Cybersecurity · Foundations

Malware

Want it in plain words first? Jump to Eli explains — the same idea, no jargon.
On this page 9 sections
  1. In 30 seconds
  2. Why this matters
  3. The college version
  4. Eli explains
  5. Worked example
  6. Key takeaway
  7. Quick check
  8. Study tools
  9. Sources & references

In 30 seconds

— short for malicious software — is software designed to harm, exploit, or take control of a device. NIST defines it as software or firmware intended to perform an unauthorized process that harms a system's confidentiality, integrity, or availability. The main families are viruses, worms, trojans, , , and , and malware arrives through infected attachments, malicious downloads, compromised websites, poisoned ads, and removable media. Good defenses — keeping software updated, treating unexpected attachments with suspicion, and running security software — reduce risk but never eliminate it.

Why this matters

Malware is the most common external threat most computers face, and nearly every security control exists to block one of its moves. Understanding what malware is lets you recognize the family behind a strange pop-up, the route it took to reach a machine, and which habit would have stopped it. Because infections can be quiet and costly — stolen logins, locked files, hijacked machines — the practical payoff is real: the same few habits that reduce malware risk protect schoolwork, accounts, and money. And knowing that no defense is perfect keeps you alert instead of complacent.

The college version

What malware is

Malware — short for malicious software — is software designed to harm, exploit, or take control of a device. NIST, the U.S. standards agency, defines malware as software or firmware intended to perform an unauthorized process that will have an adverse impact on the confidentiality, integrity, or availability of an information system. Its malware-incident guide puts it more concretely: malware is a program covertly inserted into another program with the intent to destroy data, run destructive or intrusive programs, or otherwise compromise the confidentiality, integrity, or availability of the victim's data, applications, or operating system, and it is the most common external threat to most hosts. Microsoft's security team describes the same idea in plainer terms: malicious software that attackers design to harm computer systems, whether by damaging the machine, granting remote access, or collecting and transmitting sensitive information to third parties. All three agree on the core point: malware does not misbehave by accident. That is what separates it from a vulnerability, which is a weakness, and from a threat actor, which is the person or group behind the attack.

The main families

Malware is a family name, and the families differ in how they behave. Viruses attach themselves to other programs or files and replicate by inserting a copy of their code into them; one invented example is ClipForge, a free video converter that hid copies of itself inside the installer of every other program the user later ran. Worms spread on their own across networks, without requiring anyone to open a file; BlinkLoop, for instance, copied itself to every shared folder it could reach after being run once. Trojans disguise themselves as something desirable and typically give an attacker remote access; Aurora Drift, a screensaver that quietly installed a backdoor, is one example. Ransomware locks or encrypts data and demands payment to restore it; CipherLatch encrypted a design studio's project files and demanded payment in cryptocurrency. Spyware watches the user without consent, collecting browsing habits, keystrokes, or logins; KeyPetal, hidden inside a free PDF merger, recorded which sites the user visited and what they typed. Adware floods the screen with unwanted advertisements and often changes browser settings; BrightDeals, a coupon toolbar that filled the screen with ads and replaced the home page, fits the pattern. Ransomware, viruses, and trojans each have a deeper topic of their own; here, one line each is enough to tell the families apart.

How malware gets in

The routes malware takes are familiar, and none of them require exotic techniques. Infected attachments arrive in email, sometimes from a known sender whose account was compromised. Malicious downloads include fake installers and free tools that carry a hidden payload. Drive-by websites are the route NIST describes as web-based malware: visiting an infected website is enough to let it exploit a vulnerability in the browser, with no download and often no visible click. Poisoned ads — advertisements on otherwise legitimate sites that have been compromised — can deliver the same kind of harm. Removable media, such as a USB drive carried between computers, can carry malware from one machine to the next. Notice the pattern: nearly every route depends on something ordinary — an email, a download, a website visit, a borrowed drive. That is why phishing is a close cousin of this topic: many deliveries start with a trick message that pushes the victim toward the attachment or download.

