Malware delivery is a persuasion problem, not a technical one. The most reliable way onto a modern, patched device is not an exploit but the user’s own click: convince a person to open, run, allow, or install something, and their permissions become the attacker’s. The malicious file is disguised as something you want or expect, and the surrounding message supplies a reason to act now and to override the warnings that would otherwise stop you. This entry describes only what a victim sees and how to avoid being tricked — no detail of how malware is written, packaged, or made to work.
Victims meet a recognizable set of disguises. Unexpected attachments arrive as invoices, receipts, résumés, or shipping notices — sometimes a document that then asks you to “enable content” or “enable macros” to “see” it (a real document never needs that). Fake updates and installers pose as a browser, media player, or security tool, often via a pop-up or a poisoned download ad rather than the vendor’s own app. “Copy-paste” / fake-verification lures instruct you to paste text into a system dialog or press a key sequence “to prove you’re human” or “fix” a page.
In every case the payload is downstream and irrelevant to defense; what matters is the victim-visible pattern — an unexpected file or prompt, a story that pressures you to run it, and a request to bypass a warning. Its defining feature for you: you are being asked to be the one who installs it.