Types of Malware: What Each One Does
Each malware family is defined by how it spreads and what it does. That one-line difference is what the exam tests.
Malware is any software written to do harm: steal data, take control of a device, lock files or quietly use a machine for someone else's purpose. RBI's 2026 cybersecurity directions for banks define it as software designed with malicious intent that can cause harm to entities or their information systems.
For a bank, malware arrives two ways. It lands on a staff machine through an email attachment, a pen drive or an unpatched server, or it lands on a customer's phone through a fake app. The exam expects you to name each family by how it behaves, because that is what decides the control that stops it.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
The Malware Families
The distinguishing feature of each is what the exam tests. Learn the one-line difference, not just the name.
- Virus
- Attaches itself to a host file or program and runs when that host is opened. It needs a user action to spread, such as opening an infected document.
- Worm
- Copies itself across a network on its own by exploiting a weakness. No host file and no user click needed, which is why one infected server can take down a branch network.
- Trojan
- Pretends to be something useful (a KYC update app, an invoice viewer) while doing something harmful in the background. It does not replicate by itself.
- Banking trojan / SMS stealer
- A trojan built to capture net banking logins, read incoming SMS and forward OTPs to the fraudster. Common on Android phones through apps installed from links.
- Spyware and keylogger
- Records what the user does: keystrokes, screens, browsing. A keylogger on a shared cyber cafe computer captures every password typed on it.
- Remote access trojan (RAT)
- Gives the attacker hidden control of the device, including the screen and camera.
- Rootkit
- Hides itself and other malware deep in the operating system so ordinary antivirus scans miss it.
- Bot and botnet
- An infected machine that takes orders from a remote controller. Thousands together form a botnet, used for spam and denial-of-service attacks.
- Ransomware
- Encrypts files and demands payment for the key. Covered in depth on its own page.
- Cryptominer
- Uses the victim's processing power to mine cryptocurrency. The sign is a machine that is suddenly slow and hot.
- Adware
- Pushes unwanted ads and often tracks browsing. Least damaging, but frequently bundled with worse.
How It Reaches a Bank and Its Customers
The most common customer case today is a trojan app. A caller posing as the bank or an electricity board sends a link to an app file on WhatsApp. Once installed and given SMS permission, it forwards every OTP, and the account is emptied without the customer ever sharing a code knowingly.
Inside the bank, the routes are phishing attachments, infected pen drives and unpatched internet-facing servers. RBI's 2026 directions require banks to scan removable media for malware before allowing read or write access, and to run anti-malware with behavioural detection across endpoints, servers, email and web gateways. Behavioural detection matters because new malware has no known signature yet.
Quick practice on banking operations. No signup.
What the Law Says
| Rule | What it covers |
|---|---|
| IT Act s.43(c) | Introducing a computer contaminant or virus into a computer without the owner's permission: liability to pay compensation to the person affected |
| IT Act s.66 | The same act done dishonestly or fraudulently is an offence: imprisonment up to three years, or fine up to ₹5 lakh, or both |
| IT Act s.43, Explanation | Defines 'computer virus' (destroys, damages or degrades performance, or attaches to another resource and runs on an event) and 'computer contaminant' (instructions designed to modify, destroy, record or transmit data, or to usurp normal operation) |
| CERT-In Directions, 2022 | Malicious code attacks (virus, worm, Trojan, bots, spyware, ransomware, cryptominers) must be reported to CERT-In within 6 hours of noticing them |
How the IIBF Exam Tests This
- check_circleMatching a description to a name. 'Spreads across the network without any user action' is a worm, not a virus. 'Looks like a genuine app' is a trojan.
- check_circleThe replication trap. Candidates often pick 'trojan' for anything that spreads. Trojans don't self-replicate; viruses and worms do.
- check_circleControl questions. Antivirus with behavioural detection, patching and media scanning are preventive; the CERT-In report is part of the response.
- check_circleLegal mapping. Introducing a virus is a s.43 civil wrong; it becomes a s.66 offence only with dishonest or fraudulent intent.
FAQs
What is the difference between a virus, a worm and a trojan?expand_more
A virus attaches to a host file and spreads when that file is opened. A worm spreads across networks on its own, with no host and no click. A trojan disguises itself as useful software and does not replicate.
Which section of the IT Act deals with spreading a computer virus?expand_more
Section 43(c) makes introducing a virus or contaminant without permission a ground for compensation. If done dishonestly or fraudulently, section 66 makes it an offence punishable with up to three years, a fine up to ₹5 lakh, or both.
How does malware steal OTPs from a customer's phone?expand_more
A trojan app, usually installed from a link sent by a fake caller, gets permission to read SMS and forwards every OTP to the fraudster. The customer never knowingly shares the code.
Does a bank have to report a malware attack?expand_more
Yes. CERT-In's 2022 directions list malicious code attacks among the incidents that must be reported to CERT-In within 6 hours of noticing them. RBI reporting is separate and covered on the bank incident reporting page.
Next steps
- Ransomware & Extortionarrow_forward
- Vulnerabilitiesarrow_forward
- Phishing, Vishing, Smishingarrow_forward
- Syllabusarrow_forward
120 questions, 2 hours, scored instantly.