Signs of infection

What does an infection look like? Microsoft's guidance lists the common signs: noticeably slower performance, frequent crashes, unexpected pop-ups, and programs appearing that the user did not start. Browser redirects — a search that lands somewhere unexpected — and settings that change on their own, like a new home page, are also typical, especially with adware. Unexpected activity can extend beyond the device: messages about accounts accessed from unfamiliar locations, or social media posts the user never wrote. The honest caveat is that some malware is designed to hide. NIST observes that much modern malware is stealthy, spreading quietly over long periods, and Microsoft notes that some families are built to remain unnoticed for as long as possible. Signs are clues, not proof: they justify running a scan, not a diagnosis.

Defense, and its honest limits

Defense comes down to a few practices that work. Keep software updated: CISA advises installing updates as soon as they are available and turning on automatic updates, because providers ship updates to patch the weak spots malware exploits, and software that is never updated cannot protect anyone; the mechanics of patching at scale belong to the patch-management topic. Treat unexpected attachments with suspicion: NIST's guidance says not to open suspicious attachments, even from known senders, and to confirm with the sender through another channel when an attachment is unexpected. Use security software: NIST calls antivirus software the most commonly used malware-control measure, and Microsoft recommends keeping it updated alongside the operating system. And then the honest part, which the sources state plainly: NIST warns that incidents will still occur — previously unknown threats and human error get through — and that technical controls cannot prevent all incidents, while Microsoft adds that attackers constantly evolve their methods. Defense reduces risk substantially, but it never reduces it to zero. That is not an excuse to skip the basics; it is the reason awareness and response matter alongside them.

Eli, the EliExplains learning guide

Eli explains

The same idea, in plain words

Explain it like I’m 10

Malware is software built to cause trouble: steal, spy, lock your files, or take over your machine. It is a whole family, not one thing — some kinds hitch rides inside other programs, some spread by themselves, and some dress up as something you want. It usually gets in through everyday actions: opening an attachment, downloading a free tool, plugging in a borrowed drive, or visiting a site whose ads have been poisoned. The defense is unglamorous but effective: update your software, think before opening attachments, and run security software. And here is the honest part — those habits make infection much less likely, but nothing makes it impossible.

Picture it like this

Think of malware like a gate-crasher at a house party. The gate-crasher slips in with the crowd — through a door someone left unlocked (an unpatched program), through a friend who brings them along (an infected attachment), or through the catering truck (a poisoned ad). Once inside, they do not announce themselves: they pocket valuables, change the music, or invite more gate-crashers in.

Where the picture stops working

The gate-crasher comparison understates how hard malware is to spot and how far it travels. A gate-crasher is one person at one party; malware can copy itself to other machines, hide from view, and keep working for years. And unlike a gate-crasher, who can simply be shown the door, some malware survives ordinary removal attempts and may require wiping the machine and reinstalling everything.

Worked example

Maya's laptop suddenly slows to a crawl. Pop-up ads appear even when no browser is open, and her home page now points to a search site she never chose. She remembers installing a free document-merging tool the week before, right around the time the ads started. She runs the security software that came with her laptop, which finds adware and a small trojan planted by the installer, and removes both. Next she updates her operating system and browser — several months of updates were waiting — and changes her email password from another device in case anything was captured. The pattern is instructive: the free tool was the door, the unpatched browser was the weakness the drive-by ad exploited, and acting early kept a nuisance from becoming a disaster.

Key takeaway

Malware is software designed to harm, exploit, or take control of a device, and it comes in families — viruses, worms, trojans, ransomware, spyware, and adware. Keeping software updated, treating unexpected attachments with suspicion, and running security software reduce the risk, but defense never makes it zero.

Quick check

3 questions here, of 5 in this lesson’s practice set. Answers stay hidden until you check.

Question 1 of 3foundational

Which sentence best captures what malware is?

Choose an answer, then check it.
Question 2 of 3foundational

Which malware family is characterized by spreading from computer to computer on its own, without requiring a user to open a file or attachment?

Choose an answer, then check it.
Question 3 of 3intermediate

A student installs a free video-editing tool from a download site. The tool opens normally, but in the background it installs a backdoor that lets a stranger control the computer remotely. Which malware family does this behavior match?

