Malware

Malware is malicious software that infiltrates systems without consent. A threat vector is how it gets in; an attack vector is the full infiltration plus infection.

The categories

Fileless and modern techniques

Modern malware goes fileless to dodge signature detection: it lives in memory rather than the file system.

The stages: a stage 1 dropper or downloader (lightweight shellcode) runs first. A dropper launches other malware from its payload, while a downloader pulls more tools later. Stage 2 typically installs a RAT for command and control, then comes the actions-on-objectives phase (exfiltration, encryption), then concealment (erasing logs, hiding tracks).

Living off the land: APTs abuse legitimate built-in system tools so their activity blends in.

Indicators of a malware attack

Account lockouts, concurrent sessions from different places, spikes in blocked content, impossible travel, unexplained resource consumption, resource inaccessibility (ransomware), out-of-cycle logging (activity at odd hours), missing or cleared logs, and publicly documented attacks naming your org.