What Is Malware? A Plain-English Guide for New Zealanders

Illustration of a laptop infected with a red computer bug, surrounded by icons for phishing email, ransomware and spyware and a teal protective shield, next to the heading "What Is Malware? A plain-English guide for New Zealanders".

Malware — short for “malicious software” — is any program written to damage a device, steal information, spy on you, or take control of a system without your permission. It is an umbrella term, not a single thing: viruses, ransomware, spyware, trojans and worms are all types of malware. The simplest test is consent. If a piece of software does something to your device, your files or your accounts that you never agreed to, it almost certainly counts as malware. This guide explains the main types in plain English, shows exactly how an infection happens, and sets out the defences that genuinely work for New Zealand households and small businesses in 2026.

Key Points

  • Malware is any software built to harm, spy on or hijack a device without consent — viruses, ransomware, spyware, trojans and worms are all types.
  • Phishing email is the most common way attackers deliver malware to New Zealanders; most infections exploit a flaw that already has a patch.
  • No single tool catches everything. Layered defence works best: a reputable anti-malware tool, automatic updates, unique passwords in a password manager, versioned backups and two-factor authentication.
  • A VPN is not anti-malware — it encrypts traffic but does not scan files or remove infections.
  • If you suspect an infection, disconnect from the network first, then scan or restore from a clean backup. Report serious incidents to the NCSC.

Why malware matters for New Zealanders

New Zealand is a small, highly connected country, and that combination makes it an attractive target. As a member of the Five Eyes intelligence-sharing alliance (with the United States, United Kingdom, Canada and Australia), NZ is on the radar of state-linked actors, while everyday Kiwis face the same flood of automated, financially motivated attacks as everyone else online.

The legal backdrop has real teeth now. Under the Privacy Act 2020, an organisation that suffers a data breach likely to cause serious harm — including a breach caused by malware — must notify the Office of the Privacy Commissioner and the affected people as soon as practicable (in practice, within about 72 hours). Failing to report a notifiable breach is an offence carrying a fine of up to NZ$10,000. In short, when a NZ business is hit by ransomware or a data-stealing trojan, the consequences are financial and legal, not just reputational.

The National Cyber Security Centre (NCSC) is now the country’s lead operational cyber-security agency. CERT NZ — the team most people know for consumer advice and incident reporting — completed its integration into the NCSC in 2024, so individuals, small businesses and large organisations can now report incidents and read advisories in one place. Those advisories consistently show that phishing emails carrying malware are one of the most common ways attackers get their first foothold, and that New Zealanders lose millions of dollars a year to cybercrime.

Faster internet has not made this safer. The shift to Chorus fibre — including Hyperfibre plans now running at 2Gbps, 4Gbps and 8Gbps — means a Kiwi home connection is quicker than ever, but speed cuts both ways: once malware has a foothold, a fast link simply lets it exfiltrate your data or pull down extra payloads more quickly. NZ providers such as Spark, One NZ and 2degrees offer some network-level filtering of known-bad domains, but that is not a substitute for protection on the device itself. ISP filters cannot inspect encrypted traffic or stop a malicious attachment you choose to open. For a broader look at how these attacks reach people here, see our guide to cyber attacks in New Zealand.

The main types of malware

Knowing the categories helps you recognise a threat and pick the right defence. These labels are not mutually exclusive — modern malware routinely combines several techniques in one package.

  • Viruses: self-replicating code that attaches to a legitimate file and needs a user action — opening a document, running a program — to activate and spread.
  • Worms: like viruses but self-propagating across a network with no user interaction, which makes them especially dangerous on business networks.
  • Trojans: malware disguised as something you want. You install what looks like a free game or a “cracked” app, and in the background it opens a backdoor or steals your passwords.
  • Ransomware: encrypts your files and demands payment — usually in cryptocurrency — for the key. NZ schools, health providers and small businesses have all been hit. Paying does not guarantee you get your data back.
  • Spyware: quietly watches what you do, capturing keystrokes, screenshots and browsing history. It is often bundled with free downloads.
  • Adware: floods you with unwanted ads and browser redirects, and frequently acts as a delivery channel for something worse.
  • Rootkits: burrow deep into the operating system — sometimes into firmware — making them very hard to detect or remove.
  • Botnet clients / RATs: Remote Access Trojans turn your device into one node of a botnet used to send spam, run denial-of-service attacks or mine cryptocurrency at your expense.
  • Fileless malware: runs entirely in memory and leaves no file on disk, which lets it slip past traditional signature-based antivirus.
  • Info-stealers: a fast-growing category that grabs saved browser passwords, session cookies and crypto-wallet data and ships it straight to a criminal marketplace.

