{"id":7055,"date":"2021-06-21T13:37:57","date_gmt":"2021-06-21T21:37:57","guid":{"rendered":"https:\/\/cheapsslsecurity.com\/blog\/?p=7055"},"modified":"2021-07-19T15:52:08","modified_gmt":"2021-07-19T23:52:08","slug":"what-is-malware-and-what-does-it-do","status":"publish","type":"post","link":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/","title":{"rendered":"What Is Malware and What Does It Do? A Malware Definition"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\"><a href=\"https:\/\/www.av-test.org\/en\/statistics\/malware\/\">AV-TEST Institute<\/a> registers more than 350,000 new malware and potentially unwanted applications (PUAs) daily. The sheer number of new malware is enough to make you shiver \u2014 so long as you understand what \u201cmalware\u201d entails. But what is malware and what does it do? Let\u2019s explore malware definition and meaning<\/h2>\n\n\n\n<p>Malware is a threat that can be found everywhere online. It\u2019s hidden in app stores\u2019 most popular apps, gets sent daily through email, and often can be found attached to some of your favorite share-site downloads. But what is malware and what does it do? We\u2019ll break down malicious software and why it\u2019s such a threat to businesses.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Is Malware? A Quick Malware Definition &amp; Meaning<\/h2>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/mikko-hypponen-malware-quote.jpg\" alt=\"A quote by Mikko Hypponen about malware being used as an offensive weapon\" class=\"wp-image-7057\" width=\"384\" height=\"384\" srcset=\"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/mikko-hypponen-malware-quote.jpg 1021w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/mikko-hypponen-malware-quote-300x300.jpg 300w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/mikko-hypponen-malware-quote-150x150.jpg 150w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/mikko-hypponen-malware-quote-768x768.jpg 768w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/mikko-hypponen-malware-quote-370x370.jpg 370w\" sizes=\"(max-width: 384px) 100vw, 384px\" \/><\/figure><\/div>\n\n\n\n<p>What is malware and what does it do? The definition of malware is simple: malware is a program or even just code that\u2019s written with an intent to cause harm to a computer system or a network of systems. Malware is short for malicious software (malware) \u2014 the term is an example of a <em>portmanteau<\/em> because it takes parts of two words and combines them.<\/p>\n\n\n\n<p>So, what is malicious software in the sense of how cybercriminals use it? Malware is a catch-all term that describes a software program or code that helps people perform espionage, sabotage, or steal data from others. <a href=\"https:\/\/encyclopedia.kaspersky.com\/knowledge\/history-of-malicious-programs\/\">The history of malware<\/a> goes back to the days when the internet was not widely available. Although it was once spread via physical floppy disks, malware now can be found in everything from malicious emails and websites to compromised apps and image files.<\/p>\n\n\n\n<p>The <a href=\"https:\/\/www.av-test.org\/en\/statistics\/malware\/\">AV-TEST Institute<\/a> recorded the following increase in the number of malware and potentially unwanted applications in the last 10 years:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"634\" src=\"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-malwarebytes-2020-malware-threats-1024x634.png\" alt=\"A malware bar chart using data from AV-Test Institute for the article &quot;what is malware and what does it do?&quot;\" class=\"wp-image-7056\" srcset=\"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-malwarebytes-2020-malware-threats-1024x634.png 1024w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-malwarebytes-2020-malware-threats-300x186.png 300w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-malwarebytes-2020-malware-threats-768x475.png 768w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-malwarebytes-2020-malware-threats-1536x951.png 1536w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Chart showing the rise of malware in the past 10 years. Data source: <a href=\"https:\/\/www.av-test.org\/en\/statistics\/malware\/\">AV-TEST Institute<\/a>.<\/figcaption><\/figure>\n\n\n\n<p>As you can see in the graph, malware attacks have been on a constant rise. Malware increased 13.75% to 1139.24 in 2020 from 1001.52 in 2019. And the numbers for 2021 are even more alarming. Data on the number of malware attacks that occurred between Jan. 1 and June 7 have already surpassed the total number of attacks observed in 2020. And the year is still young\u2026 What the cumulative figure for 2021 will be, only time will tell. Till then, we can only take precautionary measures to stay safe.