Skip to main content
Malware & AttacksUpdated September 3, 2026

Polymorphic Malware

Polymorphic malware changes its own code or packaging on each infection or each build so that no two samples share a file hash or a static signature, while the behaviour stays the same. It defeats hash-based blocklists and forces detection onto behaviour, network indicators and the infrastructure the samples share.

Signature detection works by recognising bytes that have been seen before. Polymorphism is the answer to it: an encrypted payload with a different key each time, a mutating decryption stub, junk instructions inserted at random, a packer that produces a fresh binary per download. The program does exactly the same thing on every machine; it just never looks the same.

The practical consequence is that a file hash identifies one sample, not a family. A feed of hashes from yesterday’s campaign catches yesterday’s binaries. Detection has to move to what does not change: the behaviour once running, the memory image after unpacking, and the domains and addresses the sample contacts.

That is where intelligence regains its footing. A thousand unique hashes that all beacon to the same three domains are one campaign, and the domains are its stable indicators. Hash reputation still has a role, as confirmation when a sample is already known, but it is the network layer that identifies the polymorphic family.

Example

An e-mail campaign delivers 4 000 attachments in a day; 4 000 distinct SHA-256 hashes, none previously seen. Every sample, once opened, resolves one of two domains registered the week before. The hashes are useless as a blocklist; the two domains stop the campaign.

In isMalicious

The file hash lookup at /threat-intel/file-hash answers whether a sample is already known to the hash sources isMalicious aggregates, and a report on the domain or address the sample contacts is where a polymorphic family is actually identified.

Frequently Asked Questions

What is Polymorphic Malware?

Polymorphic malware changes its own code or packaging on each infection or each build so that no two samples share a file hash or a static signature, while the behaviour stays the same. It defeats hash-based blocklists and forces detection onto behaviour, network indicators and the infrastructure the samples share.

How is Polymorphic Malware related to Malware?

Polymorphic Malware and Malware are both key concepts in threat intelligence. Malware is any software designed to harm, exploit, or gain unauthorized access to a system. It includes viruses, worms, trojans, ransomware, spyware, adware, rootkits, and more. Detection relies on file hashes, behavioral signatures, and threat intelligence feeds.

Related Terms

Put this intelligence to work

Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.

Check any indicator free
← Back to Glossary