Defence Framework
Part V — The Malware Ecosystem & Defence Framework
Section titled “Part V — The Malware Ecosystem & Defence Framework”Modern malware operates within a sophisticated criminal economy with a clear division of labour:
- RaaS — Developers rent tools to affiliates (70-80% revenue share)
- IABs — Sell initial access on dark web markets
- Exploit Brokers — Sell 0-days to nation-states/criminals
- MaaS — Turnkey tools for rent (Emotet, TrickBot, Qakbot)
- Cryptocurrency — Anonymous payments, mixing, laundering
This division of labour has lowered the skill barrier and dramatically increased attack volume.
Industry-standard taxonomy with 14 tactics:
| # | Tactic | Description |
|---|---|---|
| 1 | Reconnaissance | Gathering target intelligence |
| 2 | Resource Development | Acquiring infrastructure/tools |
| 3 | Initial Access | Gaining first foothold |
| 4 | Execution | Running malicious code |
| 5 | Persistence | Maintaining access |
| 6 | Privilege Escalation | Gaining higher permissions |
| 7 | Defence Evasion | Avoiding detection |
| 8 | Credential Access | Stealing credentials |
| 9 | Discovery | Understanding environment |
| 10 | Lateral Movement | Moving through network |
| 11 | Collection | Gathering data |
| 12 | Command and Control | Maintaining communication |
| 13 | Exfiltration | Stealing data |
| 14 | Impact | Disrupting availability/integrity |
Seven pillars of organisational cyber defence:
| # | Pillar | Key Principle |
|---|---|---|
| 1 | Patch Management | Critical patches within 72h; internet-facing 24h |
| 2 | Least Privilege | Minimum permissions; JIT access; tiered admin |
| 3 | Defence in Depth | Layered controls: perimeter → network → endpoint → identity → app → data → human → recovery |
| 4 | Backup & Recovery | 3-2-1 rule; immutable; tested quarterly |
| 5 | User Awareness | Quarterly training; phishing sims; no-blame reporting |
| 6 | Zero Trust | Never trust, always verify; FIDO2; micro-segmentation |
| 7 | Incident Response | Tested playbooks; tabletop quarterly; red/purple team |
| Malware Type | Risk | Self-Replicates | Primary Goal |
|---|---|---|---|
| Computer Virus | 🟠 High | ✅ Host-attached | Damage/Replicate |
| Computer Worm | 🔴 Critical | ✅ Standalone | Mass Propagation |
| Trojan Horse | 🟠 High | ❌ No | Backdoor/Theft |
| Spyware | 🟠 High | ❌ No | Surveillance |
| Adware | 🟡 Medium | ❌ No | Ad Revenue |
| Ransomware | 🔴 Critical | ⚠️ Some | Extortion |
| Rootkit | 🔴 Critical | ❌ No | Persistence |
| Keylogger | 🟠 High | ❌ No | Credential Theft |
| Backdoor | 🔴 Critical | ❌ No | Persistent Access |
| Botnet | 🔴 Critical | ✅ Yes | Coordinated Attacks |
| APT Malware | 🔴 Critical | ❌ No | Espionage |
| Fileless | 🔴 Critical | ❌ No | Evasion/Access |
| Cryptominer | 🟡 Medium | ⚠️ Some | Revenue |
| Wiper | 🔴 Critical | ❌ No | Destruction |
| Mobile | 🟠 High | ⚠️ Some | Data Theft |
| Web Shell | 🟠 High | ❌ No | Server Control |
| AI-Powered | 🔴 Critical | 🔬 Hypothetical | Adaptive Attack |
| Post-Quantum | 🟠 High | 🔬 Hypothetical | Crypto Breaking |
| UEFI/Firmware | 🔴 Critical | ❌ No | Deep Persistence |
| Supply-Chain | 🔴 Critical | ❌ No | Mass Infection |
| OT/ICS | 🔴 Critical | ⚠️ Some | Physical Damage |
| Polymorphic | 🟠 High | ✅ Yes | Detection Evasion |
Weekly Update Process
Section titled “Weekly Update Process”This encyclopaedia is updated weekly with:
- New malware families from threat intelligence feeds
- Updates to existing entries with new variants/techniques
- MITRE ATT&CK technique mappings
- Defensive tool coverage updates
Last updated: {{ git_revision_date_localized }}