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Types of Malware and What They Do<\/h2>\n\n\n\n<p>Malwarebytes observed the top malware varieties in the <a href=\"https:\/\/www.malwarebytes.com\/resources\/files\/2021\/02\/mwb_stateofmalwarereport2021.pdf\">State of Malware Report 2021<\/a>: &nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"658\" src=\"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-av-test-institute-data-1024x658.png\" alt=\"A chart using data from Malwarebytes that showcases the top 10 types of malware threats to businesses\" class=\"wp-image-7058\" srcset=\"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-av-test-institute-data-1024x658.png 1024w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-av-test-institute-data-300x193.png 300w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-av-test-institute-data-768x494.png 768w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-av-test-institute-data-1536x988.png 1536w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Data source: Malwarebytes 2021 State of Malware Report.<\/figcaption><\/figure>\n\n\n\n<p>The influx of malware is so rampant that it\u2019s possible you may have undetected malware on your device right now and not know it. Criminals, nowadays, use a combination of two or more types of malware for a stronger attack. They also keep on changing their tactics often to achieve their goals without being detected. The following malware definitions and examples of malware can help you recognize a potential threat.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Adware<\/h3>\n\n\n\n<p>Adware is a type of malware that, once installed on your device (mobile or laptop), will display spam, phishing, or other malicious ads that will lure you to click on them. Sometimes adware contains other types of malware with or without the knowledge of the advertiser. When a person clicks on the ad, his computer might get infected with the malware hidden in the ad.<\/p>\n\n\n\n<p>2020 data from <a href=\"https:\/\/press.avast.com\/adware-accounts-for-72-of-all-mobile-malware\">Avast<\/a> called out adware as the most common type of malware for Android mobile devices. Adware represented 72% of the total malware on mobile devices they detected between October and December 2019.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ransomware<\/h3>\n\n\n\n<p>Ransomware is a nasty piece of malware that uses encryption to prevent legitimate users and companies from accessing their own data. Bad guys use this leverage to demand ransom payments (often in cryptocurrencies like Bitcoin or Ethereum). They do this by saying that if the target pays, they\u2019ll provide a decryption key. But there\u2019s no guarantee that the victim will actually receive the key \u2014 or that the key will work \u2014 even if they do make the payment.<\/p>\n\n\n\n<p>What makes matters worse is that in some cases, cybercriminals will use their access to exfiltrate the victim\u2019s data so they can leak it online, use it for other crimes, or sell it to others.<\/p>\n\n\n\n<p>In a recent event, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/foxconn-electronics-giant-hit-by-ransomware-34-million-ransom\/\">BleepigComputer<\/a> reported that the electronic manufacturing giant Foxconn was hit by a ransomware attack and the actors were demanding $34 million as ransom in Bitcoin payments. The criminals DoppelPaymer hit Foxconn over the Thanksgiving weekend of 2020. A strategically located company facility in Mexico was the target of the attack.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Rootkits<\/h3>\n\n\n\n<p>Rootkits are a set of tools or programs that can make administrative changes to a device at the kernel level. Some rootkits might be harmless, but some are malicious software programs that operate in the background. The latter are designed to work under-the-radar of your antivirus and anti-malware programs, which means they can go undetected for a long time.<\/p>\n\n\n\n<p><a href=\"https:\/\/securelist.com\/operation-tunnelsnake-and-moriya-rootkit\/101831\/\">Kaspersky researchers unveiled a previously unknown rootkit<\/a> they discovered was being used to control the networks of regional organizations. Called Moriya, this rootkit was used to create \u201cpassive backdoors on public-facing servers\u201d that allowed the devices to be silently controlled via C&amp;C communications.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Spyware and Keyloggers<\/h3>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/malwarebytes-spyware-monitor-apps-data.jpg\" alt=\"\" class=\"wp-image-7059\" width=\"395\" height=\"342\" srcset=\"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/malwarebytes-spyware-monitor-apps-data.jpg 1020w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/malwarebytes-spyware-monitor-apps-data-300x260.jpg 300w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/malwarebytes-spyware-monitor-apps-data-768x666.jpg 768w\" sizes=\"(max-width: 395px) 100vw, 395px\" \/><figcaption>Data source: Malwarebytes 2021 State of Malware Report.<\/figcaption><\/figure><\/div>\n\n\n\n<p>These types of software are very useful in surveillance without the knowledge of the subject. They can also be used for constructive (although questionable) purposes like keeping track of the activities of the employees during work hours. However, when cybercriminals use the same types of software with malicious intentions, it becomes malware.<\/p>\n\n\n\n<p>Malwarebytes categorizes keyloggers as \u201cMonitor\u201d apps. In their 2021 State of Malware Report, Malwarebytes reports the detection rates for monitor apps on Android mobile devices rose 565%, and that spyware surged 1,055% between January and December 2020.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Trojans<\/h3>\n\n\n\n<p>Trojans are fraudulent and dangerous malware that often reach your computer while disguised as a legitimate program or app. Cybercriminals create fraudulent versions of legitimate software to try to trick people into downloading their fake\/malicious version instead of the legitimate software. This type of malware gets its name from the Trojan horse of Greek mythology because of its subterfuge-like uses.<\/p>\n\n\n\n<p>Bad guys took advantage of the COVID-19 global pandemic by creating a fake COVID tracking application for Android devices. <a href=\"https:\/\/www.domaintools.com\/resources\/blog\/covidlock-mobile-coronavirus-tracking-app-coughs-up-ransomware\">Researchers at domaintools.com<\/a> report that although the app claimed to provide real-time tracking information about coronavirus outbreaks, it was really a Trojan and unleashed ransomware when downloaded on the device. A file locker malware \u201cCovidlock\u201d locked the files on your device when the app was downloaded. Allegedly, the ransom of $100 was demanded from all the victims.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Viruses<\/h3>\n\n\n\n<p>A virus is an example of malicious software that infects your device and spreads to your network devices. A virus requires a user to trigger or activate the program. Often virus is connected to a legitimate program and when you install the legitimate program, it is also installed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Worms<\/h3>\n\n\n\n<p>Although worms work in ways that are similar to viruses, they should not be confused with them. A virus requires some type of user interaction to activate it; worms, on the other hand, can be activated without such a trigger. They can also spread to the network of the victim without the knowledge or the help of the victim.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Common Methods of Malware Deployment of Malware<\/h2>\n\n\n\n<p>There are many ways that threat actors can get malware onto your device. Let\u2019s explore a few of them.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Phishing Campaigns<\/h3>\n\n\n\n<p>Cybercriminals use different communication methods to spread malware that they can use to steal your personal information. Here are a few quick examples:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Email phishing: <\/strong>Bad guys can use emails to send malicious file attachments or links to sites that contain malware.<\/li><li><strong>Vishing: <\/strong>Vishing, or voice phishing, is another tactic bad guys love to use. Cybercriminals sometimes use vishing (on its own or in combination with other tactics) to impersonate tech support companies. They use this ruse to trick users into visiting malicious websites or providing their email information, which the bad guys can use to send malware.<\/li><li><strong>Smishing: <\/strong>SMS phishing text messages are another way that bad guys love to share malware. They can do this by sending messages containing malicious code or sending links that direct users to visit malicious websites.<\/li><\/ul>\n\n\n\n<p>Check out our article on <a href=\"https:\/\/cheapsslsecurity.com\/blog\/how-to-prevent-phishing-emails-attacks-from-being-successful\/\">how to prevent phishing emails and attacks from being successful<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Fake or Compromised Websites<\/h3>\n\n\n\n<p>Cybercriminals create fake websites that look legitimate to trick users into clicking on them. When a victim clicks on the fake website, malware auto-downloads and installs onto their device without their knowledge. In some cases, bad guys opt to exploit vulnerabilities in legitimate websites and use those platforms to spread malware to those site\u2019s unsuspecting users.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Malvertisments<\/h3>\n\n\n\n<p>When online advertising is used for malicious purposes, it is called malvertising (short for \u201cmalicious advertising.\u201d). Malvertising is a fake ad that displays on legitimate websites to trick users into clicking on them. If a user clicks on a malicious ad (or, in some cases, simply views it), it\u2019ll download malware onto their device. This is different from adware, which is malware that gets installed onto your device to observe your behaviors and web searches to display targeted ads.<\/p>\n\n\n\n<p>Of course, there are plenty of other ways that bad guys deploy and spread malware. But these three are among the most common methods.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Is Malware &amp; What Does It Do? 4 Alarming Consequences of Successful Malware Attacks<\/h2>\n\n\n\n<p>A malware attack causes harm on multiple levels to the victims, either individual or enterprise. Let\u2019s consider the effects of a malware attack on a business organization:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Results in Data Exposure and Theft<\/h3>\n\n\n\n<p>In the words of <a href=\"https:\/\/ana.blogs.com\/maestros\/2006\/11\/data_is_the_new.html\">Clive Humby<\/a>, a British mathematician and entrepreneur: \u201cData is the new oil.\u201d As such, every organization should treat their data like their most valued assets. Everything from customers\u2019 names to their social security numbers are valuable pieces of data that cybercriminals want to get their hands on.<\/p>\n\n\n\n<p>IBM\u2019s 2020 Cost of a Data Breach report shows that malicious attacks were responsible for 52% of data breaches they analyzed that occurred between August 2019 and April 2020. Malware attacks can cause data breaches and be used to steal data that attackers can publish online, use to commit other types of crimes or sell to other bad guys to use as they choose.<\/p>\n\n\n\n<p>But how much are various types of data really worth? <a href=\"https:\/\/www.privacyaffairs.com\/dark-web-price-index-2021\/\">Privacy Affairs<\/a> shared the prices of stolen data on the dark web for 2021:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Item Category<\/strong><\/td><td><strong>Item Name<\/strong><\/td><td><strong>Average Sale Price<\/strong><\/td><\/tr><tr><td>Personal finance<\/td><td>Bank account login details for accounts that contain a minimum of $2,000<\/td><td>$120<\/td><\/tr><tr><td>&nbsp;<\/td><td>Verified U.S. user\u2019s LocalBitcoins account<\/td><td>$350<\/td><\/tr><tr><td>&nbsp;<\/td><td>PayPal login details for accounts that have a balance of up to $1,000<\/td><td>$120<\/td><\/tr><tr><td>Personal Identification (stolen real IDs or forged)<\/td><td>Legitimate Russian Passport scan<\/td><td>$100<\/td><\/tr><tr><td>&nbsp;<\/td><td>Legitimate Canadian (Alberta) driver\u2019s license scan<\/td><td>$32<\/td><\/tr><tr><td>&nbsp;<\/td><td>Valid U.S. social security number<\/td><td>$2<\/td><\/tr><tr><td>Social media accounts<\/td><td>Hacked Facebook account<\/td><td>$65<\/td><\/tr><tr><td>&nbsp;<\/td><td>Hacked Gmail account<\/td><td>$80<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">2. Causes Financial Losses<\/h3>\n\n\n\n<p><a href=\"https:\/\/www.ibm.com\/security\/data-breach\">IBM<\/a> reports that the average cost of a data breach for businesses globally amounted to $3.86 million in 2020. In the United States, these costs soared to $8.64 million in the same period, making it the most expensive country. Their data shows that the average cost of \u201cdestructive malware\u201d was $4.52 million and $4.44 million for ransomware. This is more than the average cost of a malicious attack, which they put at $4.27 million.