Computer Literacy · Foundations
Malware
On this page 9 sections
In 30 seconds
Malware Software written to harm, disrupt, or exploit a device or the data on it; short for 'malicious software.' Full entry → is any software written to harm or exploit a device or its data. It comes in recognizable types: viruses that ride along in files, worms that spread by themselves, Trojans that hide inside programs you trust, Ransomware Malware that encrypts a victim's files to make them unusable and demands payment in exchange for the decryption key. Full entry → that locks your files for payment, plus Spyware Malware secretly installed to gather information about a person or organization without their knowledge. Full entry →, adware, rootkits, and botnets. Most infections start with a bad attachment, link, or download. You defend with updated software, reputable antivirus, care with what you open, a Firewall A barrier that filters network traffic and can block some malicious connections before they reach a device. Full entry →, and backups.
Why this matters
Malware is behind most of the everyday damage people suffer online: stolen passwords, drained accounts, locked-up files, and hijacked machines. Recognizing the main types and how they arrive lets you make good split-second decisions, like not opening an unexpected attachment or an installer from a random site. Ransomware in particular can shut down a hospital, school, or business, and the only reliable way back is an offline backup made before the attack. Whatever field you enter, you will handle data on devices that are targets, and basic malware literacy is what keeps a single careless click from becoming a crisis.
The college version
What malware is, and the main types
Malware is short for malicious software: any program or file written to harm a device, disrupt its operation, or steal, expose, or lock up the data on it. The defining trait is intent. A program is malware not because of how it is built but because it is meant to work against the owner of the device. Security agencies group malware into recognizable types by how each behaves. A Virus Malware that attaches to a file or program and needs a host and a user action to spread. Full entry → attaches itself to a file or program and needs both a host to live in and a user action, such as opening an infected attachment or running a shared file, to spread. A Worm Self-replicating malware that copies itself across a network to other computers without a host program or user action. Full entry → is different in a way worth remembering: it is self-replicating and copies itself across a network to other computers without needing a host program or any action from a user, which is why worms can spread explosively. A Trojan, named for the Trojan horse, hides harmful behavior inside something that looks legitimate, so you install it yourself believing it is a useful app, a game, or a codec. Ransomware encrypts your files so you cannot open them and then demands payment for the key; it is one of the most damaging threats today. Spyware is installed secretly to gather information about you, such as what you type or where you browse, without your knowledge. Adware forces unwanted advertising onto your screen and often travels bundled with free downloads. Two more names are worth knowing: a Rootkit A set of tools an attacker uses to conceal their presence on a compromised system and keep covert, high-level access. Full entry → is a set of tools an attacker uses to hide their presence and keep hidden access to a compromised machine, and a Botnet A network of infected computers an attacker controls remotely, often built with Trojans, to carry out large-scale tasks. Full entry → is a network of infected computers an attacker controls remotely, often assembled with Trojans, to send spam or attack other systems. These categories overlap in practice, and a single piece of malware can act as several at once.
How malware spreads and how to spot an infection
Most infections start with something you open or install. Malicious email attachments and links are the classic route: a message carries a booby-trapped document or a link to a hostile page, and opening it runs the code. Even ordinary-looking data files, such as a Word document, a PDF, a ZIP, or an image, can be weaponized to exploit a flaw in the program that opens them. Drive-by downloads infect you just for visiting a compromised or malicious web page, sometimes with no click at all. Untrusted software is another major channel: pirated apps, installers from unofficial sites, and 'free' tools frequently carry Trojans, which is why downloading only from the vendor's own site matters. Infected removable media, like a USB drive that runs automatically when plugged in, can carry malware between machines. Phishing messages are a common delivery method for all of this and are covered in their own lesson. Once malware is present, the machine often behaves oddly. Common signs include the device running noticeably slower, draining its battery quickly, crashing or throwing unexpected errors, refusing to shut down or restart, flooding you with pop-ups, redirecting your browser to pages you did not choose, changing your home page, or sprouting new icons or toolbars you never installed. Any one sign can have an innocent cause, but several at once are a strong hint that something is wrong and worth investigating rather than ignoring.
Defending yourself: layered protection and backups
No single tool stops malware, so security agencies recommend layers. Keep your operating system and applications updated, because most malware exploits known flaws that updates have already fixed; this is covered in depth in the Installing and Updating Software lesson. Install reputable antivirus or anti-malware software, keep its definitions current, and get it directly from the vendor rather than from an ad or an email link, since the software can only catch what it recognizes. Be cautious with what you open: treat unexpected attachments and links warily even when they seem to come from someone you know, and download software only from sources you trust. Turn on a firewall, which blocks some malicious traffic before it reaches you; most operating systems include one. Using an everyday account with limited permissions rather than an administrator account can keep an infection from spreading system-wide. Finally, back up your data, and treat this as the anchor of the whole plan. For ransomware specifically, backups are the defense that actually saves you: CISA recommends keeping backups that are offline, encrypted, and regularly tested, precisely because many ransomware strains hunt down and encrypt or delete any backups they can reach over the network. An offline backup made before an attack lets you restore your files instead of paying, which is why paying a ransom is never a substitute for a good backup. The Backups lesson covers how to build that backup strategy in detail. If you do get infected, disconnect from the internet, run an updated scan, and change your passwords from a device you know is clean.

Eli explains
The same idea, in plain words
Explain it like I’m 10
Malware is any program made to hurt your computer or steal your stuff instead of helping you. Some kinds sneak in attached to a file (a virus), some copy themselves from computer to computer on their own (a worm), and some pretend to be a game or app you want so you install them yourself (a Trojan). One nasty kind, ransomware, locks all your files and says 'pay us to get them back.' You stay safe by keeping your software updated, using a malware scanner, not opening surprise attachments or links, and keeping an extra copy of your important files somewhere safe and disconnected.
