Computer Worm
A computer worm is malware that self-replicates across networks without user interaction, exploiting unpatched systems — unlike trojans, it needs no one to invite it in.
A computer worm is malware that replicates itself and spreads to other systems on its own, without a host file to infect and without a user to run it. That autonomy is what distinguishes a worm from its relatives: a virus attaches to other programs, a trojan horse talks its victim into installing it, but a worm simply finds the next vulnerable machine and copies itself over.
How it works
A worm needs a propagation mechanism — some channel through which it can reach and execute on new systems unaided. Historically that has meant exploiting unpatched network service vulnerabilities (the route WannaCry and NotPetya used in 2017 via the EternalBlue SMB exploit, spreading to hundreds of thousands of machines in hours), but worms also spread through weak or stolen credentials, open file shares, removable USB media, and email or messaging worms that mail themselves to every contact in a victim's address book. Once established, the worm's payload does the real damage: deploying ransomware, recruiting the machine into a botnet, installing backdoors, or simply consuming bandwidth and crashing systems through sheer replication. Because propagation is automatic, worm outbreaks move at machine speed — the containment window is measured in minutes, not days.
How to defend
Worms are the strongest argument for unglamorous fundamentals. Patch internet-facing and internal services promptly — a worm is, in effect, a scanner for whoever skipped an update, and the "update software" pillar of basic cyber hygiene exists largely because of them. Segment networks so one infected machine cannot reach every other, disable legacy protocols, and require strong authentication on every service, since modern worms spread through reused passwords as readily as through exploits. The human layer matters at the edges: email-borne worms still need a first click, USB worms need someone to plug in the drive, and fast reporting of strange machine behavior — covered in our guide to incident response for social engineering — buys the minutes that decide whether an outbreak is one laptop or the whole subnet.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo