Blog/Security basics

The Complete Guide to Malware, Ransomware and Malicious Software

How malware and ransomware get onto phones and computers, the main types, the warning signs, how to prevent infection, and what to do if a device is infected.

CyberWatch AIReviewed by Divine Egyabeng, Security Operations AnalystLast reviewed 27 September 2026 · 10 min read
A laptop keyboard wrapped in a chain and padlock under red and green light

A message pops up while you are working: "Your browser is out of date and may be unsafe. Update now." It looks like the real thing, so you click. A small file downloads and installs. Nothing seems to change. But over the next few days, every password saved in your browser, every logged-in session and a crypto wallet you forgot you had are quietly copied and sold.

That is malware: software built to harm you, usually without you noticing. It ranges from programs that steal passwords and spy on messages to ransomware that locks every file in a business and demands payment to release them.

This guide explains how malware gets onto computers and phones, the main types including ransomware, spyware and infostealers, the signs that a device is compromised, how to prevent infection, and exactly what to do if it happens. It applies to Windows, Mac, Android and iPhone users anywhere, and to the organizations they work for.

What is malware?

Malware, short for malicious software, is any program designed to damage a device, steal from its user, spy on them or give an attacker control. It does not need to be dramatic to be dangerous. Much modern malware is designed to stay hidden for as long as possible while it collects data or waits for the right moment to strike.

How malware gets onto your device

Most malware still needs a person to open or install something. The most common routes are:

  • Email attachments and links: fake invoices, delivery notes and shared documents. See our complete guide to phishing.
  • Fake downloads and updates: pop-ups and websites offering browser updates, codecs, PDF readers or "security tools".
  • Apps from outside official stores, including modified versions of popular apps and files sent in chats.
  • Pirated and cracked software, games and cheats, which are a favourite way to spread password stealers.
  • Malicious adverts and search results that lead to lookalike download pages.
  • Browser extensions that ask for broad permissions, or legitimate extensions that change hands and turn malicious.
  • Unpatched software: known weaknesses in operating systems, browsers and internet-facing systems.
  • Removable media: USB drives from unknown sources.

Types of malware

TypeWhat it does
Virus and wormSpreads by infecting files or moving between devices and networks
TrojanPretends to be something useful to get installed, then does harm
RansomwareLocks or encrypts files and demands payment; often steals data first
InfostealerCollects saved passwords, browser cookies, crypto wallets and files
Spyware and keyloggersRecords activity, keystrokes, messages or screens
StalkerwareSpyware secretly installed by someone who knows the victim
Banking malwareTargets banking and payment apps, often by reading texts and overlaying fake screens
Remote access trojanGives an attacker control of the device
AdwareFloods the device with adverts and redirects, sometimes leading to scams
CryptominerUses the device's power to mine cryptocurrency, slowing it down

Ransomware in depth

Ransomware can stop a business, a school or a hospital outright. A typical attack runs in stages:

  1. Getting in, usually through phishing, a stolen password for remote access, or an unpatched system.
  2. Spreading quietly across the network, sometimes for days or weeks.
  3. Stealing data so it can be used as extra leverage.
  4. Encrypting files and deleting or encrypting backups that are reachable.
  5. Demanding payment for a decryption key, and threatening to publish the stolen data.

Our article how ransomware gets in covers the three most common entry points and how to close them.

Should you pay?

Law enforcement and security organizations advise against it. The No More Ransom project, run by Europol, Dutch police and industry partners, puts it plainly: paying confirms to criminals that ransomware works, and there is no guarantee you will receive a working key. No More Ransom also offers free decryption tools for some ransomware families, so check it before assuming files are lost. Paying may also raise legal questions in some countries. The strongest protection is backups that attackers cannot reach.

Malware on phones

  • Android: the biggest risk is installing apps from outside Google Play, often shared as files in chats or websites. Watch for apps that ask for accessibility, SMS or device admin permissions without a clear reason, since banking malware abuses these. Google Play Protect checks apps and warns about harmful ones; keep it on.
  • iPhone: malware is less common thanks to the App Store's controls, but phishing, malicious configuration profiles and scams still work. Do not install profiles or "enterprise" apps sent by strangers, and avoid jailbreaking.
  • Both: keep the system updated, install apps only from official stores, review app permissions, and be wary of any app that someone insists you install during a call or chat.

Fake app installers are common in messaging scams; see our guide to WhatsApp scams.

Signs a device may be infected

SignWhat it can mean
Sudden slowness, overheating or battery drainHidden processes such as miners or spyware
Pop-ups, redirects or new toolbarsAdware or a malicious extension
Apps or extensions you did not installSomething installed them for you
Security tools turned offMalware disabling protection
Accounts accessed from unknown placesStolen passwords or session cookies
Texts or messages sent without youPhone malware or a taken-over account
Files renamed and unopenable, with a ransom noteRansomware
Unusual data useData being sent from the device

Illustrative examples, with the red flags explained

These examples are fictional and written for this guide. Links and file names are illustrative.

