Malicious Software (Malware) — IT Glossary | ITU Online IT Training
+1 855.488.5327 customerservice@ituonline.com Mon – Fri: 9:00am – 5:00pm ET

Malicious Software (Malware)

Commonly used in Security, Cybersecurity

Ready to start learning?Individual Plans →Team Plans →

Malicious software, commonly known as malware, refers to software that is intentionally created to harm, exploit, or otherwise compromise computer systems, networks, or data. It is designed with malicious intent to disrupt normal operations, steal information, or gain unauthorized access.

How It Works

Malware can take many forms, including viruses, worms, Trojans, ransomware, spyware, adware, and rootkits. These malicious programs often infiltrate systems through email attachments, malicious links, infected software downloads, or compromised websites. Once inside a system, malware can replicate itself, modify or delete files, spy on user activity, or encrypt data for ransom. Many types of malware also use techniques to evade detection, such as disguising their code or disabling security tools.

Typically, malware exploits vulnerabilities within operating systems, applications, or network protocols to gain entry. Once installed, it may establish persistence, allowing it to remain active even after reboots or attempts to remove it. Advanced malware may communicate with command and control servers to receive instructions or exfiltrate stolen data.

Common Use Cases

  • Ransomware encrypts a victim’s data and demands payment for the decryption key.
  • Spyware secretly monitors user activity and transmits sensitive information to attackers.
  • Trojans disguise as legitimate software to gain unauthorized access to systems.
  • Viruses attach themselves to files or programs and spread when these are shared or executed.
  • Worms propagate across networks, infecting multiple devices without user intervention.

Why It Matters

Malware poses significant risks to individuals, businesses, and governments by causing data breaches, financial loss, and operational disruptions. For IT professionals and security practitioners, understanding malware is fundamental to developing effective defence strategies, including detection, prevention, and response measures. Certification candidates often encounter malware-related topics in cybersecurity exams, as defending against malicious software is a core component of cybersecurity expertise. Staying informed about malware types, delivery methods, and mitigation techniques is essential to maintaining secure and resilient IT environments.

Ready to start learning?Individual Plans →Team Plans →
Discover More, Learn More
Understanding the Security Operations Center: A Deep Dive Discover how a Security Operations Center enhances your cybersecurity defenses, improves incident… What Is a Security Operations Center (SOC)? Discover what a security operations center is and how it enhances organizational… Step-by-Step Guide to Implementing a Security Operations Center in Your Organization Discover how to effectively implement a security operations center in your organization… Building a Security Operations Center: A Complete SOC Setup Blueprint Discover how to build a comprehensive Security Operations Center to enhance cybersecurity… Understanding SOC Functions: The Complete Guide to Security Operations Center Operations Discover how SOC functions support security monitoring, threat detection, and incident response… Counterintelligence and Operational Security in Cybersecurity: A Guide for CompTIA SecurityX Certification Discover essential strategies to enhance your cybersecurity skills by understanding counterintelligence and…