Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

A pop-up nobody expected, a browser that suddenly opens odd pages, a laptop fan that never rests. Sometimes it's nothing, and sometimes something unwanted is running on the machine. Here's what malware is, the main types you'll meet at work, how it gets in, and what staff and IT should do the moment they suspect it.

What Is Malware?

Malware is software built to do something harmful on a device without the owner's consent. The word is short for "malicious software." NIST's security glossary defines it as hardware, firmware or software "intentionally included or inserted in a system for a harmful purpose."

The harm varies. Some malware steals passwords and browser sessions. Some encrypts files and demands payment. Some quietly gives an attacker remote control and waits.

People often say "virus" for all of it. A virus is one type of malware, the kind that copies itself into other files. Every virus is malware, but a stolen-password tool or a remote access trojan isn't a virus. The difference matters when you read an alert, because the name of the family tells you what the attacker was after.

Types of Malware

Security tools name detections by family. This table covers the types you're most likely to see in an alert or a ticket.

TypeWhat it doesHow it usually spreads
VirusCopies itself into other files or programsInfected files, macros
WormSpreads across a network on its own, no click neededUnpatched services, weak network shares
TrojanPoses as something useful, then runs a hidden payloadFake installers, cracked software, attachments
RansomwareEncrypts files and demands payment, often after stealing dataStolen credentials, remote access, loaders
InfostealerGrabs saved passwords, cookies and crypto wallets, then uploads themFake updates, ClickFix pages, malvertising
SpywareWatches activity: keystrokes, screenshots, browsingBundled apps, malicious extensions
AdwareFloods the browser with ads or redirectsFree software bundles, extensions
RootkitHides deep in the system so other malware stays invisibleInstalled by another piece of malware
LoaderGets a foothold, then downloads the real payloadPhishing attachments, fake installers

The types overlap. A single infection often chains three of them: a loader lands first, an infostealer takes the passwords, and ransomware follows weeks later. Our walkthrough of a ransomware attack shows that chain hour by hour.

Professor Messer's Security+ overview covers the same families in six minutes, if you'd rather watch than read.

How Malware Gets In

Malware needs a way onto the device. Today that route usually runs through a person, a browser or an unpatched system.

Phishing and attachments. An email carries a link or a file that starts the infection. The file might be a document with macros, a zipped script or a shortcut disguised as a PDF.

Fake fixes and fake CAPTCHAs. ClickFix pages show a fake error or "verify you're human" box, then tell the user to paste a command into the Run box or PowerShell. Microsoft reported in August 2025 that these campaigns target thousands of enterprise and consumer devices every day, and that the Lumma infostealer was the most common final payload.

Malvertising and fake installers. A search ad for a popular tool leads to a look-alike download page. The installer works, and it also installs something else.

Cracked software and browser extensions. Free versions of paid tools and unvetted extensions are a steady source of infostealers and adware.

Unpatched systems. Worms and ransomware crews go after internet-facing services with known flaws. An exploit needs no click at all when the vulnerable service is already exposed.

This r/sysadmin thread is a good read on what IT teams do about ClickFix in practice, from blocking the Run box to user training.

Signs of Malware on a Work PC

Some malware is loud. The loud kind is the easy kind. Infostealers are built to be quiet, so a clean-looking PC proves little.

Watch for these:

  • Browser changes. A new homepage, search engine or extension nobody installed.
  • Pop-ups and redirects. Ads on sites that never had them, or links landing on the wrong page.
  • Performance drops. Fans running hot and CPU pinned at idle, a common sign of a cryptominer.
  • Account alerts. Sign-in warnings from Microsoft 365 or Google, MFA prompts nobody requested, or password resets nobody started.
  • Security tool alerts. A detection, even one marked "quarantined," or protection that switched itself off.
  • Files you can't open. Renamed files with a strange extension and a ransom note. That's ransomware, and it's an emergency.

A single sign rarely proves infection. Account alerts plus a recent download from an odd site, though, is worth a call to IT that same hour.

What Staff Should Do Right Away

If you think your work computer has malware, speed matters more than certainty. Tell IT and let them decide.

Disconnect from the network: turn off Wi-Fi or unplug the cable. Don't shut the machine down unless IT asks, because memory and running processes help the investigation. Don't sign in to anything else from that device, and don't try to clean it yourself with a tool from the internet.

Then write down what happened: the site, the email, the file, the time. That detail saves IT an hour.

What IT Does After a Detection

A quarantine message closes the alert, but not always the incident. The question is what the malware did before the security tool caught it. For an infostealer, the answer is often "everything it came for," because it uploads what it finds within minutes.

This r/antivirus thread shows the usual reaction to a quarantine, and why the replies push for more than trusting the green checkmark.

A workable response runs in six steps:

  1. Isolate. Cut the device off the network, ideally through the security tool so it stays reachable for investigation.
  2. Identify. Read the detection name and family. An adware hit and an infostealer hit need very different follow-up.
  3. Scope. Check whether the same file, hash or domain shows up on other devices, and what the user's accounts did since the infection.
  4. Remove. For anything beyond adware, reimage the machine. Cleaning in place leaves doubt about what else was dropped.
  5. Reset. Change passwords from a clean device and revoke sessions and tokens. Stolen cookies bypass MFA until the sessions are revoked.
  6. Restore and learn. Bring data back from backup, then close the gap that let it in: a blocked extension, a patched service or a new rule for the Run box.

The scale explains step 5. Microsoft identified over 394,000 Windows computers infected with Lumma between 16 March and 16 May 2025, harvesting passwords, bank details and crypto wallets.

Stolen logins are how a quiet infection turns into a loud one. Verizon's 2025 Data Breach Investigations Report found ransomware in 44% of the breaches it studied.

Scoping is where fleet visibility pays off. In OpenFrame, you can run a check for a file or process as a script across a client's devices and collect the output in one place. Layers like EDR and MDR, which do the detecting, are covered in our guide to endpoint security.

Malware, in Short

Malware is any software built to do harm: steal data, lock files, spy, or open a door for something worse. It usually gets in through a person, a browser or a missing patch, and the quiet kinds do the most damage. When you suspect it, disconnect and tell IT. When IT confirms it, treat the quarantine as step one, reset what could have been stolen, and fix the way in.

Next, see how one infection grows into a full ransomware attack, or how attackers turn a known flaw into an exploit.

Kristina Shkriabina

Content Marketing Lead

Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

What Is Malware

Malware is software built to do something harmful on a device without the owner's consent. The word is short for malicious software. It can steal passwords and browser sessions, encrypt files for ransom, spy on activity, or give an attacker remote control of the machine.
A virus is one type of malware: the kind that copies itself into other files or programs. Malware is the umbrella term that also covers worms, trojans, ransomware, infostealers, spyware, adware, rootkits and loaders. Every virus is malware, but an infostealer or a remote access trojan is not a virus.
Common signs are a changed browser homepage or new extensions, unexpected pop-ups and redirects, the CPU pinned while the PC is idle, sign-in alerts or MFA prompts nobody requested, a security tool that switched itself off, and renamed files with a ransom note. Infostealers are built to be quiet, so a PC with no symptoms is not proof it is clean.
Disconnect from the network by turning off Wi-Fi or unplugging the cable, and tell IT right away. Do not shut the computer down unless IT asks, do not sign in to other accounts from it, and do not run cleanup tools from the internet. Write down what happened, including the site, email or file and the time.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.