30% off every course until Sunday, October 11. Our biggest update yet, and we'd like you to try it. Applied automatically at checkout.

Choose your certification
Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

3.4.1. Malware Attacks

💡 First Principle: Malware is software designed to cause harm. Each type has distinctive behaviors that serve as indicators. Recognizing these behaviors — not just knowing the definitions — is what the exam tests.

Ransomware encrypts files and demands payment for decryption keys. Indicators: mass file encryption events, ransom notes appearing on desktops, file extensions changed to unfamiliar types, unusually high disk I/O activity, connections to known C2 infrastructure.

Trojan disguises itself as legitimate software. Unlike viruses, Trojans don't self-replicate — they rely on the user to install them. Indicators: unexpected outbound connections, new processes running after installing "legitimate" software, behavioral changes in the system.

Worm self-replicates across networks without user interaction. Indicators: sudden network bandwidth spikes, multiple systems showing identical infections, rapid propagation across subnets.

Spyware covertly monitors user activity and exfiltrates data. Indicators: unexpected data transmissions, browser setting changes, new toolbars or extensions, degraded system performance.

Bloatware — pre-installed software that consumes resources. While not always malicious, it increases attack surface and can contain vulnerabilities.

Virus — malware that attaches to legitimate programs and requires user action to spread. Unlike worms, viruses need a host file.

Keylogger captures keystrokes to steal credentials and sensitive data. Indicators: unexpected processes with keyboard hooks, data exfiltration to unknown destinations.

Logic bomb — malicious code that triggers on a specific condition (date, event, user action). Difficult to detect before activation because the code lies dormant.

Rootkit — hides deep in the OS (kernel-level) to maintain persistent access while evading detection. Indicators: discrepancies between low-level disk analysis and OS-reported files, unexplained system behavior that antivirus can't identify.

Bot (botnet client) — malware that enrolls a host in a botnet controlled through a command-and-control (C2) server and used for DDoS, spam, or credential-stuffing campaigns. The network tell is beaconing: small, periodic outbound connections with no user action, often from several internal hosts to the same external address (section 5.4.1 covers spotting beaconing in monitoring data).

Fileless / living-off-the-land attacks abuse legitimate, signed system tools such as PowerShell or WMI, so no malware file is dropped for antivirus to find. Detection relies on process lineage (an unexpected parent, such as a document application launching a shell) and command-line flags that conceal intent (-w hidden, -enc), not on file names or paths.

Recognizing intrusion stages in a timeline — logs often show an attack in order. Delivery: the payload arrives (phishing attachment, malicious link, removable media). Execution: attacker code first runs, often through a trusted tool, as in the living-off-the-land pattern above. Persistence: the foothold is made to survive reboot or logoff (scheduled tasks, Run keys, new services or accounts), so killing the process without removing the persistence mechanism leaves the attacker in. Command and control: the implant calls home to the attacker, typically as the beaconing described above. Later stages include lateral movement and exfiltration. Naming the stage tells the responder what to look for next and what to eradicate. Stage names vary by model: the Cyber Kill Chain (section 3.2.2) folds execution and persistence into its exploitation and installation stages.

⚠️ Exam Trap: Worms self-replicate without user interaction. Viruses require a host file and user action. Trojans disguise as legitimate software. If the scenario says "spread across the network without any user clicking anything," that's a worm — not a virus or Trojan.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications