Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Threat Protection
    Malware Severity Levels and Detection Types

    Malware Severity Levels and Detection Types

    There are three malware severity levels. Creating policies that block all three levels is recommended.

    SeverityTypes
    HighBackdoor
    Browser
    Coinminer
    Dialer
    Downloader
    Dropper
    Exploit
    Heuristic
    HTML Smuggling
    Hyperlink
    Infostealer
    Keylogger
    Malware
    Network
    Password Stealer
    Phishing
    Ransomware
    Rogue
    Rootkit
    Spam
    Spyware
    Trojan
    Virus
    Worm
    MediumNone
    LowAdware
    Bundler
    Greyware
    Hacktool
    Hoax
    Joke
    Keygen
    Malicious App
    Packed
    PUP/PUA

    The following table provides explanations for the detection types in the malware dashboard pages:

    TypeDescription
    AdwareThis type of malware displays advertisements on the user’s desktop, or in the web browser. Adware is also often used to monitor and report user browsing habits to the advertiser to bring more relevant ads. Some free applications available on the web contain the adware payload, which is usually installed with user consent, while some other adware applications are installed without user consent. As with spyware, the adware application is not a legitimate infected file, and therefore it can’t be disinfected.
    BackdoorThis type of malware opens up a secret entry point for the attackers to gain access to the target system. The malware can be used to install other malicious programs, monitor the system or user activities, transfer files, acquire passwords, execute arbitrary commands, etc.
    BrowserThis type of malware is web-based or online in nature that impacts the various browsers like Internet Explorer and Firefox. The browser-based threats include a range of malicious software programs that are designed to infect victims computers, like Exploit kits, malicious script redirections, phishing, etc.
    BundlerA software that installs multiple programs at once. It’s often used to sneak potentially unwanted programs (PUPs) or malware onto a system alongside a legitimate application.
    CoinminerThis type of malware secretly uses a victim’s computer resources (CPU or GPU) to mine cryptocurrency for the attacker’s benefit.
    Custom Profile HitThis type of malware matches an entry you added in the file hash list of a File Profile. The file profile name is appended to the malware name (e.g., Custom Blocklist Hit:File_Profile_Name).
    DialerThis is a type of malware which uses the modem connected to the computers to dial premium-rate numbers, incurring expensive phone bills for the victim. The malware usually comes bundled with legitimate software downloaded from third party and torrent sites.
    DownloaderA small program that downloads and executes other files that are usually more malicious from the internet onto the infected system.
    DropperA program designed to install or “drop” other malware onto a target system. It contains the malicious payload and the code to install it.
    ExploitThis type of malware takes advantage of a bug or vulnerability in order to get unauthorized access to the target system. Successful exploitation can be used to execute arbitrary code, download malwares, conduct denial of service, etc.
    GreywareA general term for software that falls into a grey area between malicious and legitimate. It’s not a full virus but can be annoying or cause performance issues, such as adware or spyware.
    HacktoolThis type of malware is used to identify tools and software that can be used by attackers to compromise systems and networks. Programs detected as Hacktools might not be malicious, but they are designed to perform certain actions that matches the characteristics of a malware. Hacktools can perform actions like port scanning, remote connectivity, vulnerability scanning, keygens, etc.
    HeuristicThis type of malware is based on rules, patterns, or weighing methods, and is used to detect variants of existing malware and zero-day malware. This malware typically does not have signature or pattern match-based detection.
    HoaxA false warning about a non-existent computer virus or other threat, often spread via email or social media to cause panic and waste time.
    HTML SmugglingThis type of malware uses a highly evasive malware delivery technique that abuses legitimate HTML5 and JavaScript features to evade detection and deploy banking malware, remote access Trojans (RATs), and other malware payloads related to targeted attacks.
    HyperlinkA link in a digital document that leads to another location. While not malware, malicious hyperlinks are a primary method used in phishing emails and on websites to direct users to malware downloads or fraudulent sites.
    InfostealerThis type of malware gathers confidential information, such as login credentials, credit card numbers, etc., from an infected system, and sends it to a pre-determined location.
    JokeA program designed to play a prank on the user, often by displaying funny images or playing sounds. While usually harmless, they can be disruptive.
    KeygenA program that generates a product licensing key for software. While often used for software piracy, keygens themselves can sometimes contain malware or be used as a delivery mechanism for it.
    KeyloggerThis type of malware is designed to capture keystrokes from the infected machine. The stolen information is then uploaded to its command and control server. Keyloggers can be used to capture information like credentials, email conversations, instant messages, etc.
    Malicious AppThis type of malware is used to refer an unknown or new family of malware. These apps are detected based on certain behavioral properties of the file that falls under malicious activities. This can include querying system information, detection of sandboxes or virtual machines, creating persistence, clearing traces, etc.
    MalwareThis is a generic type of malware for unknown or a new family of malware. The detection is made based on certain behavioral properties of the file that falls under malicious activities. This can include querying system information, detection of sandboxes or virtual machines, creating persistence, clearing traces, etc.
    Misleading AppThis is a type of application which itself may not be malicious but could be used for malicious activities. This includes web or socks proxies, remote administration software, and more.