<\/p>\n\n\n\n<p>According to the same report, IBM found that healthcare was the most expensive industry with an average loss of $7.13 million for a data breach. If this was not enough, one in five companies that suffered malicious data breaches was infiltrated with stolen credentials that increased the loss further. &nbsp;<\/p>\n\n\n\n<p>Financial repercussions of data breaches can deal substantial blows to businesses in direct and indirect costs. The following figure shows the average breakdown of costs due to a data breach.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"621\" src=\"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/cost-of-a-data-breach-ibm-2020-data-1024x621.png\" alt=\"A pie chart of data from IBM's Cost of a Data Breach 2020 report that breaks down the cost of an average data breach.\" class=\"wp-image-7060\" srcset=\"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/cost-of-a-data-breach-ibm-2020-data-1024x621.png 1024w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/cost-of-a-data-breach-ibm-2020-data-300x182.png 300w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/cost-of-a-data-breach-ibm-2020-data-768x466.png 768w, https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/cost-of-a-data-breach-ibm-2020-data-1536x932.png 1536w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Chart showing the breakdown of the average costs relating to a data breach. Data source: <a href=\"https:\/\/www.ibm.com\/downloads\/cas\/RZAX14GX\">IBM<\/a><\/figcaption><\/figure>\n\n\n\n<p>Chart showing the segregation of cost of a data breach. Data source: <a href=\"https:\/\/www.ibm.com\/downloads\/cas\/RZAX14GX\">IBM&#8217;s Cost of a Data Breach Report 2020<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Damages Your Brand and Reputation<\/h3>\n\n\n\n<p>\u201cIt takes 20 years to build a reputation and few minutes of cyber-incident to ruin it.\u201d\u2015 <a href=\"https:\/\/ieeexplore.ieee.org\/document\/8929691\">Stephane Nappo<\/a>, Vice President of GroupeSEB.<\/p>\n\n\n\n<p>In the wake of a data breach or a malware attack, every business or organization must deal with one of the most damaging factors: the loss of their reputation and standing within the industry. Contrary to the financial liability damages, which an insurance company can cover (depending on your insurance), the damage to your reputation is sometimes irreversible. It might take years for a company to nullify the reputation damage caused by a malware attack.<\/p>\n\n\n\n<p>The worst part is the loss of customer trust. Considering that IBM\u2019s 2020 data breach data shows that it takes an average of 280 days for companies to detect and contain data breaches, and that 80% of breaches involve customers\u2019 personally identifiable information, it\u2019s no wonder why your reputation can take a hit with customers.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. Creates Noncompliance Issues That Result in Penalties<\/h3>\n\n\n\n<p>There are government and non-government bodies that specify the rules and regulations that organizations within specific industries or regions must abide by. The business enterprise is obligated to follow and to file the proof of following the compliance procedures from time to time.<\/p>\n\n\n\n<p>Specific compliance requirements are based on a variety of factors. When a business falls prey to a malware attack, it must pay the penalties and the fines laid out by the governing bodies. These fines are in addition to the detection and other expenses to be borne by the enterprise. Some of the governing bodies and their relevance are mentioned below:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">GDPR (General Data Protection Regulation)<\/h4>\n\n\n\n<p><a href=\"https:\/\/gdpr-info.eu\/\">GDPR<\/a> is applicable to the entities operating in the European Union (EU) for the protection of data and privacy in the EU and the EEA (European Economic Area). The GDPR has regulations on the processing of personal data of the people on a legal basis. The data subject must provide consent to data processing for one or more purposes in order for them to use their data.<\/p>\n\n\n\n<p>If a company violates GDPR, they may be subjected to heavy penalties. Many companies have been sued under GDPR for processing the data without permission or with \u201cforced permission\u201d including WhatsApp, Instagram, Facebook, Apple, Microsoft, and Google LLC.