This module covers the various types of malicious software used by attackers, including viruses, worms, trojans, ransomware, spyware, rootkits, fileless malware, and polymorphic threats. Understanding these threats is critical for both offensive and defensive security professionals.
The CEHStudy app carries 28 flashcards for Module 7 across 4 sections — the malware-overview section is the largest; clear it first, then drill advanced types, APT and botnets, and finish with analysis.
Key Topics Covered
Virus vs worm differences: file infection vs self-replication across networks
Malware analysis methods: static vs dynamic analysis, sandboxing
Important Terms & Concepts
Virus: Malicious code that attaches itself to legitimate programs and requires human action (executing an infected file) to spread. Types: file infector, polymorphic, encryption, multipartite.
Worm: Self-replicating malware that spreads across networks without user interaction. Unlike viruses, worms do not need a host program (e.g., Conficker, WannaCry worm component).
Ransomware: Encrypts victim's files and demands payment. Crypto-ransomware encrypts files. Scareware tricks users with fake alerts. Locker ransomware blocks system access.
Rootkit: Software that hides malware presence by intercepting OS calls at the kernel level. Can be user-mode or kernel-level. Detected via behavioral analysis and specialized tools (GMER, RootkitRevealer).
Fileless Malware: Operates entirely in memory without writing to disk. Uses legitimate tools like PowerShell and WMI. Extremely difficult to detect by traditional antivirus.
Polymorphic Malware: Changes its code/signature on each infection using encryption and mutation engines to evade signature-based detection. The decryptor stub remains constant.
How to Study This Module
Understand the key differences between viruses, worms, and trojans
Know each malware type's characteristics, infection methods, and detection techniques
Memorize ransomware variants and their specific behaviors
Understand fileless malware techniques — a major topic in CEH v13
Frequently Asked Questions
What is the difference between a virus and a worm? A virus requires a host program and human action to spread. A worm is self-contained and replicates independently across networks without user interaction.
What is fileless malware? Malware that operates entirely in memory without writing files to disk. It uses legitimate system tools (PowerShell, WMI) making it nearly invisible to traditional antivirus solutions.
Module 8: Sniffing — malware can be used to capture network traffic for sniffing
What are Malware Threats in Ethical Hacking?
Malware Threats is a critical domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers the full taxonomy of malicious software — from legacy viruses and worms to APT campaigns, fileless threats and double extortion ransomware. The exam emphasizes distinguishing malware types by propagation mechanism (host-based vs network-based), persistence technique and evasion strategy. Module 7 accounts for approximately 10% of CEH v13 exam questions.
Key Concepts in Malware Threats
APT Campaign Lifecycle: Advanced Persistent Threat campaigns follow a structured kill chain: reconnaissance → weaponization → delivery → exploitation → installation → C2 → actions on objectives. Unlike opportunistic malware, APTs are targeted, resource-intensive and maintained over months or years by nation-state or criminal actors. Know which kill-chain stage a given TTP (Tactic, Technique, Procedure) belongs to and how each stage can be detected.
Botnet C2 Architecture: Botnets are networks of compromised machines controlled by a central command-and-control server. Modern botnets use DGA (Domain Generation Algorithms) to create thousands of fallback domains, so blocking some still leaves reconnection paths. C2 has evolved from IRC to HTTP(S)-based beacons with encrypted payloads and DNS tunneling. Know the detection indicators: regular-interval beaconing, anomalous outbound connections, DGA domain resolution patterns.
Ransomware Evolution & Double Extortion: Ransomware has evolved from simple file lockers to double extortion attacks that exfiltrate data before encryption, creating two payment demands. Modern operations run as RaaS (Ransomware-as-a-Service): developers provide the toolkit, affiliates handle targeting. Backups alone are insufficient — egress filtering, DLP and network segmentation are equally critical.
Fileless & Living-off-the-Land Malware: Fileless malware executes entirely in memory using legitimate system tools (PowerShell, WMI, CertUtil, MSHTA.exe) without dropping executable files to disk, making signature-based antivirus nearly useless. Detection requires behavioral monitoring: anomalous PowerShell commands, encoded parameters, WMI event subscriptions, process injection patterns. Expect LOLBin (Living Off-the-Land Binary) identification in scenarios.