    The object is an application which is often installed and used for malicious purposes by 3rd parties. While the application itself is not malicious, experience shows that it poses a higher risk (compared to others) of being used for malicious purposes and of being installed without user consent. This category includes web or socks proxies, remote administration software and other types of software. Usually, the detected application is easy to install without user consent, and once installed, it has an option to be almost or completely hidden from the user.

    This object may not be malicious, and may be legitimately installed by a user, so it should not be quarantined or removed by default; the user should be asked instead. Obviously, since it’s an application, it can only be removed, not disinfected.

    NetworkThis type of malware infection is capable of performing network-based attacks, like denial of service, flooding, and scanning. Network-based malware infections are also capable of flowing through the network to infect other systems connected within the same range of IP address.
    PackedThis type of malware affects the files that are obfuscated using commercial or open file packers. This serves as a code obfuscation technique as packers compress the original binary code using its custom algorithm. Packers are usually legitimate programs, but they are often used by malware authors in packing their own binaries to avoid getting detected through security detection technologies.
    Password StealerA type of malware designed specifically to harvest login credentials, such as usernames and passwords, from web browsers, applications, and system files.
    PhishingThis type of malware attempts to obtain sensitive information, such as password and credit card numbers, by disguising as a trustworthy entity.
    PUP/PUAThis type of malware, Potentially unwanted applications (PUA), are programs that are unwanted and usually ships with freeware softwares and tools. PUAs are used to launch hoax advertisements, fake anti-virus scans, selling rogue products, and even launching man-in-the-browser (MitB) attacks.
    RansomwareThis type of malware encrypts the victim’s files and displays a ransom note demanding payment, usually in cryptocurrency, in exchange for the decryption key.
    RogueThis type of malware misleads users into believing there is a virus on their computer and aims to trick them into paying for a fake malware removal tool.
    RootkitA collection of software tools that enables an unauthorized user to gain control of a computer system while hiding its presence and the presence of other malware.
    SpywareThis type of malware is installed on a computing device without the end user’s knowledge to gather information about them, their browsing habits, or other data, which is then sent to a third party.
    SpamUnsolicited, unwanted commercial email messages or other electronic messages, often sent in bulk. While not malware itself, it’s a common delivery method for malware and phishing attacks.
    TrojanThis is a type of malware that disguises itself as a legitimate or useful application to trick the user into installing and running it. Once executed, it performs malicious actions.
    VirusThis is a type of malware that, when executed, replicates itself by modifying other computer programs and inserting its own code. It requires a host program to run and spread.
    WormA standalone malware computer program that replicates itself to spread to other computers, often using a computer network. Unlike a virus, it does not need to attach itself to an existing program.
    In this Topic
    • Malware Severity Levels and Detection Types