How malware gets onto your device, step by step

Malware does not appear by magic. There is almost always a chain of events, and understanding that chain is where your defence begins — because breaking any single link stops the attack.

  1. Initial contact: you receive a phishing email pretending to be from IRD, NZ Post or your bank; or you visit a compromised website, click a malicious ad, or download software from an unofficial source. In business settings, attackers also probe internet-facing services for unpatched flaws.
  2. Delivery: the payload arrives — a macro-enabled Word document, a “drive-by” download triggered by your browser, or malware hidden inside a legitimate-looking installer.
  3. Execution: something runs the code. That might be you opening an attachment, a document macro firing automatically, or an exploit taking advantage of an unpatched PDF reader or browser.
  4. Persistence: the malware writes itself into startup locations — the Windows registry, a macOS LaunchAgent, a Linux cron job — so it survives a reboot.
  5. Command and control (C2): it “phones home” to an attacker-controlled server, usually over HTTPS so the traffic blends in. This is where it receives instructions and sends stolen data out.
  6. Action on objectives: depending on the type, this is where files get encrypted, credentials get harvested, or your device is quietly enrolled in a botnet.

For automated attacks the gap between step one and step six can be seconds; for a targeted intrusion it can be weeks, as attackers move slowly to avoid tripping alarms. Either way, the earlier you interrupt the chain, the less damage is done.

Common mistakes NZ users make

Treating a VPN as anti-malware. A VPN encrypts your traffic and hides your IP address; it does not scan downloads, block malicious code or remove an infection. Some providers add DNS-level blocking of known-bad domains (Surfshark’s CleanWeb, NordVPN’s Threat Protection, Mullvad’s content blocking), but that is a supplement, not a substitute. For what a VPN really does, see our plain-English VPN guide.

Downloading from unofficial sources. Cracked software and unofficial app stores are the single most reliable way consumers pick up trojans. The same applies on mobile: sideloaded Android APKs from outside the Play Store are a major vector.

Ignoring updates. Most successful infections exploit a known flaw for which a patch already exists. On a fibre connection, updating Windows, macOS or your router firmware takes minutes — there is no good reason to run unpatched software.

Re-using one password everywhere. An info-stealer only has to grab a single password before attackers try it across every service you use. A password manager with a unique login per site keeps one theft from becoming ten.

Not backing up. Ransomware is devastating precisely because victims have no leverage without backups. Follow the 3-2-1 rule — three copies, on two types of media, with one kept offsite — and use backups with version history so ransomware cannot simply encrypt the backup too.

Assuming the built-in tools are enough on their own. Microsoft Defender and macOS Gatekeeper are genuinely good baselines and should always be switched on, but pairing them with a dedicated scanner catches threats that slip past a single signature database.

Warning signs your device may be infected

Some infections announce themselves — ransomware will literally tell you. Others are built to stay invisible. Watch for:

  • Unexplained slowdowns, or high CPU and memory use when the device should be idle.
  • Unfamiliar processes in Task Manager (Windows) or Activity Monitor (macOS).
  • Your browser home page or default search engine changing on its own.
  • Antivirus that has been disabled or can no longer update.
  • Unusual outbound traffic, especially to unexpected overseas addresses (check your router’s logs).
  • Accounts being locked, or password-reset emails you never requested.
  • Files with strange new extensions, or a ransom note sitting on your desktop.

If you suspect an infection, disconnect from the internet and any local network straight away to stop data leaving and to prevent the malware spreading to other devices. For most home users the practical next step is to reboot into Safe Mode and run a full scan; if you need to remove something stubborn on a phone, our step-by-step guide to removing malware from Android walks through the process.

Anti-malware tools and indicative NZD pricing

The table below covers the main anti-malware options available to NZ consumers and small businesses. Almost every vendor prices in US dollars and converts at checkout, and nearly all use a low first-year price that jumps sharply on renewal — so treat the figures as indicative and always check the renewal price before you buy. For a deeper comparison, see our best antivirus for New Zealand roundup and the broader antivirus software guide.

Anti-Malware Tools Compared

ToolTypePlatformsIndicative NZD/yearNotes
Microsoft DefenderBuilt-in baseline AVWindowsFreeSolid baseline included with Windows; keep it enabled and updated.
Malwarebytes FreeOn-demand scannerWin, Mac, Android, iOSFreeNo real-time protection; excellent for second-opinion scans.
Malwarebytes PremiumAnti-malwareWin, Mac, Android, iOS~NZ$70–110Strong on adware and unwanted programs; a good complement to Defender.
Bitdefender Total SecurityFull suiteWin, Mac, Android, iOS~NZ$40 first year / ~NZ$150 renewal (5 devices)Consistently top-rated detection with low system impact.
ESET Internet SecurityFull suiteWin, Mac, Linux, Android~NZ$75Linux support makes it handy for mixed-OS households.
Norton 360 DeluxeFull suiteWin, Mac, Android, iOS~NZ$45 first year / ~NZ$170 renewalBundles a VPN and cloud backup; watch the renewal jump.

