What Is Malware?

Also called: Malicious software

Related problems: Laptops infected after someone opened an attachment; Not sure our antivirus is enough anymore; Passwords and browser sessions stolen from employee devices; Need to choose between endpoint protection products

Malware, short for malicious software, is any program or code written to harm a computer, network or its data, or to give an attacker access they should not have. The term covers viruses, worms, trojans, ransomware, spyware, information stealers and remote access tools. For businesses, malware is less a single threat than the toolkit attackers use at nearly every stage of an intrusion.

At a glance

  • Malware is an umbrella term; ransomware, spyware and trojans are all types of it.
  • It arrives through phishing, malicious downloads, unpatched software and compromised vendor tools, among other routes.
  • Much modern malware avoids detection by changing constantly or by using built-in system tools.
  • Defense on devices usually combines prevention software with behavioral detection and response.

What problem it solves

Malware is a threat rather than a product, so the buyer’s question is what it puts at risk. On a single laptop it can steal saved passwords and browser sessions, log keystrokes or give an attacker remote control. On a server it can disrupt applications or serve as a launching point into the rest of the network. At its worst, as with ransomware, it can encrypt data across a whole company and halt operations.

The practical problem for mid-sized companies is that the older answer, signature-based antivirus, was built for a time when malicious files changed slowly. Today new variants appear constantly, and some attacks use no malicious file at all, relying instead on legitimate administration tools. That gap is what newer endpoint security categories were built to close.

How it works

Delivery. Malware reaches a device through a phishing attachment or link, a fake software download, a malicious browser extension, an infected USB drive, a vulnerable internet-facing service or a tampered software update.

Execution and persistence. Once it runs, malware typically tries to survive reboots, hide from security tools and gain higher privileges. Some families are small loaders whose only job is to download the next piece.

Action. Depending on its purpose, it steals credentials or files, opens a remote connection for the attacker, spreads to other machines, mines cryptocurrency, or encrypts data for ransom.

Defenses. An endpoint protection platform (EPP) tries to block malware before or as it runs, using signatures, machine learning and behavior rules. Endpoint detection and response (EDR) records activity on the device so that suspicious behavior can be investigated and the device isolated if needed, and managed detection and response (MDR) adds people who watch those alerts around the clock. Patching, limiting administrator rights, email filtering and application controls reduce how often malware gets a chance to run at all.

When it matters for buyers

  • When replacing legacy antivirus. Many companies are moving to an endpoint platform with behavioral detection and response.
  • When infections keep recurring. Repeat incidents usually point to gaps in patching, admin rights or detection rather than bad luck.
  • When cyber insurance renews. Insurers often ask specifically about EDR and who monitors it.
  • When staff use personal or unmanaged devices. Devices outside your management tools are harder to protect and to clean up.
  • When servers and cloud workloads lack coverage. Endpoint agents and policies should cover servers, not only laptops.

Our endpoint protection platforms overview compares the main approaches.

Questions to ask vendors

  • How do you detect malware that has never been seen before, and how do you limit false positives?
  • Which operating systems and device types do you support, including servers and Macs?
  • What happens automatically when malware is detected: block, quarantine, isolate the device?
  • Does your product record enough activity to investigate what the malware did?
  • Who reviews alerts outside business hours, and is that included or extra?
  • How do you handle devices that are offline or off the corporate network?
  • What does the agent cost per device, and what features sit in higher tiers?

How it differs from a computer virus

People often use “virus” to mean any malicious program, but a virus is one specific type of malware: code that attaches itself to legitimate files or programs and spreads when they run. Malware is the umbrella term that also includes worms, trojans, ransomware, spyware and more. The difference matters when reading product claims: a tool marketed only as “antivirus” may focus on known malicious files, while many current attacks rely on stolen credentials and legitimate tools that a file scanner will not flag.

Frequently Asked Questions

Is antivirus enough to stop malware?
Traditional signature-based antivirus catches known malware but struggles with new variants and with attacks that use legitimate system tools. Many businesses now use an endpoint protection platform with behavioral detection, often paired with endpoint detection and response so suspicious activity can be investigated and contained.
What are the main types of malware?
Common types include viruses and worms that spread, trojans disguised as legitimate software, ransomware that denies access, usually by encrypting data, and may also steal it for double extortion, spyware and information stealers that capture passwords and sessions, and remote access tools that give attackers control. Many real attacks combine several.
How does malware get onto business devices?
Typical routes are phishing attachments and links, malicious downloads and browser extensions, unpatched software, infected USB drives and compromised software updates or vendor tools. Attackers who already have stolen credentials may also install malware directly.
Can Macs and phones get malware?
Yes. Windows remains the most targeted platform, but malware exists for macOS, Linux, Android and, less commonly, iOS. Protection and management tools should cover every platform your staff use for work.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.