What is riskware? Definition, examples and protection

Riskware refers to legitimate software that can potentially be risky if misused, outdated, or exploited. You can stay one step ahead with awareness and the right protections in place. Learn how it works, then get a trusted antivirus solution to help detect suspicious behavior early, and keep you safer from the threats that riskware poses.

AV Comparatives award

2025

Consumer

Security Innovator

av test award

2026

Top Rated Product

Weathered triangular warning sign with a red border and yellow background, showing a bold black exclamation mark, mounted outdoors near industrial structures under a cloudy sky.

Riskware is legitimate software that isn’t inherently dangerous, but can pose a threat under certain circumstances. The risk lies in how the software is configured, used, or exploited by attackers. This means otherwise benign applications may be classified as riskware when their capabilities introduce unnecessary or exploitable risk.

Read our guide to learn more about riskware, including how to spot, remove, and help prevent riskware threats.

What is riskware and how it works

Riskware is software that isn’t designed to be malicious but has features or permissions that can create security risks. For example, remote-access tools, system utilities, and other powerful applications have legitimate uses but may also provide capabilities attackers can abuse to access sensitive data, change system settings, monitor activity, or gain control of a device.

A graphic shares the steps of how riskware works.
A graphic shares the steps of how riskware works.
A graphic shares the steps of how riskware works.

Here’s an example of how riskware becomes dangerous:

  1. A user installs a legitimate app. The software has a valid purpose but includes capabilities that could create security risks. Common types of riskware include remote administration tools, file-sharing programs, and system utilities.
  2. The software is misused or exploited: An attacker may abuse legitimate features, take advantage of excessive permissions or insecure settings, or exploit an unpatched vulnerability to gain unauthorized access.
  3. The attacker gains additional access: Depending on the software and permissions involved, the attacker may be able to install malware, access sensitive information, monitor activity, or take control of parts of the device.

That’s what makes riskware difficult to classify: the software itself may be legitimate, but its features or configuration can create opportunities for abuse.

Riskware vs. malware: The main differences

The main difference between riskware and malware comes down to intent. Malware is deliberately created to harm, disrupt, steal data, or spy on users. Riskware, by contrast, is legitimate software designed for a valid purpose. Its danger stems from features, permissions, insecure settings, or vulnerabilities that attackers may abuse.

As with other types of legitimate software, riskware is typically distributed through above-board channels, such as official app stores or trusted developers’ websites. Malware can spread through many routes, including scams, social engineering, malicious downloads, compromised websites, and software vulnerabilities.

Examples of common riskware programs

Riskware is more common than you might realize, and you may already use programs that could fall into this category. Again, it’s important to note that while these tools themselves aren’t malicious, they can still be used to compromise your security.

Here are some common types of riskware and how they can affect your cybersecurity.

A graphic shows the common types of riskware you can encounter in the real world, such as file downloaders, user activity monitors, password managers, and more.
A graphic shows the common types of riskware you can encounter in the real world, such as file downloaders, user activity monitors, password managers, and more.
A graphic shows the common types of riskware you can encounter in the real world, such as file downloaders, user activity monitors, password managers, and more.

Monitoring tools

Monitoring software such as parental control or device management tools can legitimately track activity, enforce restrictions, or collect information from a phone or computer. However, these capabilities can also create privacy and security risks if the software is misconfigured, compromised, or used without authorization.

For example, in 2023, researchers discovered multiple vulnerabilities in the Kids Place parental control app. The flaws could potentially expose credentials, allow malicious files to be uploaded, and enable restrictions to be bypassed. The developer subsequently released updates addressing the vulnerabilities, demonstrating why installing software security updates is so important.

File-sharing apps

File-sharing applications allow users to exchange files directly or through online services. But peer-to-peer (P2P) applications, in particular, can expose users to files from unknown or untrusted sources.

The application itself isn’t necessarily dangerous, but risks can arise from downloading unverified content, unintentionally sharing sensitive files, or using settings that expose more data than intended. Files distributed through P2P networks may also contain malware disguised as legitimate software, media, or documents.

Browser extensions

Browser extensions add useful features to your browser, but some require expansive permissions to read website data, modify pages, or monitor browsing activity.

These capabilities can create security and privacy risks if an extension requests unnecessary permissions, is compromised, or is deliberately abused. A risky extension could potentially collect browsing data, inject unwanted advertisements or content, redirect searches, or access sensitive information displayed in your browser.

Remote administration tools

Remote administration tools allow authorized users to access and control computers from another location. Technologies and applications such as Remote Desktop Protocol (RDP) and AnyDesk are commonly used for IT support, remote work, and system administration.

However, these same capabilities can pose security risks if cybercriminals abuse legitimate remote-access tools to control devices, steal files, install malware, or move through a network while appearing to perform normal admin or diagnostic activity.

System utilities and password recovery software

System utilities and password recovery tools perform tasks such as changing system configurations, recovering credentials, and troubleshooting devices. Because some of these tools require elevated privileges or can access sensitive information, their capabilities may also be valuable to attackers.

After compromising a device, an attacker could abuse these utilities to extract credentials, modify security settings, disable protections, or gain additional access. As with other forms of riskware, the tool itself isn’t malicious; it's the powerful functionality and potential for misuse that creates the risk.

Diagnostic and administration tools

Diagnostic and administration tools help IT professionals troubleshoot problems, inspect networks, monitor systems, and manage devices. To perform these tasks, they may provide detailed system information or powerful administrative capabilities.

Attackers who have already compromised a device can abuse these tools to discover other systems, inspect configurations, execute commands, or make changes while using software that may appear legitimate to security tools.

