Protect your organization from malware - ITSAP.00.057

 

Malware, also known as malicious software, is used by threat actors to compromise networks, systems and devices. When malware infects an organization, threat actors may be able to gain access to sensitive information, monitor activity and disrupt operations.

This publication outlines common types of malware, the warning signs of an infected device and the steps to take when a device is compromised. It also provides practical tips to help protect your organization from future threats.

On this page

How malware is introduced

Malware can enter a network, system or device through vulnerabilities or risky actions. The following examples highlight common ways in which users might inadvertently introduce malware into systems and devices.

Downloads and files

  • Opening malicious email attachments
  • Downloading software, apps or updates from untrusted sources
  • Downloading or sharing files through peer-to-peer or unofficial file-sharing platforms
  • Connecting unverified or unscanned removable media (for example, USBs or external drives)

Browsing and access

  • Clicking deceptive pop-ups, ads or fake warnings
  • Installing unauthorized browser extensions or toolbars
  • Visiting unsafe or compromised websites
  • Using unsecured or untrusted Wi-Fi networks

Device and account security

  • Using outdated, unsupported or unpatched software or devices
  • Using weak, default or reused passwords

Malware types and behaviour

Malware appears in many forms, each designed to exploit systems in different ways. Understanding the different types of malware can help you detect malicious activity early and respond with confidence. Malware can be described by how it spreads and what it does once it is running. A single attack may involve more than one method and more than one capability.

How malware spreads

Malware can spread through different techniques that allow it to install itself and move between systems or networks. The types below describe how malware gains access and propagates.

  • Trojan horse: disguises itself as harmless software to persuade users to install it, enabling unauthorized access or harmful actions
  • Virus: infects files and spreads to other systems through user actions, such as opening or sharing infected files
  • Worm: executes independently and self-replicates, usually through network connections, to cause damage such as deleting files, sending unauthorized emails or taking up bandwidth

What malware can do

Once malware is running, it may perform a range of harmful actions that affect systems, data or users. The malware types below describe the impact or effects of malware on infected devices.

  • Adware: tracks Internet activity to deliver targeted pop-up advertisements
    • it is often installed without user consent through bundled software or malicious websites
    • it may redirect browsing traffic or collect user data
  • Browser hijacker: manipulates browser settings to redirect users to unwanted websites or ads, often changing the homepage, modifying search defaults or adding unauthorized toolbars
  • Botnet: connects a network of infected devices (called "bots" or "zombies")
  • Cryptojacking: hijacks a device's processing power to mine cryptocurrency without the owner's knowledge, often causing significant slowdowns and overheating
  • Logic bomb: triggers malicious actions on a system when specific conditions are met, such as a particular date, time or user action, and often remains hidden until activated
  • Rootkit: grants hidden access to networks, systems or devices by masking itself as a legitimate operating system (OS) component.
    • it frequently embeds itself deep within OS components or firmware to avoid detection
  • Ransomware: denies access to data or systems, typically by encrypting data and withholding the decryption keys until payment is made to the threat actor
  • Spyware: designed to monitor user activity and collect sensitive information, including browsing data, login details or personal information. Common types of spyware include:
    • information stealers: extract sensitive data from a device, including user credentials, browser history, browser session cookies and tokens, autofill information such as saved payment card details, communication logs, documents, system information, and even screenshots
    • keyloggers: capture and record keystrokes so threat actors can obtain sensitive information such as passwords, personal data or financial information
      • they often operate within the OS or within keyboard input software to collect this information discreetly
  • VPNfilter: compromises routers to allow threat actors to intercept traffic, harvest information, exploit connected systems and disrupt or manipulate network traffic
  • Wiper: destroys data by permanently erasing, overwriting or corrupting files and system components, often rendering devices inoperable and leaving little or no chance of recovery

How artificial intelligence is transforming malware

Threat actors are taking advantage of artificial intelligence (AI) to make common types of malware more effective. The following sections outline the three ways AI is transforming malware.

Method 1: AI-assisted malware

This form of malware relies on AI tools that operate outside the malware itself to assist in how attacks are developed or delivered. This can make malicious activity faster, more targeted and more convincing.

For example, threat actors may use AI to generate messages, craft malicious code, automated scanning of public information to identify valuable targets and craft tailored social engineering content designed to increase infection rates.

Entry points include phishing emails with malicious links or attachments, downloads from compromised websites and the use of stolen or weak credentials to log into systems.

Method 2: AI-augmented malware

This form of malware uses AI to strengthen traditional malicious functions during execution to enhance stealth, speed or decision making. AI enhances these actions but does not completely control or replace the underlying malware processes.

For example, threat actors may use AI to choose less visible routes for lateral movement, shape data exfiltration to resemble routine traffic, prioritize targets based on observed activity or automatically fine-tune tactics to avoid malware detection tools.

Entry points include phishing emails with malicious links or attachments, exploitation of unpatched systems and misuse of remote access, which the malware then builds on using AI to improve how it spreads or hides.