Illustrative example · Fake browser update
A full-screen message on a news website: "Critical update required. Your version of Chrome is out of date and cannot display this page. Download the update to continue." [Download update: chrome_update_2026.exe]
Red flags:
  • Browsers update themselves or through their own settings, not through pop-ups on other websites.
  • A downloadable file offered by a web page you were only reading.
  • What to do: close the tab. Check for updates in your browser's own settings.
Illustrative example · Invoice attachment
Subject: Overdue invoice 44871 Please find the overdue invoice attached. Payment is required today to avoid late fees. Attachment: Invoice_44871.zip (password: 4487)
Red flags:
  • An unexpected invoice with urgency.
  • A password-protected zip, which email filters cannot inspect.
  • What to do: do not open it. Check with the supplier through a known contact, and report the email.
Illustrative example · App sent in a chat
"Hi, this is your bank's support team. To fix the problem with your account, please install our new security app from this file and grant it the permissions it asks for: BankSecure_v2.apk"
Red flags:
  • Banks do not send apps as files in chats.
  • A request to grant permissions, which can let the app read texts and control the screen.
  • What to do: do not install it. Contact your bank through its official app or phone number.

Unsure about a link or download page? Paste it into CyberWatch AI Scan for a free second opinion before you download anything.

How to prevent malware

  • Update everything: operating systems, browsers, apps and routers. Turn on automatic updates.
  • Keep built-in protection on: Microsoft Defender on Windows, XProtect and Gatekeeper on Mac, Google Play Protect on Android.
  • Install only from official stores and official developer websites. Avoid cracked software and "free" versions of paid apps.
  • Be careful with attachments and links, especially unexpected ones, and never enable macros in documents you did not expect.
  • Review browser extensions and remove any you do not use or recognise.
  • Use a standard account for daily work on computers, rather than an administrator account.
  • Back up important files regularly, with at least one copy disconnected from your device.
  • Protect accounts with two-step verification so that stolen passwords alone are not enough. See our guide to account security.

Safe downloading habits

  • Go to the source. Download software from the developer's official website or your device's official app store, reached by typing the address or searching carefully, not through adverts.
  • Be wary of sponsored search results for popular software. Scammers buy adverts that lead to convincing fake download pages.
  • Check the file you received. A "PDF" that ends in .exe, or a document inside a password-protected zip, is a red flag.
  • Say no to extra installs. Read installer screens and untick bundled offers.
  • Avoid "free" paid software, cracks, key generators and game cheats. They are among the most common carriers of password-stealing malware.

Browser extensions: small tools, big access

Extensions can read and change the websites you visit, which makes them powerful and, when malicious, dangerous. Some are malicious from the start; others begin as genuine tools and are later sold to someone who adds harmful code.

  • Install only extensions you need, from the official browser store, with a clear developer and a good track record.
  • Check the permissions. An extension that needs to "read and change all your data on all websites" should have a very good reason.
  • Review your extensions every few months and remove anything unused or unfamiliar.

Why malware can get past two-step verification

Password-stealing malware often takes more than passwords. It can copy the session cookies that keep you logged in, letting an attacker use your accounts without ever needing your code. That is why, after an infection, changing passwords is not enough on its own: sign out of all sessions on important accounts too, ideally from a clean device, so any stolen cookies stop working.

Backups that survive malware

Good backups turn ransomware from a disaster into an inconvenience. A widely used rule of thumb is 3-2-1: keep three copies of important data, on two different types of storage, with one copy kept offline or somewhere attackers cannot reach from your main systems.

  • Automate backups so they happen without anyone remembering.
  • Keep one copy disconnected or protected so it cannot be changed or deleted from the network.
  • Test restoring a file every few months. A backup is only proven when you have restored from it.
  • Remember phones: turn on backups for photos and important data there too.

What to do if a device is infected

  1. Disconnect it from Wi-Fi and wired networks to stop data leaving and malware spreading.
  2. Do not pay any ransom or "technician" who contacts you.
  3. From a different, clean device, change passwords for email, banking and other important accounts, and sign out other sessions.
  4. Run the built-in security scan and remove what it finds. On phones, uninstall unfamiliar apps and remove unusual permissions.
  5. If problems continue, back up your personal files (not programs), then reset the device or reinstall the operating system.
  6. Check your accounts for activity you did not do, and tell your bank if financial apps were on the device.
  7. Get help from your IT team at work, or a reputable local technician, and report serious incidents to your national reporting service.

If it happened at work, report it straight away; our article clicked a phishing link at work? explains the first steps.

Ransomware response for organizations

For an organization, a ransomware attack is a business emergency. Isolate affected systems without switching them off, call your IT or incident response support, protect backups, notify your insurer and the authorities, and communicate honestly with staff and customers. The US Cybersecurity and Infrastructure Security Agency's #StopRansomware guide and the UK National Cyber Security Centre's guidance give detailed checklists. Our guide to small business cybersecurity includes a one-page incident plan.

