Advanced & Specialised Malware
Part II — Advanced & Specialised Malware
Section titled “Part II — Advanced & Specialised Malware”The malware types in this section represent advanced threats that emerged from the 2000s onward. They feature sophisticated evasion, modular architectures, and criminal business models.
Risk: 🔴 Critical | Self-Replicates: ✅ Yes
A botnet (robot network) is a collection of compromised devices (bots) controlled by a bot herder via Command & Control (C2) infrastructure.
Notable: Storm (2007), Conficker (2008), Mirai (2016), Necurs (2012+), Emotet (2014+), TrickBot (2016+), Mozi (2019+)
Risk: 🔴 Critical | Self-Replicates: ❌ No
APT (Advanced Persistent Threat) malware refers to custom-developed tooling used by nation-state actors for long-term espionage, intellectual property theft, and sabotage.
Notable: PlugX (APT10/41), RedLeaves (APT10), X-Agent (APT28), WellMess/GoldMax (APT29), Sunburst (APT29), Industroyer (Sandworm)
Risk: 🔴 Critical | Self-Replicates: ❌ No
Fileless malware operates entirely in memory without writing executable files to disk. It abuses legitimate system tools (PowerShell, WMI, .NET, macros, LOLBins).
Notable: Poweliks (2014), Kovter (2015), Duqu 2.0 (2015), Emotet (2017+), Astaroth (2018)
Risk: 🟡 Medium | Self-Replicates: ⚠️ Some variants
Cryptominers use victim’s compute resources (CPU, GPU) to mine cryptocurrency without consent.
Notable: Coinhive (2017), XMRig (2017+), WannaMine (2018), Graboid (2019), Kinsing (2019+), TeamTNT (2020+)
Risk: 🔴 Critical | Self-Replicates: ❌ No
Wiper malware is designed purely for destruction — overwriting, encrypting without key, or deleting data to render systems unrecoverable.
Notable: Shamoon (2012), DarkSeoul (2013), NotPetya (2017), Olympic Destroyer (2018), HermeticWiper (2022)
Risk: 🟠 High | Self-Replicates: ❌ No
Banking trojans are specialised malware designed to steal financial credentials and conduct fraudulent transactions using overlay attacks, form grabbing, webinjects, and SMS interception.
Notable: Zeus/Zbot (2007), SpyEye (2009), Citadel (2011), Gameover Zeus (2011), Dridex (2014), TrickBot (2016), Emotet (2014+), IcedID (2017), Qakbot (2007+)
Risk: 🟠 High | Self-Replicates: ❌ No
A form grabber hooks browser APIs to capture form data (credentials, credit cards, PII) before TLS encryption, bypassing HTTPS protection.
Notable: Zeus/Zbot (2007), SpyEye (2009), Citadel (2011), Tinba (2012), Dridex (2014), TrickBot (2016)