{"id":961,"date":"2018-01-03T11:00:35","date_gmt":"2018-01-03T15:00:35","guid":{"rendered":"https:\/\/solutionsreview.com\/endpoint-security\/?p=961"},"modified":"2018-01-03T17:53:29","modified_gmt":"2018-01-03T21:53:29","slug":"the-expanded-glossary-of-digital-threats","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/","title":{"rendered":"The Expanded Bestiary of Malware and Other Digital Threats"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-962\" src=\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod.jpg\" alt=\"the expanded glossary of digital threats malware\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod.jpg 800w, https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod-300x150.jpg 300w, https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod-768x384.jpg 768w, https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod-540x270.jpg 540w, https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod-162x81.jpg 162w, https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod-360x180.jpg 360w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">\u201cIf you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle.\u201d<\/span><\/p>\n<br \/>Widget not in any sidebars<br \/>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Thus said Sun Tzu in his immortal work, <\/span><i><span style=\"font-weight: 400\">The Art of War<\/span><\/i><span style=\"font-weight: 400\">. Obviously he lived in a time before computers were even a concept, but he would probably feel right at home in the quiet war of hackers versus cybersecurity professionals waging just on the other side of our screens. After all he also said, \u201call warfare is based on deception,\u201d and deception is the hackers\u2019 greatest weapon. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">So the question now stands: do you know your enemy? Do you truly know what you are up against? <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Through our efforts we\u2019ve compiled a fairly comprehensive glossary of the major terms in <\/span><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/introducing-siem-defined-glossary\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">SIEM<\/span><\/a><span style=\"font-weight: 400\">, <\/span><a href=\"https:\/\/solutionsreview.com\/identity-management\/abridged-identity-access-management-iam-glossary\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">IAM<\/span><\/a><span style=\"font-weight: 400\">, and <a href=\"https:\/\/solutionsreview.com\/endpoint-security\/endpoint-security-glossary-of-terms-infosec-acronyms-defined\/\" target=\"_blank\" rel=\"noopener\">Endpoint Security<\/a>. We know the field is mired in jargon, and we believe clear communication is the key to facilitating better protection, less anxiety, and above all acquiring more knowledge about what threats are lurking in the electric shadows. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Looking back over our glossary, however, we noticed our definitions of cybersecurity\u2019s demons could use a little fleshing out. If we are to know our enemy, we need to know them in detail\u2014how they behave, how good online hygiene practices can help prevent them, and what to do if you are infected. Therefore we have compiled this bestiary of the digital threats you are most likely to face and how to stay calm in the roughest storm. <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>A General Guide for Cybersecurity&#8217;s Nebulous Threats<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">According to the <\/span><i><span style=\"font-weight: 400\">McAfee Labs Threat Report December 2017<\/span><\/i> <a href=\"https:\/\/solutionsreview.com\/endpoint-security\/shocking-findings-mcafee-labs-threat-report-december-2017\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">findings<\/span><\/a><span style=\"font-weight: 400\">, the number of individual ransomware samples is over 12 million. Individual malware numbers around 57.6 million. Cataloging every strain would be a task of herculean proportions; even with the resources to do so, the speed of hackers\u2019 innovations means that our record would be obsolete long before we could finish it. Instead, we have provided information on the threat categories and how they behave as a group rather than focus on the individuals. In other words, we focused on the families, not the species. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Additionally, we do not touch upon threats that are of more concern to private individuals, although they may also find useful information here. Instead, we focused on the infections that plague enterprises and small-to-medium sized businesses (SMBs). <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">With that clarified, here is our bestiary of digital threats: <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Bot<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Despite its cute name, a bot is technically any software application that runs automated tasks or scripts online. In other words, a bot is any code that obtains and calculates data in repetitive cycles at a rate many times faster than a human could manage. Google\u2019s web indexing is one example of an innocent bot. However, malicious bots can coordinate and enact automated attacks on networks, commit click fraud, harvest emails, or drain bandwidth on targeted sights. They can even be programmed to post incendiary comments on particular pages or buy up real-world concert tickets. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Servers can set rules on the bots that visit their sites, establishing limits on the data bots can access. However, no matter the website, there is no mechanism to enforce these rules; obeying them is voluntary, which renders such rules mere illusions of control. Other sites will use CAPTCHA\u2014tests that ask users to verify they are not bots\u2014as a more effective tool to fool bots, but bots can be programmed to bypass these barriers. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">See also <\/span><i><span style=\"font-weight: 400\">zombie computer.<\/span><\/i><\/p>\n<h3 style=\"text-align: justify\"><b>Botnet<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Think of the botnet as the next step in the bot\u2019s evolution, or rather the bot as the infection and the botnet as the epidemic. A botnet is a network of devices that each is running a bot, either willingly or not. Botnets can coordinate attacks, thefts, spam, bitcoin mining, \u00a0and access-cracking to much more devastating effect than an individual bot, like with a DDoS attack. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Usually the botnet devices were breached and forced to cede control to a third-party hacker using malware or another virus. This hacker, sometimes called a bot herder, can use the botnet to obfuscate their location and hide their malicious connections in pre-existing servers. When ready, the herder can remotely send a message to all of their bots to initiate an attack. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The greatest obstacle to fighting botnets is that you have to cure each client of their infection individually. In the short term, this means finding the infected computers, removing their internet access, and denying the domain access crucial to facilitating communication to the bot herder. In the long term, this means removing the code that turns the computer into a bot. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Originally, signature-based detection from anti-malware solutions could detect and remove botnet coding. However, botnets are becoming increasingly sophisticated, developing new ways to bypass signature-based detection. Solutions providers are developing behavior-based approaches to recognize and distinguish human and bot behavior and block the latter. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">See also <\/span><i><span style=\"font-weight: 400\">zombie computer<\/span><\/i><span style=\"font-weight: 400\">. <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Denial of Service (DoS) Attack<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">A Denial of Service Attack renders a server or network that connects to the Internet unavailable to legitimate users by disrupting its service. Usually this is accomplished by overwhelming the victim server or network with a flood of superfluous queries until it shuts down. While rebooting the network can revive a server crash resulting from a DoS Attack, the actual flood of queries can result in lingering damage.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">While some DoS Attacks have an extortion element to them, generally they are designed to simply sabotage an enterprise, website, or their customers. Motivations for such attacks can range from ideology to personal revenge. It depends on the attacker. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Solution providers recommend having incident response plans well in advance of such attacks, with many providing such plans as part of their solutions. Rerouting or suppressing malicious traffic through the ISP has also proven successful in stopping an attack. However, while patching vulnerabilities can help reduce the likelihood of an attack, prevention is generally impossible. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">While there are many varieties of the DoS Attack, the Distributed Denial of Service Attack is the most common. \u00a0<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Distributed Denial of Service (DDoS) Attack<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">A DoS attack that uses multiple infected systems (a botnet) to attack a server or website. This could be the result of the lone hacker or entire state governments. \u00a0<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Malware<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Short for malicious software, malware is actually an umbrella terms for any program, software, or application with ill intent. This can include worms, trojans, adware, scareware, and viruses. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Malware can come from myriad sources and have equally numerous intentions and forms; the only unifying principle is that the program acts in secret against the interests of the user. The <\/span><a href=\"https:\/\/www.networkworld.com\/article\/2998251\/malware-cybercrime\/sony-bmg-rootkit-scandal-10-years-later.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">Sony BMG Rootkit Scandal in 2005 <\/span><\/a><span style=\"font-weight: 400\">is an example of a legitimate global company distributing malware. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Malware is often most inflicted on a server or network via a downloaded file; it has existed almost since the existence of computers themselves. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">See also <\/span><i><span style=\"font-weight: 400\">rootkit<\/span><\/i><span style=\"font-weight: 400\">. <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Malwareless Attack \/ Non-Malware Attack<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">A non-malware attack lives in a world all on its own. It is still malware in the sense that it is a program running on a user\u2019s computer without their permission, working against their interests. But unlike the majority of malware throughout history, a non-malware attack uses existing software, allowed applications, and authorized protocols to carry out its malicious intentions. They do not require downloading a file in the initial phases, and are thus referred to as fileless, memory-based, or \u201cliving-off-the-land\u201d attacks.