Method 3: Embedded AI malware

This form of malware is designed with AI embedded into the payload so it can analyze the system it infects and adjust its behaviour in real time. This allows it to identify targets, respond to security controls and choose actions that maximize its effectiveness.

For example, AI may be used to select high-value files to steal, alter activity when security tools are detected, adjust execution timing based on user behaviour or learn from system conditions to refine future actions (for example, self-modifying code).

Entry points include phishing emails with malicious links or attachments and vulnerable or misconfigured Internet-facing services that allow threat actors to place the malware on a device or system.

Signs of an infected device

Malware often disrupts devices in subtle ways before the damage becomes obvious. Staying aware of the following indicators can help you identify potential threats early and protect your information effectively.

Changes on your device

  • Pop-up windows appearing on your device
  • Homepage changes
  • Browser redirects, new or unknown toolbars or unexpected icons

Performance issues

  • Slow computer performance
  • Page or system crashes
  • Unusual or excessive hard drive activity, especially when the system is idle

Security or software changes

  • Unknown programs running on your device
  • Antivirus or malware protection software being disabled
  • Security settings or administrative controls being locked or altered
  • Files becoming inaccessible, encrypted or renamed
  • Ransom notes or payment demands appearing on the device

Unusual account activity

  • Spam emails or messages sent from your account
  • Unauthorized password changes or unusual login activity

Network and device behaviour

  • High network traffic when the device is idle
  • Overheating, rapid battery drain or unusual data use on your mobile device

Steps to address infected devices

When a device becomes infected with malware, quick action is essential to limit damage, prevent further spread and protect sensitive information. The following steps outline current best practices to help you contain the threat, clean your device safely and restore it to a secure state.

Immediate actions

  • Contact your information technology (IT) security service desk or IT provider immediately
  • Disconnect the infected device from all networks (for example, Wi-Fi, Ethernet, and mobile data)
  • If malware appears to be active or spreading, power off the device to prevent further damage
  • Refrain from using the infected device to sign into sensitive accounts, such as email, financial systems or administrative portals

Containment and recovery

  • Run antivirus scans offline when possible
  • Restore data only from known, clean backups that were created before the infection
  • Scan all backup files before restoring them to ensure they are free of malware
    • Use trusted malware analysis tools, such as Assemblyline, the Canadian Centre for Cyber Security's malware detection and analysis platform, to help assess suspicious files before restoration
  • Reset all passwords associated with the device, revoke active sign-in sessions and access tokens and re-enrol multi-factor authentication (MFA) to prevent misuse of stolen credentials

Post-incident monitoring

  • Reconnect the device to your network only after the OS is reinstalled and all malware scans confirm the device is clean
  • Continue monitoring the device for unusual behaviour, suspicious traffic or new alerts
  • Perform regular antivirus scans to ensure no malware remains

Tips to protect against malware

Staying safe online requires more than just good habits; it requires intentional and proactive cyber hygiene. Malware threats continue to evolve, targeting personal devices, corporate systems and everything in between. By following best practices such as our Top 10 IT security actions and using trusted protective tools, you can significantly reduce your risk of compromise. The following tips outline the most effective steps you can take to strengthen your defences and help keep your information, devices and accounts secure.

Authentication and identity security

  • Enable passkeys or phishing-resistant MFA for all accounts, choosing authentication methods that align with the sensitivity of the account and the level of risk
  • Use a password manager to generate and store long, unique passwords
  • Limit user and administrator access to only what is required for their roles and regularly remove excess permissions

Device and system hardening

  • Install software, OS and firmware updates immediately
  • Use anti-virus, anti-malware and endpoint detection and response tools
  • Use a firewall to block and restrict unauthorized network access
  • Enable full-disk or file-based encryption
  • Use host intrusion detection systems where supported
  • Use application allowlisting so only authorized apps can run
  • Turn off wireless features like Wi-Fi, Bluetooth, GPS and near-field communication when not in use

Network and Internet safety

  • Avoid public Wi-Fi or use a virtual private network when public Wi-Fi is necessary
  • Use anti-phishing protections and align email systems with Domain-based Message Authentication, Reporting, and Conformance (DMARC)
  • Use an ad blocker to reduce risk from malicious ads or a tracker blocker and limit the collection of browsing activity information
  • Verify files, links and attachments before downloading or opening them
  • Provide regular security awareness training so users can recognize phishing emails, malicious links, fake websites and social engineering attempts
  • Encourage users to report suspected phishing or malware quickly to reduce spread and impact
  • Use a protective domain name system to prevent access to malicious or suspicious domains
  • Monitor device data usage for suspicious or unusual activity

Backup and data protection

  • Follow the 3-2-1 backup rule: 3 copies, 2 types of media, 1 offsite
  • Encrypt sensitive data stored in backups

Zero-trust and enterprise controls

  • Implement zero-trust architecture
  • Use identity threat detection and response tools
  • Strengthen supply chain security and monitor third-party risks

Learn more

Date modified: