Ask a Question

Advanced Search

Alert ID : INFO1293

Last Modified : 05/31/2018

Malware 101


5 Minute Guide to Malware

Malware – malicious software – is any code or application that damages or secretly takes control of a computer system, device, or network. Malware is used to steal private information, disrupt businesses, and extort payments. Malware is a genuine threat to your website, to your business, and to your customers. Malware leads to:

  • Website traffic loss – New customers are warned about your site and loyal customers stop coming back.

  • Brand tarnishing – Your company's reputation – not just your website – is damaged.

  • Consumer distrust – Consumers will not trust your website, business, or products and services.


Instead of overt internet vandalism and mayhem, today’s malware criminals stealthily infiltrate websites and home computers for illegal profit.

Their mission: Put malware on your site and spread the malware to your visitors for fraud and theft.

Your mission: Keep malware off your site and keep customers on your site!


Why should I care about malware?

Trust. Your customers and business partners trust that your website is safe. Malware on your site diminishes or eliminates that trust.

  • Customers who are warned of or infected by malware on your site will no longer trust your site or business.  They may stop doing business with you through any means.

  • If there is malware on your site, web browsers and search engines will show a warning that your site is dangerous when a customer tries to visit it (this is known as "blacklisting").

  • Malware on your site can install malware on your customers' computers (known as "drive-by downloads").  Malware on your customers' computers can steal their personal information, track their keystrokes and activities, and spread viruses and more malware.

What is malware?

Malware is any computer program that is installed on a computer without the owner’s knowledge, in order to deliberately damage the computer or perform illegal activities.

  • Malware is short for "malicious software". Malware is related to the more well-known term "computer virus", but they are not exactly the same.

  • Malware is a broad term used to refer to many different forms of hostile, intrusive, or annoying software, such as computer viruseswormstrojan horsesrootkitsspyware, unintended adware, and crimeware.

How is malware used?

For illegal profit, consumer deception, website vandalism, and other criminal activities.

  • Adware shows pop-up ads on infected computers and the attackers collect payment based on the number of times the ads appear.

  • Spam is the bulk junk mail that everyone gets in their Inbox.  Spam can be sent from malware-infected computers.  The attackers collect payment based on the number of emails sent or on responses to the sales or information requests in the emails.

  • Identity Theft and Infostealing capture private information, such as usernames and passwords, credit card and banking information, or social security numbers. The attackers can use the stolen data directly to impersonate the theft victim, or sell lists of stolen data within their crime network.

Where does malware come from?

Like a computer virus, malware starts on a few computers and then spreads to many computers.

  • To effectively distribute malware to as many computers as possible, the first goal of a malware attack is to infect your website.

  • Unknown to you and the people who visit your site, the malware then installs more malware on the visitors' computers.

Installation may be totally invisible to your site visitors – all a visitor needs to do is go to a certain page, and the malware can install on the visitor's computer. Installation may also be disguised as a useful app that the visitor intentionally downloads and installs.

How do I prevent a malware infection?

Keep your web server secure, clean, and backed up.

  • Maintain an up-to-date backup server.
  • Secure the web server that hosts your website.
  • Secure any applications or other code that is executed or distributed on your website.
  • Know and trust the people who manage your website.
  • Remove programs that are not needed.
  • Do not use the server for other purposes, especially browsing the web.
  • Do not rely solely on commercial, off-the-shelf antivirus services to protect your website.
  • See the Malware Best Practices article for more details on these prevention recommendations.