Picture it like this
Think of your computer as a house. A virus is a germ on something you bring inside; a worm is a burglar who copies their own key and lets themselves into every house on the street; a Trojan is a 'delivery' box you carry in yourself that has someone hiding inside; and ransomware is someone who changes all your locks and demands money for the new keys. Updates and antivirus are your locks and alarm, and a backup is a spare set of everything kept safely off-site.
Where the picture stops working
The house picture makes malware feel like a physical break-in, but malware is code and can copy itself instantly, hide with no visible trace, and travel worldwide in seconds. Real defense is not one strong lock but many small habits kept up over time, and even a careful person can still be hit, which is exactly why the off-site 'spare keys,' your backup, matter so much.
Worked example
A small clinic's front-desk computer starts acting strange one morning: it is sluggish, throws error pop-ups, and then displays a full-screen message saying the patient files are encrypted and a payment is required for the key. Walking through the concepts: the encryption-plus-payment demand identifies this as ransomware. How did it arrive? A staff member had opened an email attachment labeled as an invoice the day before, the classic malicious-attachment route. What now? Paying does not guarantee recovery and funds the attackers, so it is not the plan. Because the clinic keeps a nightly backup on an external drive that stays disconnected, they can wipe the machine, reinstall the system, apply updates, and restore yesterday's files. The offline backup, made before the attack, is what turns a disaster into an afternoon of cleanup, and it is why offline backups are the key ransomware defense.
Key takeaway
Malware is software built to harm or exploit you, and it comes in recognizable types that spread mostly through what you open or install. Defend with updates, reputable antivirus, caution with downloads and attachments, a firewall, and, above all, offline backups, which are the one defense that reliably beats ransomware.
Quick check
3 questions here, of 5 in this lesson’s practice set. Answers stay hidden until you check.
What most distinguishes a Trojan horse from a virus or a worm?
A user's files are suddenly encrypted and an on-screen message demands payment for a decryption key. Which type of malware is this, and what is the most reliable defense against losing the data?
Study tools & related lessonsYou’ll learn to · Common mistakes · Easily confused · Key vocabulary · Related
You’ll learn to
- Define malware and explain what distinguishes it from ordinary software.
- Distinguish the main types of malware (virus, worm, Trojan, ransomware, spyware, rootkit, botnet) by how each behaves.
- Explain how malware typically spreads and identify common signs of infection.
- Apply CISA's layered defenses, including why offline backups are the key ransomware defense.
- Analyze a scenario to identify a likely malware type and choose a sound first response.
Common mistakes
Calling every infection a 'virus.'
Virus is just one type of malware. Worms, Trojans, ransomware, spyware, and others behave differently, and naming the type helps you respond correctly.
Assuming antivirus software alone makes you safe.
Antivirus catches only what it recognizes. Real protection is layered: updates, caution with links and downloads, a firewall, limited-permission accounts, and backups.
Believing paying a ransom is the reliable way to get files back.
Payment does not guarantee a working key and encourages more attacks. A tested, offline backup made before the attack is the dependable recovery path.
Thinking phones, Macs, or 'careful' users cannot get malware.
Every platform is a target, and social engineering fools careful people. Habits and backups matter on all devices.
Confusing malware with phishing.
Phishing is a delivery and deception method; malware is the harmful software. Phishing is one common way malware is delivered, but they are not the same thing.
Easily confused
Virus vs. Worm
A virus needs a host file and a user action to spread; a worm self-replicates across a network with no host and no user action.
Trojan vs. Worm
A Trojan relies on tricking the user into running it; a worm spreads on its own without any user involvement.
Ransomware vs. Spyware
Ransomware announces itself by locking files and demanding payment; spyware stays hidden and quietly gathers information.
Key vocabulary
- Malware
- Software written to harm, disrupt, or exploit a device or the data on it; short for 'malicious software.'
- Virus
- Malware that attaches to a file or program and needs a host and a user action to spread.
- Worm
- Self-replicating malware that copies itself across a network to other computers without a host program or user action.
- Trojan (Trojan horse)
- Malware that hides harmful behavior inside a program that appears legitimate, so the user installs it willingly.
- Ransomware
- Malware that encrypts a victim's files to make them unusable and demands payment in exchange for the decryption key.
- Spyware
- Malware secretly installed to gather information about a person or organization without their knowledge.
- Rootkit
- A set of tools an attacker uses to conceal their presence on a compromised system and keep covert, high-level access.
- Botnet
- A network of infected computers an attacker controls remotely, often built with Trojans, to carry out large-scale tasks.
- Antivirus software
- A program that scans files and memory for patterns of known malicious code to detect and remove infections.
- Firewall
- A barrier that filters network traffic and can block some malicious connections before they reach a device.
Sources & references
- Protecting Against Malicious Code — Cybersecurity and Infrastructure Security Agency (CISA)
- Stop Ransomware — Cybersecurity and Infrastructure Security Agency (CISA)
- Malware: How To Protect Against, Detect, and Remove It — U.S. Federal Trade Commission (Consumer Advice)
- Worm - Glossary — NIST Computer Security Resource Center (CSRC)
- Spyware - Glossary — NIST Computer Security Resource Center (CSRC)
- Rootkit - Glossary — NIST Computer Security Resource Center (CSRC)
- Botnet - Glossary — NIST Computer Security Resource Center (CSRC)
- Recognize and Report Phishing — CISA (Cybersecurity and Infrastructure Security Agency)
EliExplains lessons are original prose written from the open, credible references above. See Copyright & Licensing.
Researched 2026-08-19
Educational content only. It is not medical, legal or professional advice. Found an error? Tell us.

