EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsEasy
A software development team discovers a malicious code snippet embedded within a legitimate application's source code. This snippet is designed to remain dormant until a specific date, at which point it will activate and delete critical database files. The team is concerned about the potential for future, similar attacks. Which type of malware best describes this specific code snippet based on its activation mechanism?
- ASpyware
- BWorm
- CLogic Bomb
- DAdware
Show answer & explanationAnswer & explanation
Correct answer: C. Logic Bomb
A logic bomb is a piece of code intentionally inserted into a software system that will set off a malicious function when specified conditions are met, such as a particular date or time, or when a specific event occurs.
Why the other options are wrong
- A. Spyware is designed to secretly gather information, not to delete files based on a trigger.
- B. A worm is self-replicating malware, which is not described by a dormant code snippet with a trigger.
- D. Adware displays unwanted advertisements, which is not the described malicious function.
Logic Bomb
A malicious program or code segment that lies dormant until a specific condition is met, then executes its payload.
- Triggered by specific events (e.g., date, time, user action).
- Often embedded in legitimate software.
- Can cause significant damage upon activation.
Memory trick: Logic bombs wait for a specific moment to explode.