Skip to content

Defence Framework

Part V — The Malware Ecosystem & Defence Framework

Section titled “Part V — The Malware Ecosystem & Defence Framework”

Modern malware operates within a sophisticated criminal economy with a clear division of labour:

  • RaaS — Developers rent tools to affiliates (70-80% revenue share)
  • IABs — Sell initial access on dark web markets
  • Exploit Brokers — Sell 0-days to nation-states/criminals
  • MaaS — Turnkey tools for rent (Emotet, TrickBot, Qakbot)
  • Cryptocurrency — Anonymous payments, mixing, laundering

This division of labour has lowered the skill barrier and dramatically increased attack volume.


Industry-standard taxonomy with 14 tactics:

#TacticDescription
1ReconnaissanceGathering target intelligence
2Resource DevelopmentAcquiring infrastructure/tools
3Initial AccessGaining first foothold
4ExecutionRunning malicious code
5PersistenceMaintaining access
6Privilege EscalationGaining higher permissions
7Defence EvasionAvoiding detection
8Credential AccessStealing credentials
9DiscoveryUnderstanding environment
10Lateral MovementMoving through network
11CollectionGathering data
12Command and ControlMaintaining communication
13ExfiltrationStealing data
14ImpactDisrupting availability/integrity

Seven pillars of organisational cyber defence:

#PillarKey Principle
1Patch ManagementCritical patches within 72h; internet-facing 24h
2Least PrivilegeMinimum permissions; JIT access; tiered admin
3Defence in DepthLayered controls: perimeter → network → endpoint → identity → app → data → human → recovery
4Backup & Recovery3-2-1 rule; immutable; tested quarterly
5User AwarenessQuarterly training; phishing sims; no-blame reporting
6Zero TrustNever trust, always verify; FIDO2; micro-segmentation
7Incident ResponseTested playbooks; tabletop quarterly; red/purple team

Malware TypeRiskSelf-ReplicatesPrimary Goal
Computer Virus🟠 High✅ Host-attachedDamage/Replicate
Computer Worm🔴 Critical✅ StandaloneMass Propagation
Trojan Horse🟠 High❌ NoBackdoor/Theft
Spyware🟠 High❌ NoSurveillance
Adware🟡 Medium❌ NoAd Revenue
Ransomware🔴 Critical⚠️ SomeExtortion
Rootkit🔴 Critical❌ NoPersistence
Keylogger🟠 High❌ NoCredential Theft
Backdoor🔴 Critical❌ NoPersistent Access
Botnet🔴 Critical✅ YesCoordinated Attacks
APT Malware🔴 Critical❌ NoEspionage
Fileless🔴 Critical❌ NoEvasion/Access
Cryptominer🟡 Medium⚠️ SomeRevenue
Wiper🔴 Critical❌ NoDestruction
Mobile🟠 High⚠️ SomeData Theft
Web Shell🟠 High❌ NoServer Control
AI-Powered🔴 Critical🔬 HypotheticalAdaptive Attack
Post-Quantum🟠 High🔬 HypotheticalCrypto Breaking
UEFI/Firmware🔴 Critical❌ NoDeep Persistence
Supply-Chain🔴 Critical❌ NoMass Infection
OT/ICS🔴 Critical⚠️ SomePhysical Damage
Polymorphic🟠 High✅ YesDetection Evasion

This encyclopaedia is updated weekly with:

  • New malware families from threat intelligence feeds
  • Updates to existing entries with new variants/techniques
  • MITRE ATT&CK technique mappings
  • Defensive tool coverage updates

Last updated: {{ git_revision_date_localized }}