Module 05 / 15
πŸ›

Understanding Malware to Better Avoid ItUpdated: 2026

Learn to recognize signs of infection, reduce risk, and respond correctly β€” including to ransomware.

⏱️ ~25 min
πŸ“š 8 lessons
🎯 Beginner
🎯 Module objective

By the end of this module, you'll be able to…

  • Distinguish the main types of malware and their effects
  • Recognize the signs that a device may be infected
  • Understand how ransomware deploys and spreads
  • Apply essential day-to-day prevention measures
  • Respond correctly if you suspect an infection
1

What is malware?

Malware (short for "malicious software") is any software designed to cause harm: stealing data, disrupting a system, spying on the user, or extorting money.

Contrary to the popular image of a hacker furiously typing at a keyboard, most malware infections today arrive through mundane actions: opening an attachment, clicking a link, downloading software from an unofficial site.

Key takeaway"Malware doesn't exploit your computers β€” it exploits your behaviors."
2

Main types of malware

TypeWhat it doesCommon vector
🦠 VirusReplicates by attaching itself to other filesAttachments, USB drives
🐴 Trojan horseDisguises itself as legitimate software to get installedShady downloads, fake software
πŸ•΅οΈ SpywareSpies on activity and steals informationMobile apps, free software
πŸ’° RansomwareEncrypts your files and demands a ransomPhishing, software vulnerabilities
⌨️ KeyloggerRecords every keystroke typedPhysical access, Trojan horse
πŸ“’ AdwareDisplays unwanted adsFree software, extensions
πŸͺ± WormSpreads automatically across the networkNetwork vulnerabilities, emails
3

How malware infects your devices

βœ— Most common infection vectors

  • Email attachments: Word/Excel files with malicious macros, booby-trapped PDFs, ZIP files
  • Malicious links: phishing that leads to a site downloading malware
  • Unofficial downloads: pirated software, "cracks", fake updates
  • Abandoned USB drives: a found USB drive can be a deliberate trap
  • Malicious ads (malvertising): even on legitimate sites
  • Unpatched software vulnerabilities: systems that aren't updated
4

Understanding ransomware β€” timeline of an attack

Scenario

Monday morning. Caroline opens an email from her "accountant" with an invoice attached. She clicks the Word document, enables macros when prompted. Nothing seems to happen... In the background, the malware connects to a remote server and starts silently encrypting every file on the network. Wednesday morning: every computer displays a red screen demanding $50,000 in Bitcoin.

1

Intrusion

Booby-trapped email, vulnerability, poorly secured remote access (RDP).

2

Silent reconnaissance

The malware maps the network, identifies important files and backups.

3

Encryption

Files are encrypted, often within minutes. Connected backups included.

4

Ransom demand

Ransom screen, deadline, threat to publish stolen data.

5

Signs of a compromised device

βœ— Warning signs not to ignore

  • The computer is unusually slow for no apparent reason
  • The fan runs constantly even when few programs are open
  • Files have disappeared or their icons have changed
  • Programs open or close on their own
  • Your browser shows unusual ads or redirects you to unknown sites
  • Your contacts receive strange messages from you that you never sent
  • Your files have an unknown extension added (e.g., document.docx.locked)
6

Preventing infections day to day

βœ“ The 7 prevention habits

  • Update: OS, browser, apps β€” turn on automatic updates
  • Don't click suspicious attachments: check the sender before opening
  • Download from official sources: the manufacturer's site, App Store, Play Store
  • Don't plug in found USB drives: or unknown ones
  • Use up-to-date antivirus: Windows Defender is enough for most uses
  • Back up regularly: the 3-2-1 rule (see lesson 8)
  • Limit privileges: don't use an administrator account day to day
7

What to do if you suspect an infection

βœ“ Emergency procedure

  • Don't panic β€” a hasty reaction can make things worse
  • Disconnect from the network immediately (Wi-Fi and cable) to limit the spread
  • Don't reboot if you suspect ransomware β€” it can worsen the encryption
  • Photograph the screen to document the incident
  • Contact your IT support or a professional
  • Don't pay the ransom β€” it doesn't guarantee you'll get your data back and it funds criminals
⚠️
Don't pay the ransom.

30% of businesses that pay never get their data back. 80% are attacked again within the year. The only real solution: isolated backups, tested regularly.

8

The 3-2-1 backup rule

The 3-2-1 rule is the global standard for a backup strategy robust against ransomware.

3
copies of your data
(the original + 2 copies)
2
different types of media
(hard drive + cloud)
1
offsite copy
(cloud or remote physical location)
ℹ️
Important:

The offsite copy must be disconnected from the main network β€” a permanently connected backup will be encrypted by the ransomware along with your files.

Key takeaway"An untested backup isn't a backup. Test the restore at least once a year."
Interactive demo

Ransomware crisis simulator

Simulated example for educational purposes β€” the brands mentioned are not affiliated with ObjectifCyber.

Your computer is infected with ransomware. This screen is a simulation β€” no link is active. Choose your response:

⚠️ YOUR FILES HAVE BEEN ENCRYPTED ⚠️
All your documents, photos and databases have been encrypted with a military-grade algorithm.
You have 72 hours to pay or your files will be permanently destroyed.
Ransom demanded: 0.5 BTC (~$35,000)
[SIMULATION β€” This screen is educational, no link is functional]

Module quiz

Test what you've learned with 4 questions.

See also