{"id":20841,"date":"2020-01-30T13:34:06","date_gmt":"2020-01-30T13:34:06","guid":{"rendered":"https:\/\/www.arimetrics.com\/glosario-digital\/malware"},"modified":"2026-09-28T13:24:33","modified_gmt":"2026-09-28T13:24:33","slug":"malware","status":"publish","type":"encyclopedia","link":"https:\/\/www.arimetrics.com\/en\/digital-glossary\/malware","title":{"rendered":"Malware"},"content":{"rendered":"<p><img decoding=\"async\" class=\"boxpad alignright wp-image-14566 size-full\" src=\"https:\/\/www.arimetrics.com\/wp-content\/uploads\/2020\/01\/malware-1.jpg\" alt=\"Malware\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.arimetrics.com\/wp-content\/uploads\/2020\/01\/malware-1.jpg 300w, https:\/\/www.arimetrics.com\/wp-content\/uploads\/2020\/01\/malware-1-150x150.jpg 150w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><strong>Definition:<\/strong><\/p>\n<p><strong>Malware<\/strong> is software or code created to perform harmful or unauthorized actions on a device, application, network, or data. It can steal information, monitor activity, alter files, encrypt content, disrupt services, or enable remote control of a system.<\/p>\n<p>The term comes from the expression &#8220;malicious software&#8221; and covers threats with different behaviors and objectives. <strong>A virus is a type of malware, not a synonym for all malware.<\/strong> Not every error, pop-up advertisement, or loss of performance proves that an infection is present.<\/p>\n\n<h2>How malware works<\/h2>\n<p>Malware can reach a system through attachments, links, manipulated programs, fake updates, removable devices, or unpatched vulnerabilities. <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/phishing\">Phishing<\/a> is one method that can be used to induce someone to open a file or disclose credentials, but <strong>phishing and malware are not equivalent concepts<\/strong>.<\/p>\n<p>Once executed, the code can perform one or more stages. <strong>Not every threat follows the same sequence<\/strong>, and some act immediately while others try to remain hidden for an extended period.<\/p>\n<ul>\n<li><strong>Execution:<\/strong> The malicious code is activated through a user action, a vulnerability, or a compromised process.<\/li>\n<li><strong>Persistence:<\/strong> It changes the system or uses legitimate mechanisms to run again after a restart.<\/li>\n<li><strong>Privilege escalation and movement:<\/strong> It seeks higher permissions or tries to reach other computers and accounts on the network.<\/li>\n<li><strong>Communication:<\/strong> It contacts command-and-control infrastructure to receive instructions or transfer information.<\/li>\n<li><strong>Action on objectives:<\/strong> It steals, encrypts, modifies, or destroys data, displays advertising, consumes resources, or disrupts operations.<\/li>\n<\/ul>\n<p>Some threats operate mainly in memory and use tools already present on the system. <strong>The absence of a recognizable file does not rule out malicious activity<\/strong>, just as the presence of an unknown file is not enough to classify it as malware.<\/p>\n<h2>Types of malware<\/h2>\n<p>Malware can be classified by its propagation method, technique, or intended effect. <strong>Categories can overlap<\/strong>, because a single campaign may combine several components or change behavior during an attack.<\/p>\n<ul>\n<li><strong>Virus:<\/strong> Inserts itself into a host file or program and replicates when that element is executed or shared.<\/li>\n<li><strong>Worm:<\/strong> Spreads between systems, usually through networks or vulnerabilities, without requiring a host file.<\/li>\n<li><strong>Trojan:<\/strong> Presents itself as legitimate or useful software to encourage installation and then performs a hidden function.<\/li>\n<li><strong>Ransomware:<\/strong> Locks systems or encrypts data and demands payment; some variants also steal information to increase pressure. <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/ransomware\">Ransomware<\/a> is therefore a specific category of malware.<\/li>\n<li><strong>Spyware:<\/strong> Collects activity, credentials, or other data without valid authorization. Keystroke loggers can belong to this category.<\/li>\n<li><strong>Malicious adware:<\/strong> Inserts advertising, changes the browser, or redirects traffic deceptively. Not all advertising-supported software is malware.<\/li>\n<li><strong>Rootkit:<\/strong> Hides processes or components and helps maintain privileged access to a system.<\/li>\n<li><strong>Bot:<\/strong> Turns the device into a remotely controlled node that can join a botnet to send spam, commit fraud, or participate in attacks.<\/li>\n<\/ul>\n<p>These names describe functions rather than completely separate families. <strong>A Trojan can install spyware or ransomware<\/strong>, and a bot can incorporate rootkit techniques to make detection more difficult.<\/p>\n<h2>Effects on devices, data, and services<\/h2>\n<p>The effects depend on the permissions obtained, the systems affected, and how long the threat remains active. <strong>The impact can affect the confidentiality, integrity, and availability of information<\/strong>, as well as the operation of the device.