Malware is any software designed to damage, disrupt or gain unauthorised access to a computer system. GCSE computer science expects you to distinguish between the main types of malware — viruses, worms, trojans, ransomware, spyware and adware — by how each one spreads and what damage it causes once installed.

1. What is a computer virus?

A virus is malware that attaches itself to a legitimate file or program, such as a document or an executable. It stays dormant until the infected file is opened or run, at which point it activates and can corrupt data, delete files, or copy itself into other files on the same device. Crucially, a virus needs a host file to attach to and needs a user action — opening or running that file — to spread. Without both of those, a virus cannot activate or move to another system.

2. What is a computer worm?

A worm is standalone malware that does not need to attach itself to another file. Instead, it exploits weaknesses in a network to copy itself directly from one connected device to another, without requiring any action from a user. Because worms spread automatically across a network, they can move between large numbers of devices far faster than a virus, and they often slow down networks simply by consuming bandwidth as they replicate.

3. What is a trojan horse?

A trojan disguises itself as legitimate or desirable software — a free game, a useful-looking tool, or a fake update — to trick a user into installing it voluntarily. Once installed, it carries out a hidden, malicious action: it might open a "backdoor" giving an attacker remote access to the device, steal data, or install further malware. Unlike a virus or worm, a trojan does not self-replicate; it relies entirely on deceiving the user into installing it in the first place.

4. What is ransomware?

Ransomware encrypts a victim's files, making them unreadable, and then demands payment — a ransom — in exchange for the key needed to decrypt them. It commonly spreads through phishing emails carrying an infected attachment or a malicious link, and it can arrive disguised as a trojan or spread across a network like a worm. Ransomware is particularly disruptive for schools, hospitals and businesses because it can lock staff out of essential files and systems all at once, not just a single device.

5. What is spyware?

Spyware secretly monitors a user's activity — keystrokes, browsing history, or even webcam and microphone access — and sends that information back to an attacker without the user's knowledge or consent. A keylogger is a specific and well-known type of spyware that records every key a user presses, which is particularly dangerous because it can capture passwords and bank details as they are typed. Spyware is often bundled with free downloads or hidden inside apps that appear harmless.

6. What is adware?

Adware automatically displays unwanted adverts on an infected device, and may redirect a user's browser to sponsored websites without permission. It is often bundled with free software the user chose to install. Adware is generally considered less directly damaging than the other types above, since it does not usually corrupt files or steal sensitive data directly — but it is intrusive, can slow a device down, and some variants secretly track browsing habits to target adverts more precisely, which is itself a privacy concern.

How does each type of malware compare?

Malware type Needs a host file? Spreads without user action? Main effect
Virus Yes No Corrupts or deletes files; spreads when an infected file is opened
Worm No Yes, across a network Consumes bandwidth and system resources; spreads automatically
Trojan No — disguises itself as legitimate software No Opens a backdoor or performs a hidden malicious action
Ransomware Varies Varies Encrypts files and demands payment for the decryption key
Spyware No No Secretly monitors activity and sends data to an attacker
Adware No No Displays unwanted adverts; may track browsing habits

How do you defend against malware?

No single defence stops every type of malware, so GCSE specifications expect a combination of measures:

  • Antivirus/antimalware software — scans files against known malware signatures and can quarantine or remove infected files.
  • Firewalls — monitor and filter network traffic, helping to block the kind of unauthorised connections a worm or trojan's backdoor relies on.
  • Keeping software updated — patches close the security weaknesses that malware, especially worms, is designed to exploit.
  • Caution with email attachments and downloads — most trojans and much ransomware rely entirely on a user opening something they should not.
  • Regular backups — stored separately from the main system, backups mean a ransomware attack cannot permanently lock a user out of their data.

How do GCSE exam questions test malware knowledge?

Exam questions typically describe a scenario — for example, "a user's files have all become encrypted and a message demands payment" — and ask you to name the type of malware responsible and justify your answer using its defining features. Other questions ask you to compare two types directly, such as explaining why a worm spreads faster across a network than a virus, or to suggest an appropriate technical or behavioural defence for a described attack. Because several malware types can overlap in practice — ransomware delivered by a trojan, for instance — always justify your answer using the specific behaviour described in the question rather than the malware's name alone.

Frequently asked questions

What is the difference between a virus and a worm?

A virus needs to attach itself to a host file and requires a user to open or run that file before it can activate and spread. A worm is standalone malware that spreads automatically across a network by exploiting security weaknesses, without needing a host file or any user action. This is why worms typically spread far more quickly than viruses.

Is ransomware a type of virus?

Not necessarily. Ransomware describes what the malware does — encrypting files and demanding payment — rather than how it spreads. It can be delivered as a trojan (tricking a user into installing it), spread like a worm across a network, or occasionally behave like a virus by attaching to files, so it is best thought of as a separate category defined by its effect.

How does a trojan spread if it doesn't self-replicate?

A trojan relies entirely on deception rather than automatic spreading. It disguises itself as something a user wants — a free program, a game, or a software update — and spreads only when that user is tricked into downloading and running it themselves. Because it depends on human decisions rather than technical exploitation, awareness and caution are the main defence against trojans.

What is the best defence against malware?

There is no single defence that stops every type of malware, so GCSE specifications expect a layered approach: up-to-date antivirus software, a firewall, regularly patched software, careful handling of email attachments and downloads, and regular backups stored separately from the main system. Backups are particularly important against ransomware, since they let a user restore their files without paying an attacker.


For Socratic GCSE computer science tutoring on cyber security, from malware to network defences, visit aitutors.me.