Malware
Capability, not hype
What each class of malware is for, how it gets in, how it is detected, and what reduces the blast radius.
MALWARE / 01
In this section
Ransomware
Extortion malware that encrypts systems, and increasingly steals data first, to force a payment after attackers have already gained access.
Detection guidanceMALWARE / 02
Infostealers
Malware that harvests saved passwords, session cookies, tokens and crypto wallets from browsers and apps, then sells them as ready-made access.
Detection guidanceMALWARE / 03
Loaders
Small first-stage malware that gets a foothold, profiles the victim and delivers the next payload, often a stealer, remote access tool or ransomware.
Detection guidanceMALWARE / 04
Remote access tools
Legitimate remote-management software (RMM) and remote access trojans abused to control machines while blending into ordinary IT activity.
Detection guidanceMALWARE / 05
Phishing kits
Rentable phishing-as-a-service kits that proxy real sign-in pages to steal passwords and session cookies, bypassing common MFA.
Detection guidance