GlossarySOC and monitoring

Malware

Short answer

Malware (malicious software) is any program designed to damage systems, steal data or give an attacker control of a device without the owner's consent. It includes viruses, worms, trojans, spyware, infostealers and ransomware.

Common types

Viruses attach to legitimate files and spread when they are opened. Worms spread on their own across networks. Trojans pose as legitimate software. Spyware and keyloggers watch what users do. Infostealers harvest saved passwords, session cookies and browser data, and are now one of the main sources of stolen credentials. Remote access trojans give attackers control of the device. Ransomware encrypts data to demand a payment.

How it gets in

The usual routes are email attachments and links, often through phishing, fake software downloads and cracked programs, malicious browser extensions, infected USB drives and the exploitation of unpatched systems. Some modern attacks use no malware file at all, relying on legitimate system tools to avoid detection.

How to defend against it

Signature based antivirus alone is no longer enough. EDR detects suspicious behaviour, not just known files. It works best together with patch management, limits on who can install software, email filtering and awareness training. Because infostealers target saved credentials, MFA limits the damage when passwords are stolen.

Where it shows up in compliance

ISO 27001 requires protection against malware (Annex A 8.7), combining technical measures with user awareness. The ENS and NIS2 include equivalent measures.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, SOC operations, detection engineering and incident handling.

Go to the topic hub