<\/p>\n<ul>\n<li><strong>Loss of confidentiality:<\/strong> Exposure of credentials, documents, communications, or personal data.<\/li>\n<li><strong>Information alteration:<\/strong> Changes to files, settings, transactions, or records.<\/li>\n<li><strong>Service disruption:<\/strong> Encryption, deletion, blocking, or resource consumption that prevents normal operation.<\/li>\n<li><strong>Unauthorized use:<\/strong> Sending messages, committing fraud, mining cryptocurrency, or conducting attacks from the compromised device.<\/li>\n<li><strong>Propagation:<\/strong> Access to other connected accounts, applications, or devices.<\/li>\n<li><strong>Response costs:<\/strong> Investigation, recovery, notifications, business interruption, and control reviews.<\/li>\n<\/ul>\n<p>Slow performance, crashes, and browser changes can be warning signs, but they can also have legitimate causes. <strong>Identification requires combining evidence<\/strong>, such as security alerts, unusual processes, unauthorized changes, abnormal connections, and file or log analysis.<\/p>\n<h2>Impact on websites and digital marketing<\/h2>\n<p>In a digital environment, malware can compromise a website, advertising accounts, measurement tools, or systems that store customer data. <strong>The problem is not limited to one person&#8217;s device<\/strong>, because a stolen credential can enable changes to shared services.<\/p>\n<ul>\n<li><strong>Compromised websites:<\/strong> Injection of spam pages, payment-data skimming code, malicious downloads, or redirects to other domains.<\/li>\n<li><strong>Advertising and analytics:<\/strong> Automated generation of false impressions, clicks, or conversions that distorts data and can create fraudulent spending.<\/li>\n<li><strong>Email:<\/strong> Use of compromised accounts or domains to distribute malicious messages, with possible effects on sender reputation.<\/li>\n<li><strong>Customer data:<\/strong> Access to, extraction of, or changes to personal and commercial information.<\/li>\n<li><strong>Trust and visibility:<\/strong> Browsers, security providers, or search engines may display warnings or restrict access when they detect dangerous content.<\/li>\n<\/ul>\n<p>Advertising fraud, spam, or a ranking decline can also have other causes. <strong>A marketing anomaly occurring at the same time does not by itself prove an infection<\/strong>, so security analysis should be separated from performance diagnosis.<\/p>\n<h2>Prevention, detection, and response<\/h2>\n<p>Protection against malware relies on several layers because no single tool detects every threat. <strong>Risk reduction combines technical controls, processes, and training<\/strong>, with measures adapted to the organization and the assets it needs to protect.<\/p>\n<ul>\n<li><strong>Prevention:<\/strong> Security updates, restrictive configuration, least privilege, multifactor authentication, and control of applications and macros.<\/li>\n<li><strong>Filtering and protection:<\/strong> Email and browsing security, endpoint protection, and a <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/firewall\">firewall<\/a> configured for the network.<\/li>\n<li><strong>Backups:<\/strong> Separate and tested versions that allow data to be recovered without relying on the affected system.<\/li>\n<li><strong>Detection:<\/strong> Logs, alerts, behavioral analysis, and reviews of changes to files, accounts, and connections.<\/li>\n<li><strong>Response:<\/strong> Isolation of affected systems, preservation of evidence, scope analysis, removal or rebuilding, and validated recovery.<\/li>\n<\/ul>\n<p>Response does not end when a detected file is deleted. <strong>It is necessary to determine how the threat entered, which credentials and data it could reach, and whether other access mechanisms remain.<\/strong> Depending on the incident, notifications, credential changes from clean systems, and subsequent monitoring for recurrence may also be required.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malware is malicious software or code. Learn how it works, its main types and effects, its digital impact, and measures for prevention and response.<\/p>\n","protected":false},"author":7,"featured_media":80922,"template":"","encyclopedia-tag":[1265],"class_list":["post-20841","encyclopedia","type-encyclopedia","status-publish","has-post-thumbnail","hentry","encyclopedia-tag-web-threats"],"_links":{"self":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/encyclopedia\/20841","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/encyclopedia"}],"about":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/types\/encyclopedia"}],"author":[{"embeddable":true,"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/users\/7"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/media\/80922"}],"wp:attachment":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/media?parent=20841"}],"wp:term":[{"taxonomy":"encyclopedia-tag","embeddable":true,"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/encyclopedia-tag?post=20841"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}