Cybersecurity Academy

Lesson 4 of 7

Malware

Explore viruses, worms, ransomware, and spyware, and discover how modern defences detect and stop them.

🟡 Intermediate 80 XP

Learn it

Malware is short for 'malicious software'. It is any program or app created by bad actors to harm, spy on, or mess with your computer, phone, or tablet.

There are several types of malware. Viruses attach themselves to safe files, worms spread automatically across networks, spyware secretly watches everything you type, and ransomware locks your files until you pay money.

You can protect your devices by installing trusted antivirus software, keeping your apps updated, and never downloading pirated games or untrusted files from strangers.

Key terms

Malware
An umbrella term for any software intentionally designed to cause damage, gain unauthorised access, or disrupt computer systems.
Ransomware
A category of malware that encrypts a victim files and demands payment to restore access.
Trojan Horse
Malicious software disguised as legitimate, harmless software to deceive users into installing it.
Spyware
Software that covertly monitors and collects user activities, keystrokes, and sensitive data without consent.

How Antivirus Scanners Catch Threats

Walk through the multi-stage scanning process that security tools use to protect your operating system.

  1. 1File Ingestion: When a file is downloaded, the operating system pauses execution and hands the file to the scanner.
  2. 2Signature Matching: The scanner computes the file cryptographic hash and compares it against a database of known malware signatures.
  3. 3Heuristic Evaluation: If the signature is unknown, the engine scans the code structure for suspicious patterns or packing techniques.
  4. 4Sandboxed Emulation: The scanner executes the binary in an isolated virtual sandbox to observe what actions it attempts to perform.
  5. 5Quarantine or Allow: If malicious behaviour is detected, the file is immediately quarantined and blocked from accessing system files.

File Hash Integrity Checker

pythonimport hashlib

def check_file_hash(data_bytes, known_bad_hash):
    file_hash = hashlib.sha256(data_bytes).hexdigest()
    if file_hash == known_bad_hash:
        return 'MALWARE DETECTED: Hash matches known threat signature!'
    return 'File passed initial hash check.'

# Example test
test_data = b'Sample file contents'
bad_hash = 'e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855'
print(check_file_hash(test_data, bad_hash))

Antivirus engines calculate cryptographic hashes (like SHA-256) of downloaded files to instantly identify known malware strains.

Try it

Match each malware type with its core characteristic.

Ransomware
Spyware
Trojan Horse
Worm

Challenge

Explain why having an up-to-date offline backup is the best defence against ransomware attacks.

Pick whichever way suits you — every mode earns the same bonus XP.

Write at least 40 more characters to submit.

Mark your own work

Guided walkthrough — 0/5 clues revealed

  1. Clue 1 locked — reveal it only if you get stuck.
  2. Clue 2 locked — reveal it only if you get stuck.
  3. Clue 3 locked — reveal it only if you get stuck.
  4. Clue 4 locked — reveal it only if you get stuck.
  5. Clue 5 locked — reveal it only if you get stuck.

Each clue costs 4 XP (never below 20 XP). You'd earn 40 XP right now.

Extension: Describe the 3-2-1 backup strategy used by enterprise cybersecurity architects.

Quiz time

Question 1 of 4Score 0

What makes a computer worm different from a computer virus?