Understanding Malware to Better Avoid ItUpdated: 2026
Learn to recognize signs of infection, reduce risk, and respond correctly β including to ransomware.
By the end of this module, you'll be able toβ¦
- Distinguish the main types of malware and their effects
- Recognize the signs that a device may be infected
- Understand how ransomware deploys and spreads
- Apply essential day-to-day prevention measures
- Respond correctly if you suspect an infection
What is malware?
Malware (short for "malicious software") is any software designed to cause harm: stealing data, disrupting a system, spying on the user, or extorting money.
Contrary to the popular image of a hacker furiously typing at a keyboard, most malware infections today arrive through mundane actions: opening an attachment, clicking a link, downloading software from an unofficial site.
Main types of malware
| Type | What it does | Common vector |
|---|---|---|
| π¦ Virus | Replicates by attaching itself to other files | Attachments, USB drives |
| π΄ Trojan horse | Disguises itself as legitimate software to get installed | Shady downloads, fake software |
| π΅οΈ Spyware | Spies on activity and steals information | Mobile apps, free software |
| π° Ransomware | Encrypts your files and demands a ransom | Phishing, software vulnerabilities |
| β¨οΈ Keylogger | Records every keystroke typed | Physical access, Trojan horse |
| π’ Adware | Displays unwanted ads | Free software, extensions |
| πͺ± Worm | Spreads automatically across the network | Network vulnerabilities, emails |
How malware infects your devices
β Most common infection vectors
- Email attachments: Word/Excel files with malicious macros, booby-trapped PDFs, ZIP files
- Malicious links: phishing that leads to a site downloading malware
- Unofficial downloads: pirated software, "cracks", fake updates
- Abandoned USB drives: a found USB drive can be a deliberate trap
- Malicious ads (malvertising): even on legitimate sites
- Unpatched software vulnerabilities: systems that aren't updated
Understanding ransomware β timeline of an attack
Monday morning. Caroline opens an email from her "accountant" with an invoice attached. She clicks the Word document, enables macros when prompted. Nothing seems to happen... In the background, the malware connects to a remote server and starts silently encrypting every file on the network. Wednesday morning: every computer displays a red screen demanding $50,000 in Bitcoin.
Intrusion
Booby-trapped email, vulnerability, poorly secured remote access (RDP).
Silent reconnaissance
The malware maps the network, identifies important files and backups.
Encryption
Files are encrypted, often within minutes. Connected backups included.
Ransom demand
Ransom screen, deadline, threat to publish stolen data.
Signs of a compromised device
β Warning signs not to ignore
- The computer is unusually slow for no apparent reason
- The fan runs constantly even when few programs are open
- Files have disappeared or their icons have changed
- Programs open or close on their own
- Your browser shows unusual ads or redirects you to unknown sites
- Your contacts receive strange messages from you that you never sent
- Your files have an unknown extension added (e.g., document.docx.locked)
Preventing infections day to day
β The 7 prevention habits
- Update: OS, browser, apps β turn on automatic updates
- Don't click suspicious attachments: check the sender before opening
- Download from official sources: the manufacturer's site, App Store, Play Store
- Don't plug in found USB drives: or unknown ones
- Use up-to-date antivirus: Windows Defender is enough for most uses
- Back up regularly: the 3-2-1 rule (see lesson 8)
- Limit privileges: don't use an administrator account day to day
What to do if you suspect an infection
β Emergency procedure
- Don't panic β a hasty reaction can make things worse
- Disconnect from the network immediately (Wi-Fi and cable) to limit the spread
- Don't reboot if you suspect ransomware β it can worsen the encryption
- Photograph the screen to document the incident
- Contact your IT support or a professional
- Don't pay the ransom β it doesn't guarantee you'll get your data back and it funds criminals
30% of businesses that pay never get their data back. 80% are attacked again within the year. The only real solution: isolated backups, tested regularly.
The 3-2-1 backup rule
The 3-2-1 rule is the global standard for a backup strategy robust against ransomware.
The offsite copy must be disconnected from the main network β a permanently connected backup will be encrypted by the ransomware along with your files.
Ransomware crisis simulator
Simulated example for educational purposes β the brands mentioned are not affiliated with ObjectifCyber.
Your computer is infected with ransomware. This screen is a simulation β no link is active. Choose your response:
You have 72 hours to pay or your files will be permanently destroyed.
Module quiz
Test what you've learned with 4 questions.
See also