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">California Consumer Privacy Act (CCPA) of 2018<\/h4>\n\n\n\n<p>The <a href=\"https:\/\/oag.ca.gov\/privacy\/ccpa\">California Consumer Privacy A<\/a>ct aims to protect the privacy of California residents. The legislation applies to every business that collects the personal data of CA consumers (regardless of whether the company is located within California) and fulfills one or more conditions:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Has annual gross revenue that exceeds $25 million;<\/li><li>Buys, receives, or sells the personal data of at least 50,000 consumers, households or devices; or<\/li><li>Earns more than half of its annual revenue from selling consumers\u2019 personal data.<\/li><\/ul>\n\n\n\n<p>&nbsp;Although consumers typically can\u2019t sue under the CCPA (in most cases), statutory damages are to be paid in case of violation:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The companies falling prey to a data breach\/theft must pay $100 to $750 per incident, per California resident, or the actual damages, whichever is higher. The court may ask the company to pay any other relief as it may deem fit.<\/li><li>A fine of $7,500 in case of an intentional violation and $2,500 in case of an unintentional violation.<\/li><\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">Payment Card Industry Data Security Standard (PCI DSS)<\/h4>\n\n\n\n<p><a href=\"https:\/\/www.pcisecuritystandards.org\/pci_security\/maintaining_payment_security\">PCI DSS<\/a> is the information security set of standards that all organizations and companies globally that handle credit card data must abide by. The PCI standards must be followed by all the companies that accept online payment and process consumers&#8217; credit card details. In case of a data breach, the council will levy penalties on the company. Even if the data breach is due to a malicious attack, the victim company is liable to pay the penalties.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Final Words on Malware<\/h2>\n\n\n\n<p>Malicious software or malware causes losses both financial and non-financial losses to businesses and organizations. There are insurance policies available that may be able to mitigate your financial losses to a certain extent, but your organization and the trust your customers have in it are still going to suffer as a result.<\/p>\n\n\n\n<p>The only way to minimize the chances of incurring all these losses is by doing everything in your power to prevent a cyber attack. This includes educating your employees and taking the necessary steps to <a href=\"https:\/\/cheapsslsecurity.com\/blog\/how-to-prevent-malware-attacks\/\">prevent malware attacks<\/a> from being successful.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>AV-TEST Institute registers more than 350,000 new malware and potentially unwanted applications (PUAs) daily. The sheer number of new malware is enough to make you shiver \u2014 so long as you understand what \u201cmalware\u201d entails. But what is malware and what does it do? Let\u2019s explore malware definition and meaning Malware is a threat that<\/p>\n","protected":false},"author":8,"featured_media":7062,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[417],"tags":[421,450,457],"class_list":{"0":"post-7055","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cybersecurity","8":"tag-featured","9":"tag-malware","10":"tag-what-is-malware"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What Is Malware and What Does It Do? A Malware Definition<\/title>\n<meta name=\"description\" content=\"What is malware? We&#039;ll explore everything to know about malware definition and meaning before diving into the consequences of these threats.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What Is Malware and What Does It Do? A Malware Definition\" \/>\n<meta property=\"og:description\" content=\"What is malware? We&#039;ll explore everything to know about malware definition and meaning before diving into the consequences of these threats.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/\" \/>\n<meta property=\"og:site_name\" content=\"Savvy Security\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/cheapsslsecurities\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-21T21:37:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-07-19T23:52:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-and-what-does-it-do.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Savvy Security\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@sslsecurity\" \/>\n<meta name=\"twitter:site\" content=\"@sslsecurity\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Savvy Security\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/what-is-malware-and-what-does-it-do\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/what-is-malware-and-what-does-it-do\\\/\"},\"author\":{\"name\":\"Savvy Security\",\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/#\\\/schema\\\/person\\\/1ce9a5743b7f25b5be6e4972864b4493\"},\"headline\":\"What Is Malware and What Does It Do? A Malware Definition\",\"datePublished\":\"2021-06-21T21:37:57+00:00\",\"dateModified\":\"2021-07-19T23:52:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/what-is-malware-and-what-does-it-do\\\/\"},\"wordCount\":2708,\"image\":{\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/what-is-malware-and-what-does-it-do\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/what-is-malware-and-what-does-it-do.jpg\",\"keywords\":[\"featured\",\"Malware\",\"What is Malware\"],\"articleSection\":[\"SMB Cybersecurity\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/what-is-malware-and-what-does-it-do\\\/\",\"url\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/what-is-malware-and-what-does-it-do\\\/\",\"name\":\"What Is Malware and What Does It Do? A Malware Definition\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/what-is-malware-and-what-does-it-do\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/what-is-malware-and-what-does-it-do\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/what-is-malware-and-what-does-it-do.jpg\",\"datePublished\":\"2021-06-21T21:37:57+00:00\",\"dateModified\":\"2021-07-19T23:52:08+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/#\\\/schema\\\/person\\\/1ce9a5743b7f25b5be6e4972864b4493\"},\"description\":\"What is malware? We'll explore everything to know about malware definition and meaning before diving into the consequences of these threats.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/what-is-malware-and-what-does-it-do\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/what-is-malware-and-what-does-it-do\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/what-is-malware-and-what-does-it-do\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/what-is-malware-and-what-does-it-do.jpg\",\"contentUrl\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/what-is-malware-and-what-does-it-do.jpg\",\"width\":1600,\"height\":1000},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/what-is-malware-and-what-does-it-do\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What Is Malware and What Does It Do? A Malware Definition\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/\",\"name\":\"Savvy Security\",\"description\":\"Practical cybersecurity advice\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/#\\\/schema\\\/person\\\/1ce9a5743b7f25b5be6e4972864b4493\",\"name\":\"Savvy Security\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4e5539150b16b5af1d22136f03dedda89a96babb3e9b5ceb18c2bde4e1dcba57?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4e5539150b16b5af1d22136f03dedda89a96babb3e9b5ceb18c2bde4e1dcba57?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4e5539150b16b5af1d22136f03dedda89a96babb3e9b5ceb18c2bde4e1dcba57?s=96&d=mm&r=g\",\"caption\":\"Savvy Security\"},\"description\":\"Welcome to Savvy Security, a blog focused on providing practical cybersecurity advice for website owners and small businesses. Our team brings you the latest news, best practices and tips you can use to protect your business...without a multi-million dollar budget or 24\\\/7 security teams.\",\"sameAs\":[\"blogadmin\"],\"url\":\"https:\\\/\\\/cheapsslsecurity.com\\\/blog\\\/author\\\/blogadmin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What Is Malware and What Does It Do? A Malware Definition","description":"What is malware? We'll explore everything to know about malware definition and meaning before diving into the consequences of these threats.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/","og_locale":"en_US","og_type":"article","og_title":"What Is Malware and What Does It Do? A Malware Definition","og_description":"What is malware? We'll explore everything to know about malware definition and meaning before diving into the consequences of these threats.","og_url":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/","og_site_name":"Savvy Security","article_publisher":"https:\/\/www.facebook.com\/cheapsslsecurities","article_published_time":"2021-06-21T21:37:57+00:00","article_modified_time":"2021-07-19T23:52:08+00:00","og_image":[{"width":1600,"height":1000,"url":"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-and-what-does-it-do.jpg","type":"image\/jpeg"}],"author":"Savvy Security","twitter_card":"summary_large_image","twitter_creator":"@sslsecurity","twitter_site":"@sslsecurity","twitter_misc":{"Written by":"Savvy Security","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/#article","isPartOf":{"@id":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/"},"author":{"name":"Savvy Security","@id":"https:\/\/cheapsslsecurity.com\/blog\/#\/schema\/person\/1ce9a5743b7f25b5be6e4972864b4493"},"headline":"What Is Malware and What Does It Do? A Malware Definition","datePublished":"2021-06-21T21:37:57+00:00","dateModified":"2021-07-19T23:52:08+00:00","mainEntityOfPage":{"@id":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/"},"wordCount":2708,"image":{"@id":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/#primaryimage"},"thumbnailUrl":"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-and-what-does-it-do.jpg","keywords":["featured","Malware","What is Malware"],"articleSection":["SMB Cybersecurity"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/","url":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/","name":"What Is Malware and What Does It Do? A Malware Definition","isPartOf":{"@id":"https:\/\/cheapsslsecurity.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/#primaryimage"},"image":{"@id":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/#primaryimage"},"thumbnailUrl":"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-and-what-does-it-do.jpg","datePublished":"2021-06-21T21:37:57+00:00","dateModified":"2021-07-19T23:52:08+00:00","author":{"@id":"https:\/\/cheapsslsecurity.com\/blog\/#\/schema\/person\/1ce9a5743b7f25b5be6e4972864b4493"},"description":"What is malware? We'll explore everything to know about malware definition and meaning before diving into the consequences of these threats.","breadcrumb":{"@id":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/#primaryimage","url":"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-and-what-does-it-do.jpg","contentUrl":"https:\/\/cheapsslsecurity.com\/blog\/wp-content\/uploads\/2021\/06\/what-is-malware-and-what-does-it-do.jpg","width":1600,"height":1000},{"@type":"BreadcrumbList","@id":"https:\/\/cheapsslsecurity.com\/blog\/what-is-malware-and-what-does-it-do\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cheapsslsecurity.com\/blog\/"},{"@type":"ListItem","position":2,"name":"What Is Malware and What Does It Do? A Malware Definition"}]},{"@type":"WebSite","@id":"https:\/\/cheapsslsecurity.com\/blog\/#website","url":"https:\/\/cheapsslsecurity.com\/blog\/","name":"Savvy Security","description":"Practical cybersecurity advice","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cheapsslsecurity.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/cheapsslsecurity.com\/blog\/#\/schema\/person\/1ce9a5743b7f25b5be6e4972864b4493","name":"Savvy Security","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4e5539150b16b5af1d22136f03dedda89a96babb3e9b5ceb18c2bde4e1dcba57?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4e5539150b16b5af1d22136f03dedda89a96babb3e9b5ceb18c2bde4e1dcba57?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4e5539150b16b5af1d22136f03dedda89a96babb3e9b5ceb18c2bde4e1dcba57?s=96&d=mm&r=g","caption":"Savvy Security"},"description":"Welcome to Savvy Security, a blog focused on providing practical cybersecurity advice for website owners and small businesses. Our team brings you the latest news, best practices and tips you can use to protect your business...without a multi-million dollar budget or 24\/7 security teams.","sameAs":["blogadmin"],"url":"https:\/\/cheapsslsecurity.com\/blog\/author\/blogadmin\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/cheapsslsecurity.com\/blog\/wp-json\/wp\/v2\/posts\/7055","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cheapsslsecurity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cheapsslsecurity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cheapsslsecurity.com\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/cheapsslsecurity.com\/blog\/wp-json\/wp\/v2\/comments?post=7055"}],"version-history":[{"count":0,"href":"https:\/\/cheapsslsecurity.com\/blog\/wp-json\/wp\/v2\/posts\/7055\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cheapsslsecurity.com\/blog\/wp-json\/wp\/v2\/media\/7062"}],"wp:attachment":[{"href":"https:\/\/cheapsslsecurity.com\/blog\/wp-json\/wp\/v2\/media?parent=7055"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cheapsslsecurity.com\/blog\/wp-json\/wp\/v2\/categories?post=7055"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cheapsslsecurity.com\/blog\/wp-json\/wp\/v2\/tags?post=7055"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}