ALL PASS, NO FAIL!

CEH v13 Module 7: Malware Threats

This module covers the various types of malicious software used by attackers, including viruses, worms, trojans, ransomware, spyware, rootkits, fileless malware, and polymorphic threats. Understanding these threats is critical for both offensive and defensive security professionals.

The CEHStudy app carries 28 flashcards for Module 7 across 4 sections — the malware-overview section is the largest; clear it first, then drill advanced types, APT and botnets, and finish with analysis.

Key Topics Covered

Important Terms & Concepts

Virus: Malicious code that attaches itself to legitimate programs and requires human action (executing an infected file) to spread. Types: file infector, polymorphic, encryption, multipartite.
Worm: Self-replicating malware that spreads across networks without user interaction. Unlike viruses, worms do not need a host program (e.g., Conficker, WannaCry worm component).
Trojan (RAT): Malicious software disguised as legitimate. Remote Access Trojan (RAT) gives attackers full remote control: keylogging, screen capture, file access.
Ransomware: Encrypts victim's files and demands payment. Crypto-ransomware encrypts files. Scareware tricks users with fake alerts. Locker ransomware blocks system access.
Rootkit: Software that hides malware presence by intercepting OS calls at the kernel level. Can be user-mode or kernel-level. Detected via behavioral analysis and specialized tools (GMER, RootkitRevealer).
Fileless Malware: Operates entirely in memory without writing to disk. Uses legitimate tools like PowerShell and WMI. Extremely difficult to detect by traditional antivirus.
Polymorphic Malware: Changes its code/signature on each infection using encryption and mutation engines to evade signature-based detection. The decryptor stub remains constant.

How to Study This Module

Frequently Asked Questions

What is the difference between a virus and a worm?
A virus requires a host program and human action to spread. A worm is self-contained and replicates independently across networks without user interaction.

What is fileless malware?
Malware that operates entirely in memory without writing files to disk. It uses legitimate system tools (PowerShell, WMI) making it nearly invisible to traditional antivirus solutions.

Related Modules

What are Malware Threats in Ethical Hacking?

Malware Threats is a critical domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers the full taxonomy of malicious software — from legacy viruses and worms to APT campaigns, fileless threats and double extortion ransomware. The exam emphasizes distinguishing malware types by propagation mechanism (host-based vs network-based), persistence technique and evasion strategy. Module 7 accounts for approximately 10% of CEH v13 exam questions.

Key Concepts in Malware Threats

Common Exam Mistakes in Module 7

Conflating virus, worm, and trojan: the exam's pivot question is always "who does the replicating?" A virus attaches to a host file and needs human action to spread; a worm is standalone and self-replicates across networks with no user interaction; a trojan disguises itself as legitimate software but never self-replicates. Get that triangle right and most classification questions solve themselves.
Calling polymorphic malware metamorphic: polymorphic strains mutate their signature through a mutation engine while keeping the same underlying algorithm; metamorphic engines rewrite the entire code structure on every infection — same function, different code — making metamorphic the harder-to-detect answer.
Assuming "fileless" means undetectable: fileless malware still leaves footprints — it just writes no files to disk. It lives in memory using legitimate binaries (PowerShell encoded commands, WMI event subscriptions), so detection moves from disk signatures to process behavior, in-memory analysis and encoded/script-based execution monitoring.

Tools Used in Malware Threats

Analysis tooling the CEH v13 exam references for this domain, by job:

Worked Example: Triage of a Suspicious Executable

An endpoint alert hands you an unknown .exe. First, hash it (MD5 and SHA-256) and check VirusTotal without executing anything on a production machine. Static stage: inspect the PE header, run strings for URLs and registry keys, and use PEiD to see whether it is packed — a packed binary tells you disassembly needs an unpacking step first.

Then go dynamic: in an isolated sandbox with no internet access (or a controlled lab network), let the sample run and watch what it does — dropped files, new scheduled tasks, registry persistence keys, outbound connections to an IP that resolves to nothing. Correlate with YARA rules against known families; if behavior is purely in-memory, capture the sandbox host's RAM for a Volatility pass before shutting down.

How to Study Malware Threats for the CEH v13 Exam

To study Module 7:

  1. Create a comparison table of all malware types: virus (needs host + human), worm (self-replicating, no host), trojan (disguised, no replication), ransomware (cryptoware/extortion), rootkit (hiding), spyware (data theft) — the exam frequently asks you to classify a described behavior
  2. Know the APT kill chain stages and map specific TTPs to the correct stage — a high-frequency question format
  3. Hands-on: download a safe sample from Malware-Traffic-Analysis.net, analyze it in ANY.RUN (free tier), document network connections, file modifications and registry changes, then write a YARA rule for the indicators you observed
  4. Review Module 6 (System Hacking) — initial access enables malware deployment — and Module 12 (Evading IDS) — how APT malware evades detection

Frequently Asked Questions About Malware Threats

What is the difference between static and dynamic malware analysis on the CEH exam?

Static analysis examines the binary without executing it — PE headers, import tables, strings, sections, disassembled code. Safer (no execution risk) but defeatable by packing, encryption or polymorphism. Dynamic analysis executes the sample in a sandbox and observes runtime behavior: network connections, files created/modified, registry keys added, processes spawned, API calls. The correct approach is always static first (safe triage), then dynamic (behavioral confirmation). Never run dynamic analysis without a sandbox — malware can activate anti-analysis routines if it detects debugging or VMs.

How do polymorphic and metamorphic malware differ?

Polymorphic malware encrypts its payload with a different key each time it replicates — a different encrypted body per infection — but the decryption stub remains constant, keeping it detectable by signature. Metamorphic malware rewrites its entire code on each replication (instruction substitution, register reassignment, dead code insertion) with no encryption stub; every copy is structurally different. Key distinction: polymorphic = encrypted body + constant stub; metamorphic = fully rewritten code with no constant component. Both defeat signature-based detection, but metamorphic is harder to catch even with behavioral analysis.

Related CEH v13 Modules

Related Glossary Terms