Skip to content

Advanced & Specialised Malware

Part II — Advanced & Specialised Malware

Section titled “Part II — Advanced & Specialised Malware”

The malware types in this section represent advanced threats that emerged from the 2000s onward. They feature sophisticated evasion, modular architectures, and criminal business models.


Risk: 🔴 Critical | Self-Replicates: ✅ Yes

A botnet (robot network) is a collection of compromised devices (bots) controlled by a bot herder via Command & Control (C2) infrastructure.

Notable: Storm (2007), Conficker (2008), Mirai (2016), Necurs (2012+), Emotet (2014+), TrickBot (2016+), Mozi (2019+)


Risk: 🔴 Critical | Self-Replicates: ❌ No

APT (Advanced Persistent Threat) malware refers to custom-developed tooling used by nation-state actors for long-term espionage, intellectual property theft, and sabotage.

Notable: PlugX (APT10/41), RedLeaves (APT10), X-Agent (APT28), WellMess/GoldMax (APT29), Sunburst (APT29), Industroyer (Sandworm)


Risk: 🔴 Critical | Self-Replicates: ❌ No

Fileless malware operates entirely in memory without writing executable files to disk. It abuses legitimate system tools (PowerShell, WMI, .NET, macros, LOLBins).

Notable: Poweliks (2014), Kovter (2015), Duqu 2.0 (2015), Emotet (2017+), Astaroth (2018)


Risk: 🟡 Medium | Self-Replicates: ⚠️ Some variants

Cryptominers use victim’s compute resources (CPU, GPU) to mine cryptocurrency without consent.

Notable: Coinhive (2017), XMRig (2017+), WannaMine (2018), Graboid (2019), Kinsing (2019+), TeamTNT (2020+)


Risk: 🔴 Critical | Self-Replicates: ❌ No

Wiper malware is designed purely for destruction — overwriting, encrypting without key, or deleting data to render systems unrecoverable.

Notable: Shamoon (2012), DarkSeoul (2013), NotPetya (2017), Olympic Destroyer (2018), HermeticWiper (2022)


Risk: 🟠 High | Self-Replicates: ❌ No

Banking trojans are specialised malware designed to steal financial credentials and conduct fraudulent transactions using overlay attacks, form grabbing, webinjects, and SMS interception.

Notable: Zeus/Zbot (2007), SpyEye (2009), Citadel (2011), Gameover Zeus (2011), Dridex (2014), TrickBot (2016), Emotet (2014+), IcedID (2017), Qakbot (2007+)


Risk: 🟠 High | Self-Replicates: ❌ No

A form grabber hooks browser APIs to capture form data (credentials, credit cards, PII) before TLS encryption, bypassing HTTPS protection.

Notable: Zeus/Zbot (2007), SpyEye (2009), Citadel (2011), Tinba (2012), Dridex (2014), TrickBot (2016)