Atlas record

Malware

Malware is the general name for programs written to get into your device in order to steal data, watch you, hold your files to ransom or use the device in further attacks. Viruses, trojans, ransomware and spyware are all members of this family.

In briefMalware is the general name for programs written to get into a device in order to steal data, watch the user or hold files to ransom.
How it works
  • The malicious code reaches the device looking like a fake attachment, pirated content, an application from outside the store or a fake update.
  • It begins to run when the user opens the file or approves the installation.
  • The software hides itself, makes itself persistent and usually opens a connection to a remote server.
  • Depending on its type it gathers data, records keystrokes, encrypts files or uses the device for further attacks.
  • It passes what it has gathered to the attacker, or reveals itself with a ransom demand.
Warning signs
  • The device slowing down markedly, heating up or the battery draining quickly
  • Adverts, pop-up windows and unrecognised applications appearing by themselves
  • The browser home page or the search engine changing on its own
  • An unexpected rise in data use
  • Antivirus or update services shutting down
  • Files not opening and a ransom note appearing
How to protect yourself
  • Keep the operating system and applications up to date; do not put updates off.
  • Download applications only from official stores and manufacturers' own sites.
  • Verify the sender before opening unexpected email attachments and message links.
  • Back your important files up regularly to somewhere off the device (an external disk or the cloud).
  • Use current security software and run regular scans.
  • Stay away from pirated software and 'cracked' applications.
If it happens to you
  • Cut the device's internet connection; switch the wireless network off.
  • Run a full scan with trustworthy security software and clean up what it finds.
  • Change the passwords of critical accounts from a clean device.
  • If the clean-up fails, consider restoring the device from backups or returning it to factory settings.
  • If you are faced with a ransom demand, approach the official authorities before making any payment; payment is no guarantee that the files come back.

Members of the family

Different behaviours gather under the umbrella term: viruses spread by attaching themselves to other files; trojans come in through the door wearing the appearance of a useful program; ransomware encrypts files and demands money; spyware quietly records keystrokes, the screen and location. From the user's point of view the common denominator is the same: the device is no longer under your control alone.

How does it get in through the door?

The main entrance for modern malware is the user rather than a hole in the system: fake email attachments, pirated software and game files, applications installed from outside the official store, fake 'update' warnings and fake text message links. Operating systems that are not updated also send out an invitation by leaving known holes open.

Backup: the least exciting, most effective measure

The strongest defence against ransomware is a regular backup kept independently of the device: if a current copy of your important files sits on a separate disk or in the cloud, the encrypted files have no bargaining value left. For a backup to be of use, a restore attempt has to be made now and then as well; a backup that will not open is not a backup.

Related terms: Phishing, Fake Text Messages, Remote Access Scams

From the same atlas

First published: 2026-08-12Last reviewed: 2026-08-12Editorial status: working editionReport an error