Secure development lifecycle (SSDLC): what it is and how to put it in place
What the secure development lifecycle is, what happens in each phase, what SAST, DAST and SCA add, and where to start if you have nothing in place today.
Almost every list of malware types is the same run of six names, and a run of names is no help in deciding anything. Here they are classified by the two axes that do change your defence, how they spread and what they are after, and at the end the concrete steps for when you already suspect that a machine is infected.
Malware is any software written to do something you did not want: steal, encrypt, spy, delete or use your resources. It is the umbrella term.
"Virus" is one of the families underneath it, and for historical reasons it ended up naming all of them. The confusion is not harmless: a virus is the malware that attaches itself to another file and needs somebody to run it in order to replicate. A worm is not one, because it travels on its own. A trojan is not one either, because it does not replicate: it disguises itself. Ransomware is not one either, because it is a business model that can arrive by many routes. All of them are malware; only one of them is a virus.
And this changes what you do. Somebody who thinks they have "a virus" looks for a program to clean up a file. Somebody with a credential stealer inside does not have a file problem: their passwords are outside, and cleaning the machine does not bring them back. The word you use decides where you look.
A flat list of names helps you decide nothing, because it mixes two different questions. Separated, they become useful.
Axis 1: how it arrives and how it stays. This is the preventive defence axis, because two families that come in through the same door get stopped by the same thing.
Axis 2: what it is after. This is the impact axis, and the one that decides who you notify and what you recover.
Ordered by what they are after, which is the second axis.
The usual list of symptoms (the machine is slow, windows pop up, programs close on their own) still holds, but the thing almost no page says has to be said: those signs belong to the malware that does not mind being noticed. Adware wants you to see it, because that is what it lives on. A miner shows up because the fan never stops. The one that actually does the damage tries the opposite: a rootkit exists so that you do not see it, a backdoor can sit there for months doing nothing, and a credential stealer works once and deletes itself.
A practical rule, uncomfortable but honest: noticing something odd is reason enough to look, and noticing nothing is not a reason to be calm. In a company the signs that are worth having are not on the machine, they are in the accounts: sign ins from places where nobody was, new forwarding rules on a mailbox, second factors registered that nobody registered.
And once the suspicion is there, the order matters. The first three steps are the ones people skip and the ones that stop a small incident from becoming a big one.
And one thing that is on no list and decides the outcome: write down what you are doing, with the time. What you saw, when, what you touched. If this turns out to be something serious, that note is the difference between reconstructing what happened and guessing it.
On which program detects what, and why a classic antivirus does not see a good part of the above, there is what an antimalware is. The two articles answer different questions and deliberately do not repeat each other.
This is where the previous version of this article jumped straight to offering pentesting, and the jump did not hold up: somebody searching for types of malware is not buying an audit. The bridge, where there is one, is this.
Look at axis 1 again. Almost every family comes in through two doors: a person, or something of yours that is exposed and unpatched. The first one gets checked with a controlled phishing exercise, which measures how many people report it and how long they take, not how many click. The second one gets checked by looking from outside at what you have published, which almost never matches what you think.
And axis 2 leads to the question that no list of malware answers: if something gets in, how far does it get? An antivirus does not answer that; walking the route does. An internal network pentest starts from inside and measures how far somebody who is already there can move. The difference between one infected machine and a company at a standstill is usually exactly there, and it is the only thing on this whole page that can be measured in advance.
Last reviewed: 4 August 2026. Originally published on 27 November 2023.
If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.
Talk to a senior pentesterPick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.