Malware
Malware is malicious software that infiltrates systems without consent. A threat vector is how it gets in; an attack vector is the full infiltration plus infection.
The categories
- Virus: malicious code that runs and infects when executed. Ten flavors to recognize: boot sector, macro (inside a document), program (infects executables), multipartite (boot + program), encrypted (hides via encryption), polymorphic (changes its code each run), metamorphic (fully rewrites itself), stealth, armored (resists analysis), hoax (scare-based social engineering).
- Worm: self-replicates and spreads across the network with no user action. Dangerous both for infection and for the traffic it generates.
- Trojan: disguised as desirable software. A Remote Access Trojan (RAT) gives the attacker remote control and acts as a backdoor for persistence.
- Ransomware: encrypts data, demands payment. Defend with backups, patching, awareness, MFA. If hit: never pay, disconnect from the network, notify authorities, restore from known-good backups.
- Botnet/zombie: compromised machines (zombies) run by a command-and-control node, used for DDoS, spam, pivoting, cracking. Attackers typically use only 20-25% of a zombie’s power to stay hidden.
- Rootkit: gains admin or root control undetected by moving from Ring 3 (user mode) toward Ring 0 (kernel mode), often via DLL injection or shims. Best detection: boot from external live media and scan the internal drive.
- Backdoor / logic bomb: a backdoor bypasses auth for persistent access; a logic bomb waits for a trigger condition to fire. (Easter eggs are hidden dev features that can carry vulnerabilities.)
- Keylogger: records keystrokes, in software (bundled or phished in) or hardware (an inline USB or cable). Defend with patching, AV, MFA, keystroke encryption, physical checks.
- Spyware: gathers info secretly. Bloatware is unrequested preinstalled software: not malicious, but it wastes resources and adds attack surface.
Fileless and modern techniques
Modern malware goes fileless to dodge signature detection: it lives in memory rather than the file system.
The stages: a stage 1 dropper or downloader (lightweight shellcode) runs first. A dropper launches other malware from its payload, while a downloader pulls more tools later. Stage 2 typically installs a RAT for command and control, then comes the actions-on-objectives phase (exfiltration, encryption), then concealment (erasing logs, hiding tracks).
Living off the land: APTs abuse legitimate built-in system tools so their activity blends in.
Indicators of a malware attack
Account lockouts, concurrent sessions from different places, spikes in blocked content, impossible travel, unexplained resource consumption, resource inaccessibility (ransomware), out-of-cycle logging (activity at odd hours), missing or cleared logs, and publicly documented attacks naming your org.