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Non-malware attacks take advantage of vulnerable software that a typical end user would leverage on a day-to-day basis, such as Flash Player or Microsoft Office-suite applications; the successful exploit grants access to the computer\u2019s native operating system tools. This gives the attacker a huge degree of freedom within the infected system, allowing them to take control with relative ease. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The issue with non-malware attacks is not that they are hidden so much as that they operate in plain sight\u2014by using native applications and not downloading files in the initial phases, traditional anti-malware solutions typically can\u2019t prevent them or even detect them, which means an increased dwell time and thus more damage. This has proven successful over the past few years: the Democratic National Committee hack was accomplished via a non-malware attack. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Solutions providers have developed or are developing detection and prevention methods for non-malware attacks. The most commonly utilized prevention solution is to use streaming logs to look for incongruous behavior and activity in conjunction with regular activity, a clear sign of non-malware attacks. SIEM solutions and their log capabilities are often the most effective in this regard.<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Phishing <\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Phishing refers to any attempt by hackers to obtain vital information\u2014credentials or direct financial information\u2014by impersonating a trusted entity in an electronic communication. This can be in the form of an email, instant message, or direct message, and often purports to be from a bank, social media site, or IT administrator. Phishing messages will ask users to input their credentials on a forged \u00a0website that looks legitimate, and by doing so the user unintentionally hands hackers their information. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">While there are many different kinds of phishing techniques, the most commonly employed is called <\/span><b>spear phishing<\/b><span style=\"font-weight: 400\">. This refers to phishing attempts that target a specific individual or company, using personal information gathered online to fool the victim into trusting it. If this is done on an upper-level executive the technique is called <\/span><b>whaling<\/b><span style=\"font-weight: 400\">. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">While solutions can certainly help prevent phishing emails through machine learning, a good deal of prevention can come from employee training. Employees should not click on emailed links or give their information to websites, even to trusted websites; the most talented phishers can mask the true identity of their weblinks as legitimate ones. Users should also be on the lookout for spelling mistakes in official communications, as these are typically red flags. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">If a user is in doubt about the legitimacy of an emailed request for verification from a legitimate company, they should call that company to make sure the request is real. \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Ransomware<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Arguably the most well-known form of malware, ransomware (as the name suggests) ruthlessly holds a computer\u2019s or network\u2019s data hostage for a ransom. If the user doesn\u2019t pay the cybercriminal the ransom within a certain amount of time, their data will be deleted and lost forever. Supposedly, if the ransom is paid the victim will receive the tool or encryption key to access their data. Ransoms can range in amount from a few hundred to several thousand dollars. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">There are actually three distinct families of ransomware, distinguishable by how the computer or network is held hostage:<\/span><\/p>\n<p style=\"text-align: justify\"><b>Screen Locking Ransomware<\/b><span style=\"font-weight: 400\">: The user is unable to move off or out of the screen demanding payment. Files may still be accessible outside the screen, but the user is prevented from leaving until paying. With some IT expertise, this ransomware may be bypassed. <\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><\/p>\n<p style=\"text-align: justify\"><b>Encryption Ransomware<\/b><span style=\"font-weight: 400\">: The user can still move within the computer\u2019s operating system but cannot access any files due to encryption. Without the encryption key, these files are generally impossible to recover, granting even more power to the hacker. <\/span><\/p>\n<p style=\"text-align: justify\"><b>Fake Ransomware<\/b><span style=\"font-weight: 400\">: This is a bluff tactic, the suddenness and scariness of which is designed to intimidate users into paying. However, the screen is not locked and the files are not encrypted. This is still a threat in that an external malicious actor has gained access into your network, but it is a much less serious threat than its brethren.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Some ransomware, regardless of family, will try to disguise itself as an official entity such as the FBI and IRS. The ransomware will attempt through this masquerade to intimidate users by accusing them of some crime or violation and demanding payment as punishment for that crime. No official government organization operates in this fashion; users should not fall for these ploys. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">All security experts agree on one thing when dealing with ransomware: <\/span><i><span style=\"font-weight: 400\">do not pay the ransom<\/span><\/i><span style=\"font-weight: 400\">. Ransomware is a one-sided relationship. You cannot trust the hacker to have a sense of honor. While paying the ransom may result in the return of your files, they could also demand more money after the initial payment or lock your files again later on. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">If you are infected with ransomware, do not panic. Alert the authorities and your solution provider if you have one. Disconnect your computer from the network if possible; ransomware may also be programmed as a worm to spread to all computers in your network. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Ransomware can be difficult to detect; they are often hidden deep in innocent-looking files. As a prevention method, keep your files backed up on a separate server or drive. Do not open attachments in emails unless you are sure the sender can be trusted, ignore spam emails, and train your employees to maintain these digital hygiene practices.<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Rootkit<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The definition of rootkit can be contentious, but it is generally understood to be malware designed gain unauthorized access to a server and conceal its existence. Essentially, it uses a vulnerability to hack into a system, give privileged access to the hacker, and then cover up all of its activities. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">What makes rootkits insidious is that they essentially give the hacker the ability to modify the existing software of the computer including the software that would normally detect such blatant breaches, undermining their capabilities and making removal incredibly difficult. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Rootkits, like all malware families, are numerous in form and capability. Some solutions can detect some forms of rootkits\u2014often through behavior or user analysis\u2014and even remove them. However, many rootkits will remain firmly entrenched in the compromised system despite these efforts. In those cases, a total rebuild of the compromised system (physically or via digital software) may be necessary, as there is no way to be sure a rootkit has been totally removed otherwise. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Rootkits are file-based, and therefore monitoring and carefully selecting what is installed on your computer can help prevent them. Solutions that carefully control system permissions and continually apply security patches are usually the most fortified against rootkits. <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Spyware<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">A branch of malware that is itself an umbrella term for malicious programs such as keyloggers, remote access trojans, and backdoor trojans\u2014software that allows remote surveillance of passwords and other sensitive data without the user being aware their information is being collected. Spyware can trace user actions, collect hard drive information, and even monitor your keyboard typing. Firewalls are designed in part to prevent them and anti-malware scanners are designed in part to detect and remove them. \u00a0\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Trojan Horse (\u201cTrojan\u201d)<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">As the name suggests, a trojan is any malicious program&#8211;malware, ransomware, spyware, etc\/&#8211;that poses as a legitimate program or download to disguise its intentions. Usually this can be in the form of a seemingly innocuous download from a reputable company. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Generally, trojans operate as backdoors, opening the network or server for hackers to enter unchallenged or exposing personal information. Other trojans turn the infected computer into a proxy, so the hacker can use the Internet for illegal purposes while all the incriminating evidence is attached to the hacked IP address. Anti-malware solutions can generally prevent, detect, and remove Trojans, as they are file-based attacks. \u00a0<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Virus<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">While often used to referred to all forms of malware, the term \u201cvirus\u201d actually applies to the specific kind of malware that replicates itself and spreads from host to host. Viruses need a file or document on the victim\u2019s computer to replicate, and therefore cannot be a non-malware attack. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Viruses require human action to be spread, either knowingly or not, which can be through an emailed link, a infected download, or a removable hard drive. Viruses can delete, add, copy, encrypt, or modify files or manipulate core functions. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Anti-malware solutions are often designed to fight viruses directly, but virus innovations have made them harder to detect and remove. <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Worm<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">A worm refers to any piece of malware that replicates itself to spread to other computers or servers on a network, using security failures and vulnerabilities to infiltrate them. Unlike a virus, worms do not need human action to spread and don\u2019t need to copy itself to a host program to replicate. Worms by themselves don\u2019t do harm beyond consuming bandwidth. However, many worms will harbor a \u201cpayload\u201d attachment that can delete files, inflict ransomware attacks, or install spyware depending on their purpose. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Firewalls, anti-virus, and anti-spyware solutions can help prevent worms so long as they are regularly updated to patch vulnerabilities. Worms are often propagated on zero-day attacks. <\/span><\/p>\n<h3 style=\"text-align: justify\"><strong>Zero-Day Attack <\/strong><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">A zero-day attack refers to when an attack on a security vulnerability or exploit occurs on the same day as the discovery of that vulnerability, which leaves solutions providers scrambling to patch the issue as the attack wrecks havoc. Zero-day attacks can either occur when a hacker learns of the vulnerability through reconnaissance or when a solution provider announces the discovery of a vulnerability before they have released a patch for it. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">While called \u201czero-day\u201d it can be months or even years before the vulnerability that led to an attack is discovered and patched. Because of the nature of zero-day attacks, there is no real method of prevention or detection. <\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Zombie Computer<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The sci-fi term belies the serious nature of the compromise. A zombie is any endpoint device compromised by a hacker that can be used to carry out their (usually malicious) will, attacking under remote direction. They are often part of botnets. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">What makes these things scary is that typically the owners of infected computers will have no idea that their endpoint is being used in this way. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">There are some warning signs that an endpoint has been turned into a zombie, including slower than usual start-up, shut-down, or operation times, unexpected error messages, unusual loss of hard drive storage, and unexplained web browser closures. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">To kill a zombie computer (or perhaps more accurately bring it to the world of the living) first contact your solution provider. They should be able to deploy anti-malware applications that will remove the rogue control code. It is generally not advisable to try to remove the zombie threat yourself; zombie programs often employ self-defenses that will prevent some anti-malware programs from running; some may even use rootkits to embed themselves in the server. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Setting your enterprise\u2019s firewall to the maximum security setting will force every application that wants internet access to ask for your permission first. While perhaps annoying, it will give you a level of personal control that will make it hard for hackers to slip their activities past you. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">A good solution will certainly help prevent many attacks, but you and your employees need to always check emails before clicking any attachments within them, as this is the most common bot vector and thus the initial infection vector for zombies.<\/span><\/p>\n<div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a href=\"https:\/\/insightjam.com\"><img decoding=\"async\" title=\"Insight Jam Ad\" src=\"https:\/\/solutionsreview.com\/wp-content\/uploads\/2023\/11\/ij2.jpg\" alt=\"Insight Jam Ad\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u201cIf you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle.\u201d Thus said Sun Tzu in [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":962,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[2,1,335],"tags":[31,234,75,462,22,13,30,161,35,94,203,23,84],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>The Expanded Bestiary of Malware and Other Digital Threats<\/title>\n<meta name=\"description\" content=\"Through our efforts we\u2019ve compiled a fairly comprehensive glossary of the major terms in malware and cybersecurity in general.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Expanded Bestiary of Malware and Other Digital Threats\" \/>\n<meta property=\"og:description\" content=\"Through our efforts we\u2019ve compiled a fairly comprehensive glossary of the major terms in malware and cybersecurity in general.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/\" \/>\n<meta property=\"og:site_name\" content=\"Endpoint Security &amp; Protection Platforms | Solutions Review\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/solutionsreview\" \/>\n<meta property=\"article:published_time\" content=\"2018-01-03T15:00:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-01-03T21:53:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ben Canner\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@InfoSec_Review\" \/>\n<meta name=\"twitter:site\" content=\"@InfoSec_Review\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"16 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/\"},\"author\":{\"name\":\"Ben Canner\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"headline\":\"The Expanded Bestiary of Malware and Other Digital Threats\",\"datePublished\":\"2018-01-03T15:00:35+00:00\",\"dateModified\":\"2018-01-03T21:53:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/\"},\"wordCount\":3148,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#organization\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod.jpg\",\"keywords\":[\"Best Practices\",\"Botnet\",\"Cybersecurity\",\"DoS Attack\",\"Endpoint Protection\",\"Endpoint Security\",\"Hacks and Attacks\",\"Infosec\",\"Lists\",\"Malware\",\"Phishing\",\"Ransomware\",\"Security\"],\"articleSection\":[\"Best Practices\",\"Endpoint Security News\",\"Featured\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/\",\"url\":\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/\",\"name\":\"The Expanded Bestiary of Malware and Other Digital Threats\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod.jpg\",\"datePublished\":\"2018-01-03T15:00:35+00:00\",\"dateModified\":\"2018-01-03T21:53:29+00:00\",\"description\":\"Through our efforts we\u2019ve compiled a fairly comprehensive glossary of the major terms in malware and cybersecurity in general.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod.jpg\",\"width\":800,\"height\":400,\"caption\":\"the expanded glossary of digital threats malware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/endpoint-security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Expanded Bestiary of Malware and Other Digital Threats\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#website\",\"url\":\"https:\/\/solutionsreview.com\/endpoint-security\/\",\"name\":\"Endpoint Security &amp; Protection Platforms | Solutions Review\",\"description\":\"Evaluating Enterprise EPP Software, Next-Gen Antivirus &amp; EDR Solutions.