Skip to main content
01543 524 594  ·  hello@initialit.co.uk
CYBER ESSENTIALS · MICROSOFT PARTNER · UK HELPDESK · 5.0 ★ GOOGLE
HomeBlog › Cyber Security

How to spot hidden malware on your devices

Modern malware is designed to stay invisible. Here are the signs your device might be infected, and what to do before damage is done.

Andy Price · Founder13 January 2026 · 5 min read

Modern malware is designed to stay invisible. Gone are the days of obvious pop-ups and slow performance announcing an infection. Today’s threats hide quietly, exfiltrate data, capture passwords and wait for the right moment to strike. By the time you notice something obvious, the damage is already done.

This guide covers the subtle signs that your device might be compromised, the tools that find what your eyes can’t, and the steps to take if you suspect something is wrong.

Key takeaways

  • Most modern malware is built to be invisible. The “obvious” symptoms staff associate with viruses (pop-ups, slowness) often aren’t there.
  • Look for: unexpected outbound network traffic, unfamiliar processes, sudden battery drain, slower performance over time, unauthorised account activity.
  • Run a proper EDR scan, not just a basic antivirus. Free tools have their place but are not a substitute.
  • If you genuinely suspect compromise, disconnect the device from the network and call your IT provider before doing anything else.
Key takeaways on how to spot hidden malware on your devices

The signs to watch for

Performance and behaviour

  • Slower than it used to be. Not just at boot, but consistently. Cryptominer malware is a common culprit; it uses your CPU/GPU silently.
  • Battery draining faster on a laptop. Hidden processes consume power.
  • Fan running constantly when you’re idle. Same reason.
  • Programs crashing or behaving unexpectedly. Especially security software refusing to update or run.

Network activity

  • Unexpected internet usage. If your usage has spiked without explanation, something might be sending data out.
  • New, unrecognised connections in Task Manager. Open Task Manager (Ctrl+Shift+Esc), Network tab, look for processes with high outbound traffic.
  • DNS queries to unfamiliar domains. Visible in your firewall or router logs.

Account and email behaviour

  • Email contacts saying they received emails from you that you didn’t send. Classic sign of a compromised account, sometimes via malware on the device.
  • Unexpected sign-in alerts from Microsoft 365 or other accounts.
  • Inbox rules you didn’t create. Attackers commonly add rules that auto-delete or auto-forward messages from finance/HR.
  • Saved passwords behaving oddly or password manager flagging unusual access.

System changes you didn’t make

  • New programs installed that you don’t recognise.
  • Browser homepage or default search engine changed.
  • Browser extensions you didn’t add.
  • Files appearing or disappearing from documents folders.
  • Antivirus or Windows Defender turned off without your knowledge.

The tools to actually find it

Visual checks are useful for raising suspicion. Confirming and removing malware needs proper tools.

Microsoft Defender for Endpoint

If your device is enrolled in our managed service, you already have Defender for Endpoint running. It’s a behaviour-based EDR (endpoint detection and response) tool that catches many threats antivirus misses. It also reports back to a central console where suspicious activity gets flagged for human review.

Microsoft Safety Scanner

Free, on-demand tool from Microsoft. Useful for a one-off scan if you suspect something. Doesn’t replace ongoing protection. Available at microsoft.com/safety-scanner.

Process Explorer (Sysinternals)

Free Microsoft tool that shows running processes in much more detail than Task Manager. Right-click a process, “Check VirusTotal” to see whether anyone else has flagged it. Available at learn.microsoft.com/sysinternals.

Wireshark / netstat

For network analysis. Most staff won’t need these. Useful when an IT team is investigating in depth.

What to do if you suspect compromise

  1. Disconnect from the network. Turn off Wi-Fi, unplug the Ethernet cable. This prevents further data exfiltration and stops the malware from spreading.
  2. Don’t sign in to anything. Especially not banking, email or sensitive systems. Assume keystrokes might be captured.
  3. Note what you’ve seen. Time, date, specific symptoms. Useful for the people who’ll investigate.
  4. Call your IT provider. If you don’t have one, call us on 01543 524 594. Don’t wait for them to “have a look” later, this is a same-hour call.
  5. From a different device, change passwords for any accounts you’ve used on the suspect device, starting with email.
  6. Don’t try to “clean” it yourself. Reformatting and reinstalling Windows is sometimes the only safe option, and that needs to happen with proper backups in place.

Frequently asked questions

How does malware get on my device in the first place?

Most commonly: phishing email attachments, drive-by downloads from compromised websites, malicious browser extensions, software downloaded from unofficial sources, USB drives picked up at conferences. Also from compromised software updates (the SolarWinds attack pattern, increasingly common).

Will reinstalling Windows definitely remove it?

For most malware, yes, when done properly with a USB-stick installer (not the device’s own recovery partition). Some advanced threats can persist in firmware or BIOS, but these are rare for SMBs and usually nation-state level.

Can my phone be infected too?

Yes, especially Android phones with apps installed from unofficial sources. iPhones are tighter but not immune. Same principle: keep your OS up to date, only install apps from the official store, watch for unusual battery drain or data usage.

How do you protect against this for managed clients?

Layered defence. Defender for Endpoint on every device, advanced email filtering blocking malicious attachments, Conditional Access blocking sign-ins from compromised devices, immutable backups so we can recover quickly. Plus quarterly cyber awareness training so staff don’t click the link in the first place.

Initial IT runs Microsoft Defender for Endpoint with 24/7 monitoring across every managed-IT client. If something hostile lands on your device, we usually know about it before you do.