled as one army (for spam/DDoS)
Rootkitburies itself deep in the system, hides its presence, grants attacker admin rights

The three distinctions exams plant

  1. Virus vs Worm: a virus rides on a host file and waits for you to run it; a worm needs no host — it crawls through the network by itself.
  2. Trojan vs Virus: a trojan never replicates — it waits, disguised as legitimate software, and opens the door from inside (backdoor).
  3. Ransomware vs Spyware: ransomware takes your files hostage for money; spyware takes copies quietly and leaves everything in place.

How malware arrives

Infected email attachments and links, pirated software, infected USB drives, drive-by downloads from unsafe sites, and fake "your PC is infected" pop-ups. Once inside, malware may slow the machine, corrupt or delete files, steal data, or enlist the machine into a botnet without the owner noticing anything beyond sluggishness.

Symptoms of an infected machine

Unexplained slowness, files renamed or missing, programs opening on their own, browser home page changed, sudden pop-ups, the fan and disk working when you do nothing. None of these proves malware alone — but together they are the exam's favourite scenario line.

Quick revision

  • Virus needs a host; Worm needs none; Trojan replicates not.
  • Ransomware = lock and demand money (WannaCry 2017); Spyware spies; Keylogger records keystrokes.
  • Botnet = army of zombie machines; Rootkit = hidden admin-level intruder.
  • Malware spreads by attachments, pirated software, unsafe downloads.

Types of questions asked

Every way this subtopic shows up in exams — how to recognise it, the formula or logic to use, and a solved example.

Type 1: Malware identification by behaviourvery common4 practice Q
How to spot it:

A behaviour is described ('self-replicates without a host', 'disguises as useful software', 'encrypts files for ransom') and the malware is asked.

  1. Needs a host file = Virus; self-replicates alone over the network = Worm.
  2. Disguised as useful software, does not replicate = Trojan horse.
  3. Locks files and demands money = Ransomware; watches silently = Spyware/Keylogger.

Example: A program that enters a computer disguised as a free game and does not replicate is a:

Trojan horse — the disguise is its signature; replication belongs to virus/worm.

Type 2: Ransomware scenarioscommon3 practice Q
How to spot it:

'Files are locked and money is demanded', 'WannaCry' or any hostage-style scenario.

  1. Encrypt-and-demand-money = Ransomware — the fastest identification in the topic.
  2. Defence = offline backups; paying the ransom is never advised.
  3. WannaCry (2017) is the named example exams use.

Example: A hospital finds all its patient records encrypted with a demand for money to unlock them. This is:

Ransomware — data taken hostage; restored from backups, not by paying.

Type 3: Spyware, keylogger and adwarecommon3 practice Q
How to spot it:

'Records every keystroke', 'secretly collects browsing data', 'shows endless advertisements' — the quiet watchers.

  1. Records keystrokes = Keylogger (passwords captured as you type).
  2. Secretly gathers and sends your information = Spyware.
  3. Throws unwanted ads = Adware. All three spy or annoy — none of them locks files.

Example: Ravi suspects his typed passwords are being captured as he types them. Which malware fits?

Keylogger — it records every keystroke, so even a strong password leaks.

Type 4: Botnet and zombiesoccasional3 practice Q
How to spot it:

'A network of infected computers controlled by an attacker', 'zombie machines used for spam/DDoS'.

  1. Botnet = many infected 'zombie' machines remotely commanded as one — owners usually unaware.
  2. Botnets are the muscle behind DDoS floods and mass spam.
  3. The controller is the 'bot herder'; your slow machine may be someone's soldier.

Example: Thousands of infected home computers are ordered together to flood one server. The infected network is a:

Botnet — the army of zombies that powers DDoS attacks.

Shortcut tricks

⚡ V-W-T triangle

Virus needs a Vehicle (host file); Worm Wanders alone; Trojan Tricks you into installing. Replication + host = virus; replication without host = worm; disguise without replication = trojan.

Example: Which malware self-replicates without needing a host file?

Worm.

⚡ Ransom = Ransomware

Encrypts your files, demands money -> ransomware (WannaCry). 'Keystrokes recorded' -> keylogger. 'Hides with admin rights' -> rootkit. 'Zombie army' -> botnet.

Example: WannaCry (2017) was an example of?

Ransomware.

Where students lose marks

  • Saying a trojan self-replicates - only viruses and worms replicate; a trojan relies on disguise.

  • Saying a worm needs a host file - the worm is host-free by definition.

  • Calling ransomware a 'data thief' - its business model is encryption + extortion.

Practice sets — 17 questions

Sets of 10, mixed across the question types above. Each answer comes with a step-by-step explanation.

Topic test · 10 questions

Suggested time 5 min · wrong answers go to your mistake notebook automatically.