IAS/UPSC Coaching Institute  

Whatsapp 88106-52225 For Details

Get Free IAS Booklet

Get Free IAS Booklet

COMPUTER VIRUSES

• A computer virus is a type of malicious code or program written to alter the way a computer operates and is designed to spread from one computer to another.

• In the process, a virus has the potential to cause unexpected or damaging effects, such as harming the system software by corrupting or destroying data.

What are the different types of computer viruses?

Boot sector virus: This type of virus can take control when you start or boot your computer. One way it can spread is by plugging an infected USB drive into your computer.

Web scripting virus: This type of virus exploits the code of web browsers and web pages. If you access such a web page, the virus can infect your computer.

Browser hijacker: This type of virus “hijacks” certain web browser functions, and you may be automatically directed to an unintended website.

Resident virus: This is a general term for any virus that inserts itself in a computer system’s memory. A resident virus can execute anytime when an operating system loads.

Direct action virus: This type of virus comes into action when you execute a file containing a virus. Otherwise, it remains dormant.

Polymorphic virus: A polymorphic virus changes its code each time an infected file is executed. It does this to evade antivirus programs.

File infector virus: This common virus inserts malicious code into executable files (files used to perform certain functions or operations on a system).


Multipartite virus: This kind of virus infects and spreads in multiple ways. It can infect both program files and system sectors.

Macro virus: Macro viruses are written in the same macro language used for software applications.

• Such viruses spread when you open an infected document, often through email attachments. A computer worm is malware, just like a virus, but a worm takes a copy of itself and propagates it to other users.

Effects of Computer Virus

• It can steal data or passwords and log keystrokes,

• spam user email contacts, corrupt files and erase data

potential to permanent damage to the hard disk and sometimes can even take over your device control.

MALWARE

• Attackers use malware, often known as malicious software, to purposefully damage and infect networks and devices.

There are numerous subcategories under the general phrase, such as the following:

Viruses

• A virus is a kind of harmful program or code that is intended to change a computers functionality and propagate from one computer to another.

Worms

• Without human help, a computer worm can copy itself and spread to other systems. Malicious links, files, or security flaws allow this virus to infect devices. Worms search for networked devices to assault once they are inside. Users frequently fail to detect worms since they typically seem as authentic work files.

• One of the most well-known ransomware assaults is WannaCry, which is actually a type of malware. The malware exploited the Server Message Block protocol’s Eternal Blue vulnerability in out-of-date versions of Windows. 150 countries were affected by the worm’s first year of spread. It infected around 5 million devices the next year.

Ransomware

• Ransomware encrypts devices and forces the victims to pay a ransom in exchange for re-entry. Although malware and ransomware are sometimes used interchangeably, ransomware is a particular type of malware.

• There are four main types of ransomware:

• Locker locks: Ransomware known as Locker locks

victims out of their gadgets entirely.

Crypto Ransomware : On a device, crypto ransomware encrypts all or portion of the files.

Double extortion ransomware: It encrypts and

exports users’ files. In this way, attackers can receive payment from the ransom and/or the selling of the stolen data.

Ransomware-as-a-Service : Affiliates and clients can rent ransomware through the use of Ransomware as a service (RaaS). The creator of the ransomware receives a portion of every ransom.

• Prominent ransomware variations include the strains employed in the Colonial Pipeline assault, REvil, and WannaCry.

Bots

• A bot is a type of malware that reproduces itself and spreads to other machines to form a network of other bots, or botnet. Devices that have been infected carry out automatic actions under the attacker’s control. DDoS assaults frequently make use of botnets. They are also capable of sending phishing emails and keylogging.

• A well-known illustration of a botnet is Mirai. This malware continues to target IoT and other devices, having launched a large DDoS attack in 2016. Studies also reveal that during the COVID-19 epidemic, botnet usage increased.

Trojan Horses

• Trojan Horses is malicious software that appears very trustworthy to users. Trojan horses infiltrate devices through social engineering methods. The Trojan’s payload, or malicious code, is loaded on a device once it has gained access to it and is what makes the exploit possible. Trojans implant viruses or worms, perform keylogging, provide attackers with a backdoor into a device and steal data.