Common Exam Mistakes in Module 7
Conflating virus, worm, and trojan: the exam's pivot question is always "who does the replicating?" A virus attaches to a host file and needs human action to spread; a worm is standalone and self-replicates across networks with no user interaction; a trojan disguises itself as legitimate software but never self-replicates. Get that triangle right and most classification questions solve themselves.
Calling polymorphic malware metamorphic: polymorphic strains mutate their signature through a mutation engine while keeping the same underlying algorithm; metamorphic engines rewrite the entire code structure on every infection — same function, different code — making metamorphic the harder-to-detect answer.
Assuming "fileless" means undetectable: fileless malware still leaves footprints — it just writes no files to disk. It lives in memory using legitimate binaries (PowerShell encoded commands, WMI event subscriptions), so detection moves from disk signatures to process behavior, in-memory analysis and encoded/script-based execution monitoring.
Tools Used in Malware Threats
Analysis tooling the CEH v13 exam references for this domain, by job:
Ghidra / IDA Pro: disassemblers and decompilers for static analysis — Ghidra is the free NSA-published option, IDA Pro the commercial workhorse
PEiD / strings / exiftool: the quick static triad — packer ID, embedded string extraction, metadata inspection before anything runs
Cuckoo / ANY.RUN / Joe Sandbox: dynamic sandboxes that run the sample in isolation and capture file drops, registry edits, process trees and outbound traffic
OllyDbg / x64dbg / GDB: step-through debuggers for dynamic analysis — OllyDbg and x64dbg on Windows (32- and 64-bit), GDB on Linux
YARA: pattern-based identification with custom detection rules, used to confirm a sample belongs to a known family
VirusTotal: multi-engine scanning plus threat-intel context before investing in hands-on analysis
Wireshark / TCPView with Process Monitor and API Monitor: the sandbox observation layer — C2 traffic on the wire plus per-process file, registry and API activity
Volatility: memory-forensics framework for analyzing RAM captures — essential when the sample is fileless or a rootkit is hiding kernel objects
Worked Example: Triage of a Suspicious Executable
An endpoint alert hands you an unknown .exe. First, hash it (MD5 and SHA-256) and check VirusTotal without executing anything on a production machine. Static stage: inspect the PE header, run strings for URLs and registry keys, and use PEiD to see whether it is packed — a packed binary tells you disassembly needs an unpacking step first.
Then go dynamic: in an isolated sandbox with no internet access (or a controlled lab network), let the sample run and watch what it does — dropped files, new scheduled tasks, registry persistence keys, outbound connections to an IP that resolves to nothing. Correlate with YARA rules against known families; if behavior is purely in-memory, capture the sandbox host's RAM for a Volatility pass before shutting down.
How to Study Malware Threats for the CEH v13 Exam
To study Module 7:
Create a comparison table of all malware types: virus (needs host + human), worm (self-replicating, no host), trojan (disguised, no replication), ransomware (cryptoware/extortion), rootkit (hiding), spyware (data theft) — the exam frequently asks you to classify a described behavior
Know the APT kill chain stages and map specific TTPs to the correct stage — a high-frequency question format
Hands-on: download a safe sample from Malware-Traffic-Analysis.net, analyze it in ANY.RUN (free tier), document network connections, file modifications and registry changes, then write a YARA rule for the indicators you observed
What is the difference between static and dynamic malware analysis on the CEH exam?
Static analysis examines the binary without executing it — PE headers, import tables, strings, sections, disassembled code. Safer (no execution risk) but defeatable by packing, encryption or polymorphism. Dynamic analysis executes the sample in a sandbox and observes runtime behavior: network connections, files created/modified, registry keys added, processes spawned, API calls. The correct approach is always static first (safe triage), then dynamic (behavioral confirmation). Never run dynamic analysis without a sandbox — malware can activate anti-analysis routines if it detects debugging or VMs.
How do polymorphic and metamorphic malware differ?
Polymorphic malware encrypts its payload with a different key each time it replicates — a different encrypted body per infection — but the decryption stub remains constant, keeping it detectable by signature. Metamorphic malware rewrites its entire code on each replication (instruction substitution, register reassignment, dead code insertion) with no encryption stub; every copy is structurally different. Key distinction: polymorphic = encrypted body + constant stub; metamorphic = fully rewritten code with no constant component. Both defeat signature-based detection, but metamorphic is harder to catch even with behavioral analysis.