Updated: October 2026
A pop-up nobody expected, a browser that suddenly opens odd pages, a laptop fan that never rests. Sometimes it's nothing, and sometimes something unwanted is running on the machine. Here's what malware is, the main types you'll meet at work, how it gets in, and what staff and IT should do the moment they suspect it.
What Is Malware?
Malware is software built to do something harmful on a device without the owner's consent. The word is short for "malicious software." NIST's security glossary defines it as hardware, firmware or software "intentionally included or inserted in a system for a harmful purpose."
The harm varies. Some malware steals passwords and browser sessions. Some encrypts files and demands payment. Some quietly gives an attacker remote control and waits.
People often say "virus" for all of it. A virus is one type of malware, the kind that copies itself into other files. Every virus is malware, but a stolen-password tool or a remote access trojan isn't a virus. The difference matters when you read an alert, because the name of the family tells you what the attacker was after.
Types of Malware
Security tools name detections by family. This table covers the types you're most likely to see in an alert or a ticket.
| Type | What it does | How it usually spreads |
|---|---|---|
| Virus | Copies itself into other files or programs | Infected files, macros |
| Worm | Spreads across a network on its own, no click needed | Unpatched services, weak network shares |
| Trojan | Poses as something useful, then runs a hidden payload | Fake installers, cracked software, attachments |
| Ransomware | Encrypts files and demands payment, often after stealing data | Stolen credentials, remote access, loaders |
| Infostealer | Grabs saved passwords, cookies and crypto wallets, then uploads them | Fake updates, ClickFix pages, malvertising |
| Spyware | Watches activity: keystrokes, screenshots, browsing | Bundled apps, malicious extensions |
| Adware | Floods the browser with ads or redirects | Free software bundles, extensions |
| Rootkit | Hides deep in the system so other malware stays invisible | Installed by another piece of malware |
| Loader | Gets a foothold, then downloads the real payload | Phishing attachments, fake installers |
The types overlap. A single infection often chains three of them: a loader lands first, an infostealer takes the passwords, and ransomware follows weeks later. Our walkthrough of a ransomware attack shows that chain hour by hour.
Professor Messer's Security+ overview covers the same families in six minutes, if you'd rather watch than read.
How Malware Gets In
Malware needs a way onto the device. Today that route usually runs through a person, a browser or an unpatched system.
Phishing and attachments. An email carries a link or a file that starts the infection. The file might be a document with macros, a zipped script or a shortcut disguised as a PDF.
Fake fixes and fake CAPTCHAs. ClickFix pages show a fake error or "verify you're human" box, then tell the user to paste a command into the Run box or PowerShell. Microsoft reported in August 2025 that these campaigns target thousands of enterprise and consumer devices every day, and that the Lumma infostealer was the most common final payload.
Malvertising and fake installers. A search ad for a popular tool leads to a look-alike download page. The installer works, and it also installs something else.
Cracked software and browser extensions. Free versions of paid tools and unvetted extensions are a steady source of infostealers and adware.
Unpatched systems. Worms and ransomware crews go after internet-facing services with known flaws. An exploit needs no click at all when the vulnerable service is already exposed.
This r/sysadmin thread is a good read on what IT teams do about ClickFix in practice, from blocking the Run box to user training.
Signs of Malware on a Work PC
Some malware is loud. The loud kind is the easy kind. Infostealers are built to be quiet, so a clean-looking PC proves little.
Watch for these:
- Browser changes. A new homepage, search engine or extension nobody installed.
- Pop-ups and redirects. Ads on sites that never had them, or links landing on the wrong page.
- Performance drops. Fans running hot and CPU pinned at idle, a common sign of a cryptominer.
- Account alerts. Sign-in warnings from Microsoft 365 or Google, MFA prompts nobody requested, or password resets nobody started.
- Security tool alerts. A detection, even one marked "quarantined," or protection that switched itself off.
- Files you can't open. Renamed files with a strange extension and a ransom note. That's ransomware, and it's an emergency.
A single sign rarely proves infection. Account alerts plus a recent download from an odd site, though, is worth a call to IT that same hour.
What Staff Should Do Right Away
If you think your work computer has malware, speed matters more than certainty. Tell IT and let them decide.
Disconnect from the network: turn off Wi-Fi or unplug the cable. Don't shut the machine down unless IT asks, because memory and running processes help the investigation. Don't sign in to anything else from that device, and don't try to clean it yourself with a tool from the internet.
Then write down what happened: the site, the email, the file, the time. That detail saves IT an hour.
What IT Does After a Detection
A quarantine message closes the alert, but not always the incident. The question is what the malware did before the security tool caught it. For an infostealer, the answer is often "everything it came for," because it uploads what it finds within minutes.
This r/antivirus thread shows the usual reaction to a quarantine, and why the replies push for more than trusting the green checkmark.
A workable response runs in six steps:
- Isolate. Cut the device off the network, ideally through the security tool so it stays reachable for investigation.
- Identify. Read the detection name and family. An adware hit and an infostealer hit need very different follow-up.
- Scope. Check whether the same file, hash or domain shows up on other devices, and what the user's accounts did since the infection.
- Remove. For anything beyond adware, reimage the machine. Cleaning in place leaves doubt about what else was dropped.
- Reset. Change passwords from a clean device and revoke sessions and tokens. Stolen cookies bypass MFA until the sessions are revoked.
- Restore and learn. Bring data back from backup, then close the gap that let it in: a blocked extension, a patched service or a new rule for the Run box.
The scale explains step 5. Microsoft identified over 394,000 Windows computers infected with Lumma between 16 March and 16 May 2025, harvesting passwords, bank details and crypto wallets.
Stolen logins are how a quiet infection turns into a loud one. Verizon's 2025 Data Breach Investigations Report found ransomware in 44% of the breaches it studied.
Scoping is where fleet visibility pays off. In OpenFrame, you can run a check for a file or process as a script across a client's devices and collect the output in one place. Layers like EDR and MDR, which do the detecting, are covered in our guide to endpoint security.
Malware, in Short
Malware is any software built to do harm: steal data, lock files, spy, or open a door for something worse. It usually gets in through a person, a browser or a missing patch, and the quiet kinds do the most damage. When you suspect it, disconnect and tell IT. When IT confirms it, treat the quarantine as step one, reset what could have been stolen, and fix the way in.
Next, see how one infection grows into a full ransomware attack, or how attackers turn a known flaw into an exploit.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
