Back to glossary

Worm

3 min read

A worm is malware that spreads across networks on its own, without anybody having to open anything. That is the whole distinction from a virus, and it is what makes a worm a problem measured in minutes rather than in weeks.

July 30, 2026
Compartir:

A worm is a type of malware that propagates across computer networks on its own, with no direct human involvement.

That is the difference from a virus, and it is the only one that matters: a virus needs somebody to run an infected file, while a worm spreads by itself, exploiting weaknesses in operating systems, applications or network services.

Because propagation is automatic, a worm affects availability, integrity and confidentiality at a speed no manual process can match, and the containment window is correspondingly short.

What characterises it

Self-propagation. It scans for reachable systems and exploits the same weakness again, copying itself onward. One infected host becomes many without anybody clicking anything.

Damage, sometimes as a side effect. A worm can consume network and compute resources to the point where services degrade, and it can corrupt or destroy data, whether or not that was the intent. Some of the most disruptive incidents on record did their damage simply by spreading faster than anybody could respond.

Stealth and persistence. Some are built to avoid detection and to survive a reboot, so that removing the visible copy does not end the infection.

A worked example

A worm reaches a corporate network by exploiting a vulnerability in server management software.

Once it infects one device, it automatically scans other devices on the same network for the same weakness.

Where it finds one, it exploits it and copies itself across.

Over time it spreads through the estate, congesting the network, interrupting services and potentially corrupting or deleting data. Nobody had to open an attachment for any of this to happen.

Why the distinction changes the response

Against a virus, awareness training is a real control, because a human decision is in the loop. Against a worm it is not, because there is no decision.

What stops a worm is narrower and less comfortable: patching the vulnerability it uses, and segmenting the network so that reachability is limited and the blast radius has a boundary. Segmentation is what turns an estate-wide incident into a contained one, and it is the control most often postponed because nothing visibly breaks while it is missing.

The self-propagating technique has not gone away. It reappears whenever a widely deployed service has a remotely exploitable flaw, and it has been combined with ransomware more than once, which is what turns a payload that would have hit one machine into one that hits every machine it can reach.

Where to read more

Kaspersky, What is the difference between a virus and a worm: a clear treatment of the distinction, the propagation methods and the preventive measures for each.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.