Malware vs Virus. What’s the Difference?

Malware vs Virus. What’s the Difference?

Malware and viruses. We all heard these two cybersecurity-related terms, and people often use them interchangeably. Is such use legitimate? Let us delve into the terminology of harmful software to judge the malware vs. virus semantic dispute.

Malware is a more general concept encompassing all software written to harm targeted computers, networks, data, or users (the latter – via blackmail, spying, racketeering, etc.) A computer virus is just a type of malware, which is, by the way, not that spread nowadays. However, since the history of malicious software began with the viruses, and no other word from the known vocabulary matched their nature better, all future malware got vilified as “viruses.”

CONSIDER READING: Network security in a nutshell. That’s how you protect your workgroup.

What is a computer virus?

Computer viruses per se are pieces of code that, being added to harmless programs (or data files), contain instructions to self-replicate and harm the system where they reside (although the latter is not necessary). The viruses’ main distinctive feature is that they need a vehicle, a host. Executables and data files usually play this role. The viruses can also exist not in files in a strict sense. For example, they can incrust themselves within the boot sector or any list of commands for a processor to execute.

Creators of viruses back in the ’80s designed their brainchildren to spread from file to file and then, logically, from computer to computer via floppy disks. Viruses occasionally travel as email attachments, but some viruses spread via the Internet specifically. That means they “know” what email is, and “to send the virus-infected file by email” is a part of the instruction to the contaminated computer they contain. Ironically, the first virus transferred from one machine to another was created in the early ’70s and was spread remotely via the ARPANET, not on a floppy drive!

The main difference between viruses and other malware is that the former are not separate files (worms and Trojans are). Viruses are pieces of code, and they either use files as vehicles or integrate with non-file records (see boot sector viruses). Viruses and worms do self-replicate, while Trojans don’t.

Internet worms are separate-file agents that self-replicate and spread themselves via the Internet. Viruses are self-replicating pieces of code, while Trojans are files that don’t self-replicate.

CONSIDER READING: Windows 11 Security Approach: Zero-Trust Juggernaut Launched.

Conceptual mess

Although professionals always told viruses from worms and Trojans, the three being the types of malware classified by the method of spreading, popular culture inherited the term “virus” and applied it to all the variety of computer malware. As computers became widespread, and so did the malware, it became clear that average users were experiencing a conceptual mess regarding harmful software. That is so not without reason. On the one hand, there are some strict definitions in malware taxonomy, but on the other hand, there are also some optional and non-scientific terms, and they are all mixed up. So are the criteria of classification. People may think that you can put, for example, “malware,” “ransomware,” and “Trojan,” on a par and that the object in question is either “ransomware” or “Trojan.” In reality, there is a lot of malware describable as ransomware by function and a Trojan by delivery method.

Marcus Vance
Author

Marcus Vance

Marcus Vance is a cybersecurity auditor and technology writer dedicated to educating the public about online safety, data privacy regulations, enterprise security, and emerging cyber threats.