Malware is a broad category of malicious software; CISA describes ransomware as one type. Spoofing deceives a system or person about identity or origin, while OWASP describes XSS as browser-side script injection. These terms may appear on the same security checklist, but they describe different mechanisms and targets.
Core words
The diagram classifies the attacks by behavior. It does not mean every ransomware infection begins with spoofing or that every XSS incident installs malware.
| English term | Meaning and use |
|---|---|
Malware | Software intentionally designed to harm, disrupt, spy on, or gain unauthorized control of a system. |
Ransomware | Malware that denies access to data or systems, often by encrypting files, and demands payment; paying does not guarantee recovery. |
MOTP | Mobile One-Time Password: a one-use authentication code generated or used on a mobile device. It is an authentication term, not an attack type. |
Smishing(SMS phishing) | Phishing delivered by text message, often using a deceptive link or request to obtain credentials or money. |
Sniffing | Capturing and inspecting network traffic; whether it is authorized monitoring or an attack depends on context and access. |
Snooping | Secretly observing another person's information or activity, often without authorization. |
Spoofing | Falsifying an identity, address, or origin so a message or system appears to be someone or something else. |
Scanning | Probing systems to identify hosts, services, or weaknesses; also used legitimately in authorized assessment. |
Words to distinguish together
| English term | Meaning and use |
|---|---|
Trojan horse | Malware disguised as legitimate software or content to persuade a user to run it. |
Pharming | Redirecting users to a fraudulent site by manipulating name resolution or another navigation path, even when they intended a legitimate address. |
Doxing | Gathering and publishing someone's private identifying information without permission, commonly to harass or expose them. |
Doxware | Extortionware that threatens to expose stolen private information unless a demand is met. |
Spyware | Software that secretly collects information about a user or device, often without meaningful consent. |
Worm | Self-replicating malware that can spread across systems or networks without attaching to a separate host program. |
Cracking | Unauthorized defeat of system protections or access controls; the word can refer to several distinct activities and needs context. |
Hoax | A false warning or fabricated claim, such as a nonexistent security threat, circulated to mislead people. |
Words encountered in security work
| English term | Meaning and use |
|---|---|
Buffer overflow | Writing past a buffer boundary, potentially causing a crash, data corruption, or exploitable code execution. |
Brute force attack | Systematically trying candidate passwords or keys; the attempts need not be in random order. |
Backdoor | A hidden route that bypasses normal access controls; an unauthorized one is a serious vulnerability or malicious feature. |
Crack | A tool or modification that defeats a software protection mechanism, often discussed in the context of license or access circumvention. |
Threat | A potential source or act of harm. It differs from a vulnerability (a weakness) and risk (likelihood and impact in context). |
Secure coding | Developing software with practices intended to reduce vulnerabilities during design and implementation. |
Session hijacking | Taking over or misusing another user's authenticated session. |
XSS | Cross-Site Scripting: injecting script or other active content into a web page so it runs in another user's browser context. |
A passage from a security review
Malware names a broad software category. Ransomware and spyware describe more specific behavior, while spoofing and XSS describe different ways an attack can be carried out.
When reading a finding, ask what asset is targeted, what weakness exists, and what action the attacker takes. A scan alone does not establish compromise. A threat is not the same as an exploitable vulnerability, and an authentication control such as MOTP is not itself an attack.
Key takeaways
Do not collapse malware, attack methods, weaknesses, and risk into one category. Ransomware and spyware describe malicious software behavior; spoofing describes deception; XSS describes browser-side injection. Precise terms help you choose the relevant evidence and defense.