Most ransomware starts with a person opening a message or a password being stolen. CyberWatch AI helps organizations reduce that risk with realistic phishing practice, short training and one-step reporting for every employee.

Stalkerware and safety

Stalkerware is monitoring software secretly installed by someone with access to your phone, such as a partner or family member, to read messages, track location or listen to calls. Signs can include the other person knowing things they should not, unusual battery drain, or unfamiliar apps with broad permissions.

If you suspect stalkerware, think about your safety first. Removing it may alert the person who installed it. Consider using a device they cannot access to seek help, and contact a domestic abuse support service, which can help you plan safely before making changes.

Old devices and unsupported software

Every device eventually stops receiving security updates. After that point, newly discovered weaknesses are never fixed, and attackers know it. An old phone, an old version of Windows or a router that the manufacturer no longer supports can be the easiest way into a home or office.

  • Check whether your devices still receive updates, and plan to replace those that do not.
  • Do not use unsupported devices for banking, email or work.
  • Replace or update old home and office routers, which are often forgotten.

Shared and public computers

Computers in cafés, hotels, libraries and shared offices may be poorly maintained or deliberately infected with keyloggers. Avoid signing in to email, banking or work accounts on them. If you must, use a private browsing window, never let the browser save your password, sign out completely and change the password afterwards from your own device.

Keeping children's devices safe

  • Use the parental controls built into phones, tablets and app stores to limit installs to approved apps.
  • Explain that "free" game currency, cheats and modified apps are a common way malware spreads.
  • Keep family devices updated and backed up.

Common myths about malware

  • "Macs and iPhones can't get malware." They are targeted less often, but not never, and phishing works on every device.
  • "I'd notice if I was infected." Much modern malware is designed to be invisible.
  • "Antivirus makes me safe." It helps, but updates, official app stores and careful habits matter more.
  • "Paying the ransom gets my files back." There is no guarantee, and it funds the next attack.
  • "Only dodgy websites spread malware." Malicious adverts and hacked legitimate sites can too.

Frequently asked questions

What is malware?

Malware is any software designed to harm a device or its user: stealing data or passwords, spying, locking files for ransom, showing unwanted adverts, or giving criminals remote control. Viruses, trojans, spyware and ransomware are all types of malware.

How does malware usually get onto a device?

Most often through something the user opens or installs: an email attachment, a link to a fake download or update, an app from outside the official store, pirated software, or a malicious browser extension. Unpatched software is another common route.

Should I pay a ransomware demand?

Law enforcement and security organizations advise against paying. Payment does not guarantee you get your files back, it funds further crime and it may mark you as willing to pay. Check the No More Ransom project for free decryption tools and restore from backups where possible.

Can phones get malware?

Yes. Android phones are most at risk from apps installed outside official stores and from apps that abuse permissions. iPhones are less often affected but not immune, and both can be targeted through phishing and malicious profiles or links.

Do I still need antivirus?

Modern operating systems include built-in protection, such as Microsoft Defender on Windows, XProtect on Mac and Google Play Protect on Android, which should be kept on and updated. Updates, official app stores and careful habits matter more than adding extra products.

What are the signs that my device has malware?

Signs include a sudden slowdown, crashes, pop-ups, unfamiliar apps or browser extensions, settings changing on their own, security tools being turned off, unexpected data use or battery drain, and accounts being accessed without you.

What should I do if I think my computer is infected?

Disconnect it from the internet, run your built-in security scan, and change important passwords from a different, clean device. If the problem persists, back up your personal files, then reset or reinstall the system, or get professional help.

What is an infostealer?

An infostealer is malware that quietly collects saved passwords, browser cookies, crypto wallets and other data from a device and sends them to criminals. It is often spread through fake downloads and pirated software, and can lead to account takeover even when two-step verification is on.

What is stalkerware and what should I do if I suspect it?

Stalkerware is software secretly installed to monitor someone's messages, location and activity, often by a partner or family member. If you suspect it, consider your safety before removing it, because the person may notice. Support services for domestic abuse can help you plan safely.

Can CyberWatch AI check a suspicious link or download page?

Yes. Paste the link or message, or upload a screenshot, into CyberWatch AI Scan for free, and it will explain what looks suspicious. Do not download or open a file you are unsure about while you check.

Sources

  1. How To Recognize, Remove, and Avoid Malware, US Federal Trade Commission
  2. StopRansomware, US Cybersecurity and Infrastructure Security Agency
  3. #StopRansomware Guide, US Cybersecurity and Infrastructure Security Agency
  4. Mitigating malware and ransomware attacks, UK National Cyber Security Centre
  5. Device security guidance, UK National Cyber Security Centre
  6. No More Ransom, Europol, Dutch Police and industry partners
  7. Use Google Play Protect to help keep your apps safe, Google Play Help
  8. Protecting against malware, Apple Platform Security
  9. Report cybercrime online, Europol
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.