Malware Doesn't Look Like Malware Anymore
The mental image most people still carry around is decades out of date: a garish pop-up, a flashing "YOU HAVE WON" banner, a suspiciously named .exe from a website that looks like it was built in 2003. That stuff still technically exists, sure, in the same way fax machines technically still exist. It's not what's actually catching people. What's actually catching people looks helpful.
Modern malware's entire strategy is looking exactly like the thing you were already trying to install. That's the shift worth understanding, because the old advice — "don't click suspicious links" — assumes you can still tell what's suspicious. Increasingly, you can't, on sight alone.
The current top offenders, and why they work
Cracked game and software installers. Still the single most reliable delivery method there is, because the person downloading it has already made a decision to bypass a warning — they're expecting a sketchy download, so a Windows SmartScreen prompt doesn't register as unusual, it registers as expected friction. Bundled malware rides in on exactly that lowered guard.
Fake cracks for games that don't need cracking. A newer, meaner variation — malware disguised as a crack, trainer, or "unlock" for a free-to-play or already-purchased game, targeting people searching for cheats or mods rather than piracy specifically. The search intent is different but the trap is identical.
Malicious browser extensions. These are particularly nasty because they arrive through a legitimate channel — the actual extension store — often starting as a genuinely useful, well-reviewed tool before being sold to a new owner or quietly updated with malicious code months after you installed it and stopped paying attention.
Fake Discord bots and "free Nitro" links. Built specifically to exploit the trust baked into a platform where links get shared constantly between people who actually know each other. A link from a friend's compromised account doesn't trigger the same suspicion a random email does — which is exactly the point.
AI-generated phishing. Grammatically perfect, personally addressed, contextually plausible — the "written by someone who clearly doesn't speak English natively" tell that used to be a reliable red flag has largely stopped being reliable at all.
The permissions question that actually matters
Here's a genuinely useful mental shortcut that cuts through most of the disguises above: does this thing actually need what it's asking for? A wallpaper app requesting access to your clipboard and browsing history has no legitimate reason to want either of those things, regardless of how polished its installer looks or how many five-star reviews it has. A browser extension that claims to block ads shouldn't need permission to read and change data on every website you visit — some legitimately do for technical reasons, but it's worth being suspicious by default, not by exception.
What's actually changed about how you should protect yourself
- Source matters more than it ever did. Official storefronts, official extension marketplaces, official download pages. Not because they're infallible, but because they at least have a review process and a reporting mechanism between the malware and you.
- Update your mental model of "looks legit." Professional design, good grammar, and social proof (reviews, star ratings, follower counts) are all trivially fakeable now, and increasingly are faked. They're no longer meaningful signals on their own.
- Watch behaviour, not appearance, after install. Unexpected new browser extensions you didn't add, a spike in background network activity, your homepage or default search engine quietly changing — these are the actual tells now, and they show up after installation, not before.
- Keep something actually scanning in the background. Not as a silver bullet — nothing catches everything — but as a second opinion running continuously, rather than something you remember to run manually once a year after something's already gone wrong.
If you think something's already gotten in
The honest signs are rarely dramatic: a PC that's slower than it should be for no clear hardware reason, a browser doing things you didn't tell it to, fans running hot when nothing's actually open, or accounts logging you out unexpectedly on services you didn't touch. None of those alone is proof. Together, or persisting after an obvious fix, they're worth taking seriously.
Think something's already on your PC?
VoltTech's Virus & Malware Removal service does a full system sweep — not just a surface scan — and checks for the persistence tricks modern malware uses to survive a basic cleanup.
See Virus & Malware Removal →