Malware types explained: what each one is and how it arrives
"Malware" covers a wide family of software, and the members differ in ways that matter: how they reach a device, what they do once there, and which defences actually help. This page takes each type in turn, then compares them in one table.
Quick answer. Malware is any software written to act against the person using the device. The main types are viruses, worms, trojans, ransomware, spyware, adware and rootkits. Most of them need you to open, install or approve something before they can do harm, which is why habits and updates matter as much as the security software you choose.
Viruses
A virus attaches its code to another file or program and copies itself whenever that host is run. The original sense of the word is precise: self-copying code that needs a host. In everyday use, and in the name "antivirus", it has come to mean any malicious software, which can make product descriptions harder to follow than they need to be.
Classic file-copying viruses are a smaller share of what security products deal with than they once were, partly because modern operating systems make it harder for one program to modify another. The term survives mainly as a convenient shorthand.
Worms
A worm spreads on its own across a network. It does not need anyone to open an attachment; it finds other devices with the same unpatched flaw and copies itself to them. Worms can travel very quickly through organisations with many identical machines, and through home networks where devices go months without updates.
The most effective defence against worms is installing operating system and router updates promptly, because a worm relies on a weakness that has usually already been fixed by the time it spreads widely. Security software adds a second layer by recognising the worm's files or its network behaviour.
Trojans
A trojan is named after the wooden horse: it looks like something you want, and carries something you do not. Typical disguises include free versions of paid software, game cheats, invoices, delivery notices and "codec" downloads that a video site claims you need. The trojan does not spread by itself. It depends on someone choosing to run it.
Once running, a trojan can do almost anything the user account it runs under is allowed to do. Many trojans exist mainly to download other malware, open a backdoor for remote control, or steal saved passwords.
Worked example. A web page offers a free "unlocked" copy of a paid photo editor. The download is a working installer, and it also installs a small additional program that runs at start-up and sends saved browser passwords to a remote server. The photo editor works, so nothing appears wrong. This is the commonest trojan pattern, and it is why official guidance advises installing software only from the maker's site or an official app store.
Ransomware
Ransomware encrypts files, or locks a whole device, and then shows a demand for payment, often in cryptocurrency, in exchange for a key. Some variants also copy data out first and threaten to publish it. Paying does not reliably bring files back, and it funds further attacks.
The defence that works regardless of how the ransomware arrived is a backup that the ransomware cannot reach: an external drive disconnected after each backup, or a cloud service that keeps earlier versions of files. Security software may stop many ransomware attempts, particularly through behaviour monitoring, but backups are what make recovery possible when it does not.
Ransomware incidents can be reported to the National Cyber Security Centre through its reporting page, and the Own Your Online guides cover backups for households in practical terms.
Spyware and stalkerware
Spyware collects information without the user's knowledge — what you type, which sites you visit, your messages, your location — and sends it elsewhere. Keyloggers, which record keystrokes, are one form.
A related category, sometimes called stalkerware, is monitoring software installed on someone's phone by a person who knows them, such as a current or former partner. It is often sold openly as a parental or "employee" monitoring tool. If you suspect it, be careful: removing it may alert the person who installed it. Netsafe provides support for people experiencing online harm, and that support is a safer first step than deleting things on your own.
Adware and potentially unwanted programs
Adware exists to show advertisements: extra pop-ups, injected banners, a search engine you did not choose. It often arrives bundled with free software, with consent technically obtained through a pre-ticked box in an installer. Security vendors usually classify it with other potentially unwanted programs, a group that also includes "registry cleaners", fake speed-up tools and browser hijackers.
Because these programs sit in a legal grey area, products tend to treat them more cautiously than malware, sometimes only detecting them if you enable the option. If your browser's home page or search engine has changed without your doing, this category is the likeliest explanation.
Rootkits
A rootkit is designed to conceal itself, and usually other malware, by modifying parts of the operating system so that the files and processes involved become invisible to normal tools. Rootkits are less common on consumer devices than they were, because modern operating systems check that their core components have not been tampered with when they start up. Where one is present, a reinstall of the operating system is often the most reliable remedy.
Malware on phones and tablets
Phones and tablets face the same broad categories, but the route in is different. On Android, the common route is an app installed from outside the Google Play Store, or a harmful app that slipped past review. Google describes how Google Play Protect checks apps. On iPhone and iPad, apps run in tightly restricted sandboxes and come from Apple's App Store, as Apple explains in its Platform Security guide. This changes what a security app on iOS is able to do, so products for iPhone tend to focus on web filtering, scam message detection and account monitoring rather than scanning files.
On both platforms, the most effective steps are the same: install apps only from the official store, read the permissions an app asks for, and keep the system updated.
The types compared
| Type | Main aim | Usual way in | Spreads by itself? | Defence that matters most |
|---|---|---|---|---|
| Virus | Copy itself into other files | Running a carrier file | Within a device, when the host runs | Security software; caution with files |
| Worm | Spread across networks | Unpatched flaw | Yes | Prompt updates |
| Trojan | Open a door for other harm | Disguised download | No | Install only from official sources |
| Ransomware | Extort payment | Trojan, email attachment, exposed remote access | Some variants | Backups out of the attacker's reach |
| Spyware | Collect information | Bundled app, physical access | No | Device lock, app review, support services |
| Adware or PUP | Show adverts, change settings | Bundled installer | No | Custom install options; PUP detection on |
| Rootkit | Hide malware | Delivered by other malware | No | Secure start-up, updates, reinstall |
What antivirus software can and cannot do here
Security software is good at recognising known malicious files, at spotting suspicious behaviour from unknown ones, and at blocking access to websites already identified as harmful. It is a reasonable layer to have, and Windows and macOS both include built-in malware protection, as the built-in protection page explains with links to the makers' own documentation.
It cannot stop you from typing your password into a convincing fake website, approving a payment, or handing control of your computer to a caller who claims to be from your internet provider. In those cases the software is working exactly as designed, because nothing malicious has been installed. Those problems are the subject of the scam terms page.
What to watch out for
- Any web page that claims to have scanned your device. A web page has no means of doing so; this is scareware.
- "Cleaner" or "optimiser" programs offered after a warning you did not ask for. Many are themselves potentially unwanted programs.
- Phone calls offering to fix a problem with your computer that you did not report.