\",\"publisher\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/endpoint-security\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#organization\",\"name\":\"Solutions Review\",\"url\":\"https:\/\/solutionsreview.com\/endpoint-security\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2016\/05\/SR_Icon.png\",\"contentUrl\":\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2016\/05\/SR_Icon.png\",\"width\":200,\"height\":200,\"caption\":\"Solutions Review\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/solutionsreview\",\"https:\/\/x.com\/InfoSec_Review\",\"https:\/\/www.linkedin.com\/company\/cyber-security-solutions-review\",\"https:\/\/www.youtube.com\/user\/SolutionsReview\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/endpoint-security\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Expanded Bestiary of Malware and Other Digital Threats","description":"Through our efforts we\u2019ve compiled a fairly comprehensive glossary of the major terms in malware and cybersecurity in general.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/","og_locale":"en_US","og_type":"article","og_title":"The Expanded Bestiary of Malware and Other Digital Threats","og_description":"Through our efforts we\u2019ve compiled a fairly comprehensive glossary of the major terms in malware and cybersecurity in general.","og_url":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/","og_site_name":"Endpoint Security &amp; Protection Platforms | Solutions Review","article_publisher":"https:\/\/www.facebook.com\/solutionsreview","article_published_time":"2018-01-03T15:00:35+00:00","article_modified_time":"2018-01-03T21:53:29+00:00","og_image":[{"width":800,"height":400,"url":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod.jpg","type":"image\/jpeg"}],"author":"Ben Canner","twitter_card":"summary_large_image","twitter_creator":"@InfoSec_Review","twitter_site":"@InfoSec_Review","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"16 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#article","isPartOf":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/"},"author":{"name":"Ben Canner","@id":"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"headline":"The Expanded Bestiary of Malware and Other Digital Threats","datePublished":"2018-01-03T15:00:35+00:00","dateModified":"2018-01-03T21:53:29+00:00","mainEntityOfPage":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/"},"wordCount":3148,"commentCount":0,"publisher":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/#organization"},"image":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod.jpg","keywords":["Best Practices","Botnet","Cybersecurity","DoS Attack","Endpoint Protection","Endpoint Security","Hacks and Attacks","Infosec","Lists","Malware","Phishing","Ransomware","Security"],"articleSection":["Best Practices","Endpoint Security News","Featured"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/","url":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/","name":"The Expanded Bestiary of Malware and Other Digital Threats","isPartOf":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod.jpg","datePublished":"2018-01-03T15:00:35+00:00","dateModified":"2018-01-03T21:53:29+00:00","description":"Through our efforts we\u2019ve compiled a fairly comprehensive glossary of the major terms in malware and cybersecurity in general.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#primaryimage","url":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod.jpg","contentUrl":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2018\/01\/bestiary-mod.jpg","width":800,"height":400,"caption":"the expanded glossary of digital threats malware"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/endpoint-security\/the-expanded-glossary-of-digital-threats\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/endpoint-security\/"},{"@type":"ListItem","position":2,"name":"The Expanded Bestiary of Malware and Other Digital Threats"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/endpoint-security\/#website","url":"https:\/\/solutionsreview.com\/endpoint-security\/","name":"Endpoint Security &amp; Protection Platforms | Solutions Review","description":"Evaluating Enterprise EPP Software, Next-Gen Antivirus &amp; EDR Solutions.","publisher":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/endpoint-security\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/solutionsreview.com\/endpoint-security\/#organization","name":"Solutions Review","url":"https:\/\/solutionsreview.com\/endpoint-security\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/logo\/image\/","url":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2016\/05\/SR_Icon.png","contentUrl":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2016\/05\/SR_Icon.png","width":200,"height":200,"caption":"Solutions Review"},"image":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/solutionsreview","https:\/\/x.com\/InfoSec_Review","https:\/\/www.linkedin.com\/company\/cyber-security-solutions-review","https:\/\/www.youtube.com\/user\/SolutionsReview"]},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/endpoint-security\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/posts\/961"}],"collection":[{"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/comments?post=961"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/posts\/961\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/media\/962"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/media?parent=961"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/categories?post=961"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/tags?post=961"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}