For a careful NZ home user — one who keeps their operating system updated, avoids dodgy download sites and uses a password manager — Microsoft Defender left switched on, plus an occasional Malwarebytes Free second-opinion scan, is a reasonable no-cost baseline. If you want continuous real-time protection beyond Defender, a mainstream paid suite such as Bitdefender for a whole household is strong value in the first year. Small businesses should look at endpoint detection and response (EDR) rather than consumer antivirus, because the threat model is different.

One product to note: Kaspersky, long a strong performer in independent lab tests, has been banned from sale to and updates for US customers since 29 September 2024 under a US Commerce Department determination citing national-security risk tied to its Russian ownership. It is not banned for private use in New Zealand, but for a Five Eyes audience the jurisdiction question is a real one, which is why it is not included above.

Protecting your NZ accounts and personal data

Info-stealing malware specifically targets the passwords saved in your browser, which means your streaming logins — TVNZ+, Neon, Sky Sport Now, ThreeNow — are at risk alongside your banking. Stolen streaming credentials are sold in bulk on criminal marketplaces, then either used directly or resold. The single most effective countermeasure is two-factor authentication (2FA): even if a password leaks, the attacker still cannot log in without your second factor. Turn it on for every financial, email and streaming account that supports it.

Remember that the Privacy Act 2020 protects you when an organisation you deal with is breached — it does not cover malware on your own devices. That responsibility sits with you, and the good news is that the basics are cheap and effective.

Malware on phones and tablets

Android is more exposed than iOS because it allows apps from outside the official store. Stick to Google Play, keep Google Play Protect switched on, and be sceptical of any app requesting permissions it has no reason to need. iOS is not immune — malicious configuration profiles and, historically, zero-click exploits have been used against high-value targets — but the average Kiwi faces far lower everyday risk on an iPhone.

On both platforms, be wary of text-message phishing (“smishing”) that tries to push you toward installing an app from outside the store. NZ Post and IRD are among the brands most often impersonated in these campaigns.

Router and firmware malware

Your router deserves special attention because it sits upstream of every device in the house, so infected router firmware can intercept traffic before any endpoint protection sees it. Routers supplied by Spark, One NZ and 2degrees are generally kept updated automatically, but third-party and older models may not be. Log into the admin panel, install any firmware update, change the default admin password, and switch off remote management if you do not use it.

Vanliga frågor (FAQ)

Can Macs get malware?

Yes. macOS has strong built-in defences — Gatekeeper, XProtect and System Integrity Protection — but Mac malware is real and growing as Apple’s market share rises. Adware, browser hijackers and info-stealers aimed at macOS are well documented. Do not assume a Mac is immune: keep it updated and consider a reputable third-party scanner for peace of mind.

Does a VPN protect me from malware?

Not directly. A VPN encrypts your internet traffic and hides your IP address, but it does not scan the files you download or stop malicious code running on your device. Some VPNs add DNS-based blocking that can prevent connections to known malware servers, which is a useful extra layer — but it is no replacement for dedicated anti-malware software.

What should I do if I think I have ransomware?

Disconnect from the internet and your local network immediately so it cannot spread to other devices or shared drives. Do not rush to pay — payment does not guarantee decryption and it funds more attacks. Check the No More Ransom project to see whether a free decryptor exists for your ransomware variant, then restore from a clean backup if you have one, or seek professional help. Report the incident to the NCSC so others can be warned.

Is free antivirus enough for a NZ home user?

For a careful user who keeps their system updated, avoids unofficial software and uses a password manager, Microsoft Defender plus periodic Malwarebytes Free scans is a reasonable baseline. Free tools generally lack real-time web protection, email scanning and advanced behavioural detection, so if you do online banking, run a small business, or share a device with less security-conscious family members, a paid suite adds meaningful protection for a modest first-year cost.

Can my router really be infected?

Yes. Router malware is less common than PC malware but more dangerous, because the router handles traffic for every device on your network before any endpoint protection can inspect it. Log into your router’s admin panel, apply firmware updates, change the default admin password and disable remote management if you do not need it — that closes off the most common ways routers get compromised.