What is the difference between a virus, malware, ransomware and spyware?
Malware is the umbrella term for any software written to cause harm. Everything else is a category within it, and the distinctions are about how it spreads or what it does.
Categories by how they spread:
Virus — attaches itself to a legitimate file or program and requires user action to execute and spread. The biological analogy is exact: it needs a host. True viruses are far less common than they were, but the word became a generic label for all malware, which is why "antivirus" software handles everything.
Worm — spreads by itself across networks with no user action, exploiting vulnerabilities. This self-propagation makes worms the fastest-spreading category; WannaCry spread this way.
Trojan — disguised as something desirable. It does not self-replicate; it relies on you installing it. Most modern malware arrives this way.
Categories by what they do:
Ransomware encrypts your files and demands payment for the key. Modern variants also exfiltrate data first and threaten publication — double extortion — so backups alone no longer remove the leverage.
Spyware covertly collects information. Keyloggers record keystrokes; infostealers harvest saved passwords, cookies and crypto wallets; stalkerware is marketed for monitoring partners or family and is a serious abuse vector.
Adware injects advertising, sometimes benign, sometimes a wrapper for worse.
Rootkit hides at a deep system level to evade detection.
Botnet malware conscripts your machine into a network used for attacks or spam.
Cryptojacking uses your hardware to mine cryptocurrency.
Fileless malware runs in memory using legitimate system tools, leaving little on disk for scanners to find.
Categories overlap constantly — a trojan can install a rootkit that deploys ransomware.
The defences are the same regardless: patch promptly, keep offline backups, use multi-factor authentication, and be suspicious of attachments and installers.