EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsMedium
An organization relies heavily on a legacy industrial control system (ICS) that is isolated from the internet. However, a recent security audit revealed that an employee inadvertently introduced malware to the ICS network by connecting an infected USB drive, previously used on their home computer, to an engineering workstation. The malware then spread autonomously across the ICS network without any further human interaction or internet connectivity. Which type of malware best describes this behavior?
- ATrojan Horse
- BSpyware
- CWorm
- DRansomware
Show answer & explanationAnswer & explanation
Correct answer: C. Worm
A worm is a standalone malware computer program that replicates itself in order to spread to other computers. It often uses network vulnerabilities or removable media for propagation and can do so without user interaction after initial introduction. The scenario describes autonomous spreading without further human interaction or internet connectivity after initial introduction via a USB drive.
Why the other options are wrong
- A. A Trojan horse relies on deceit to be installed; it does not usually self-propagate autonomously.
- B. Spyware collects information secretly and does not typically have autonomous self-propagation as its primary characteristic.
- D. Ransomware encrypts files and demands payment; it doesn't primarily describe the self-propagation mechanism.
Worm
A standalone malware computer program that replicates itself to spread to other computers, often without human interaction.
- Self-propagating and self-contained.
- Can spread via networks, email, or removable media.
- Does not require a host program to infect.
Memory trick: Worms Wriggle and Replicate.