Remote access Trojans (RATs) : Remote Access from a distance Attackers can get control of an infected device by using Trojan horses, or RATs. Once inside, the compromised device can be used by the attackers to spread the RAT to further devices and build a botnet.

• In 2014, the Emotet banking Trojan was initially identified. Emotet was taken down globally at the start of 2021, however it was rebuilt and is still assisting threat actors in obtaining the financial details of their victims.

Keyloggers

• A keylogger is a type of malware used for surveillance that tracks keystroke patterns. Keyloggers are used by threat actors to get sensitive information such as victims’ passwords and usernames.

Keyloggers may be software- or hardware-based. Keyboards are manually fitted with hardware keyloggers. The attacker needs to personally pick up the device after the victim uses it. Conversely, software keyloggers don’t need physical access. The victim frequently downloads them through malicious downloads or links.


Software keyloggers capture keystrokes and transmit the information to the assailant.

• In 2014, the Agent Tesla keylogger was first discovered. Even with its most recent iterations, the spyware RAT continues to annoy people by recording keystrokes and capturing screenshots of their devices.

Rootkits

Malicious software known as a rootkit gives threat actors remote access to and control over a device. Keyloggers, viruses, and ransomware are just a few of the malware variants that are made easier to spread by rootkits.

• Because rootkits have the ability to disable antivirus and endpoint antimalware programs once they’re inside a device, they frequently go undiscovered. Usually, malware attachments and phishing emails are how rootkits infiltrate networks and devices.

• Cybersecurity teams should examine network behavior to identify rootkit assaults. Set alerts, for instance, if a user starts logging on at a different time or place every day after consistently doing so at the same time and place.

• In 1999, NT Rootkit the original rootkit was released. Released in 2003, Hacker Defender quickly became one of the most widely used rootkits of the 2000s.

Spyware

• Malware that installs itself on a device without the users consent is known as spyware. Users’ data is stolen and sold to outside users and advertising. Spyware can monitor user credentials and acquire private information such as bank account details. Via rogue programs, URLs, webpages, and email attachments, it infects devices.

• Mobile device spyware is especially harmful since it records a user’s position and has access to the device’s camera and microphone. It can be distributed through Short Message Service and Multimedia Messaging Service. Spyware includes Trojan horses, adware, keyloggers, and mobile spyware.

• The mobile spyware Pegasus targets Android and iOS gadgets. When it was initially found in 2016, Israeli technology provider NSO Group was connected to it. In November 2021, Apple filed legal action against the merchant for disparaging Apple consumers and goods. In 2018, Pegasus was also connected to the assassination of Saudi journalist Jamal Khashoggi.

Cryptomining Malware

Mining -Although it takes a lot of processing power, the process of confirming transactions within a blockchain is quite profitable. For every legitimate transaction, miners receive a reward. The process by which cryptomining malware operates, known as cryptojacking, gives

threat actors the ability to verify using the resources of a compromised device.

CISCO discovered that in 2020, 69% of its users were impacted by malware that mined cryptocurrency, which accounted for the majority of DNS traffic to malicious websites in that year.

In 2020, XMRig emerged as the most widely used cryptocurrency mining virus, with JSEcoin, Lucifer, WannaMine, and RubyMiner trailing behind.

Adware

Adware: “Adware” is software that displays or downloads unsolicited advertisements, typically in the form of pop-ups or banners. In order to present users with appropriate adverts, it collects browsing history and cookies.

Adware isnt always harmful. Software developers use legitimate adware with users’ consent to offset development costs. Malicious adware, however, has the ability to show adverts that could infect a computer when clicked.

• Threat actors insert malicious adware into already- installed applications and utilize vulnerabilities to infect PCs. Additionally, users may download programs that have already been tainted with malware. Alternatively, adware—also referred to as bloatware—may be pre- installed on a device or be part of a software bundle that is downloaded together with a genuine program.

• Programs like Fireball, Gator, Dollar Revenue, and OpenSUpdater are examples of adware.