Choose an answer, then check it.
Practice all 5

Keep learning

Ready to build on this? Continue to the next lesson.

Practice this lesson
Study tools & related lessonsYou’ll learn to · Common mistakes · Easily confused · Key vocabulary · Related

You’ll learn to

  • Define malware using the NIST working definition: software or firmware intended to perform an unauthorized process that harms a system's confidentiality, integrity, or availability.
  • Name the main malware families — viruses, worms, trojans, ransomware, spyware, and adware — with one distinguishing line for each.
  • Explain, at a conceptual level, the common ways malware gets onto devices: infected attachments, malicious downloads, drive-by websites, poisoned ads, and removable media.
  • Recognize the general signs that a device may be infected, including slowness, pop-ups, changed settings, and unexpected activity.
  • Apply the core defense practices — keeping software updated, avoiding unexpected attachments, and using security software — to everyday situations.
  • Evaluate the honest limits of defense: good practices reduce risk but never reduce it to zero.

Common mistakes

  • Calling every infection "a virus."

    A virus is one family of malware, not the whole category. NIST's glossary lists viruses, worms, and trojan horses as distinct types of malicious code, with spyware and some forms of adware as further examples. The umbrella term is malware.

  • Assuming a clean-looking machine is a clean machine.

    Some malware is built to hide. NIST notes that much modern malware is stealthy by design, and Microsoft warns that certain families can remain unnoticed for long periods. Signs are clues, not proof — their absence does not guarantee safety.

  • Treating software updates as optional once security software is installed.

    Antivirus software catches known threats, but updates close the underlying weaknesses those threats exploit. CISA advises installing updates as soon as they are available and enabling automatic updates; NIST describes patching as a core malware-prevention measure. The two defenses work together.

  • Blaming only "shady" websites and strangers.

    Malware can arrive through poisoned ads on trusted sites and through attachments from known senders whose accounts were compromised. NIST's guidance says not to open suspicious attachments even when they appear to come from someone you know.

Easily confused

A virus vs. A worm

Both replicate, but a virus needs a host file and usually some action such as running that file, while a worm spreads on its own across networks without requiring a user to open anything.

A trojan horse vs. Legitimate software

Both look desirable, but a trojan is built to do something harmful once inside, such as granting remote access; looking legitimate is exactly the disguise.

Spyware vs. Adware

Both usually slip in silently, but spyware's purpose is watching and collecting information without consent, while adware's purpose is pushing unwanted ads — and some adware also changes settings and installs more software.

Key vocabulary

malware
Software or firmware intended to perform an unauthorized process that harms a system's confidentiality, integrity, or availability; the umbrella term for harmful programs.
virus
A program that attaches itself to other programs or files and replicates by inserting a copy of its code into them.
worm
A self-spreading program that copies itself across networks without needing a user to open a file.
trojan horse
Malicious software that disguises itself as something desirable in order to gain access, often giving an attacker remote control of the computer.
ransomware
Malware that locks or encrypts a victim's data and demands payment in order to restore access.
spyware
Software that watches a user's activity or collects personal information without the user's consent.
adware
Software that displays unwanted advertisements, often also changing browser settings and installing more software.
drive-by download
Malware that installs itself when a user merely visits an infected website, exploiting a browser weakness without a deliberate download or click.

Sources & references

  1. NIST Special Publication 800-83 Rev. 1: Guide to Malware Incident Prevention and Handling for Desktops and Laptops — National Institute of Standards and Technology (NIST)
  2. NIST Computer Security Resource Center Glossary — malware — National Institute of Standards and Technology (NIST), Computer Security Resource Center
  3. Microsoft Learn: Explain malware (Explore malware and threat protection module) — Microsoft Learn
  4. Microsoft Security 101: What Is Malware? Definition and Types — Microsoft (Microsoft Security)
  5. Update Software (Secure Our World) — Cybersecurity and Infrastructure Security Agency (CISA)

EliExplains lessons are original prose written from the open, credible references above. See Copyright & Licensing.

Researched 2026-08-21

Educational content only. It is not medical, legal or professional advice. Found an error? Tell us.