SECAI Core · phase 11 of 15 · noun
Malware
Software that serves a malicious purpose, typically installed without the user's consent (or knowledge).
The Explain card
- Plain English
- Malware is any software built for a malicious purpose, usually installed without the user's consent or knowledge. Viruses, worms, ransomware, spyware, and trojans are all members of the family.
- Example
- A researcher downloads a "pretrained model" from a file-sharing site. The pickle file executes code on load, dropping a credential stealer that harvests cloud API keys from the machine.
- Why it matters
- Model files, notebooks, and plugins are executable content in disguise. Defenders need scanning, safe serialization formats, and sandboxed loading to keep AI tooling from becoming a malware delivery channel.
- Hook
- Software with a hidden agenda.
Word knowledge
How the word is built, where it came from, and what it sits beside in memory.
In a sentence
The security team quarantined malware detected on a model-training server before restoring the machine from a verified image.
How it is built
- mal- clipped element from malicious
- -ware combining form a type of computer software
Where it came from
- Origin
- an English blend of malicious and software
- Entered the language
- 1990
- What changed
- It began as an umbrella coinage for threats such as viruses and worms, then expanded to include newer families such as ransomware and spyware.
How it is spelled
- Pattern
- Like many computing terms ending in -ware, malware is written as one closed word.
Spelled like
- software
- spyware
- ransomware
Broken into chunks
-
mal
- malicious
- malign
- malpractice
-
ware
- software
- hardware
- spyware
What it sits beside
Same subject
- virus
- worm
- Trojan
- ransomware
Same shape
- adware
- scareware
- spyware
- ransomware
malware families
- virus
- worm
- Trojan
- ransomware
Where it sits in the deck
Phase 11: Threat Landscape: Attack Vectors and Adversarial Techniques
With defences named, learn what they must defend against — the full catalogue of attack techniques targeting AI systems, their inputs, outputs, training pipelines, and supply chains.