Software cracks and key generators

Software cracks and key generators are designed to bypass licensing or activation restrictions. Unlike most other forms of riskware, pirated software isn’t completely legit, even if it isn’t inherently malicious. But because cracked programs and pirated files are often distributed through untrusted sources and require users to run modified or unknown code, they carry a particularly high risk of malware infection.

Attackers may disguise Trojans, information stealers, cryptocurrency miners, and other malware as cracks or key generator tools. Pirated or modified software may also lack reliable security updates, leaving vulnerabilities unpatched and creating additional security risks over time.

How riskware impacts security

Riskware can increase an individual’s or organization’s attack surface, creating opportunities for cybercriminals to exploit vulnerabilities. Common security and privacy impacts include data theft and unauthorized remote access.

Data theft can impact organizations and individuals. If private data is stolen from users, it can lead to identity theft, financial loss, and targeted phishing attacks.

If a business experiences a data breach, it can directly harm customers, which creates mistrust, as well as potential legal challenges. Organizations may be in violation of regulations like the General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA), leading to fines, legal action, and reputational damage.

Another impact is unauthorized remote access. Attackers may abuse riskware vulnerabilities to access a device or network to execute malicious code, install malware, alter files, move laterally across a network, or cause disruption.

How to spot potential riskware threats

Riskware can be difficult to recognize because the software itself is typically above board. Instead of looking only for traditional cyber-threat signs, pay attention to what an app can access, what capabilities it provides, and whether you recognize and still need it.

A graphic shows common signs to help spot riskware threats.
A graphic shows common signs to help spot riskware threats.
A graphic shows common signs to help spot riskware threats.

Potential riskware warning signs include:

  • Excessive permissions: An app requests access to data or device features that don't seem necessary for its purpose, such as your location, contacts, microphone, files, or administrator privileges.
  • Powerful remote-access features: Remote administration and monitoring tools can give someone extensive control over your device. Make sure you recognize the software, know who installed it, and understand who can access it.
  • Unfamiliar software: Programs you don't remember installing deserve further investigation, particularly if they can monitor activity, modify system settings, recover passwords, or remotely control your device.
  • Unnecessary privileged access: Some system utilities and administration tools require elevated permissions to work. If you no longer use them, leaving them installed can create an unnecessary security risk.
  • Unexpected background activity: A legitimate program that suddenly behaves differently, consumes unusual resources, or accesses features unexpectedly may be misconfigured, compromised, or being misused.
  • Security warnings: Antivirus or other security software may identify legitimate programs as riskware, potentially unwanted applications (PUAs), or similar threats because their capabilities could be abused. Don't automatically dismiss these alerts simply because you recognize the program.

How to remove riskware

If you identify software that creates unnecessary security or privacy risks, removing it can help reduce your device's attack surface. Before uninstalling anything, make sure it isn't a system component or legitimate program that you still need.

Follow these steps to remove potential riskware:

  1. Uninstall unnecessary software: Review your installed apps and remove programs you don't recognize, trust, or use. If you're unsure about an application, research it before uninstalling it.
  2. Remove suspicious browser extensions: Check your browser for extensions you don't recognize or no longer need, especially those with permission to read website data, modify pages, or monitor browsing activity.
  3. Review app permissions: Revoke unnecessary access to sensitive features such as your files, location, camera, microphone, or administrator controls. If an app requires permissions that don't make sense for its purpose, consider removing it.
  4. Run an antivirus scan: Use reputable antivirus software to check for malware, potentially unwanted applications, and other threats that may be associated with the software.
  5. Update your device: Install available operating system and application updates to patch known vulnerabilities that attackers could exploit.

How to prevent riskware

Preventing riskware starts with following strong cybersecurity habits. Being selective about what you install, carefully managing software settings and permissions, and downloading apps from trusted sources can help reduce the security risks associated with potentially risky software.

A graphic shares a checklist of ways to prevent riskware from infecting your devices.
A graphic shares a checklist of ways to prevent riskware from infecting your devices.
A graphic shares a checklist of ways to prevent riskware from infecting your devices.

Here are some practical ways to reduce your exposure to riskware:

  • Read the terms of service: Understand what data an app can access, collect, and share before installing it.
  • Delete unrecognized software: Regularly review your programs and browser extensions, and remove anything you don’t recognize or no longer use.
  • Limit app permissions: Only grant apps permissions they genuinely need to function.
  • Avoid pirated software: Cracks, key generators, and pirated apps can expose you to malware and other security risks.
  • Download apps from official sources: Stick to official app stores and trusted developer websites whenever possible.
  • Review installation prompts: Watch for bundled software and unexpected requests for elevated permissions during installation.
  • Keep software updated: Install security updates promptly to patch vulnerabilities that attackers could exploit.
  • Use antivirus software: Run reputable antivirus software on your devices to help detect malicious or potentially risky programs.

Protect against riskware threats

Riskware threats can slip in through legitimate-looking apps and software, making it especially important to have extra layers of security that can spot trouble early.

Norton 360 helps protect your devices with real-time threat protection, a Smart Firewall, and AI-powered scam protection designed to detect and block suspicious activity before it compromises your security. Get cutting-edge protection today.

FAQs

What does riskware detected mean?

“Riskware detected” means your security software has identified an application that could introduce security or privacy risks. This doesn’t necessarily mean the program is malicious. Instead, it may have features, permissions, or vulnerabilities that could be misused or exploited.

Should I delete riskware?

Whether you should remove riskware depends on the program and why it was flagged. Consider uninstalling it if you don’t recognize or need it, downloaded it from an untrusted source, or can’t verify that it’s safe. If you need the software, keep it updated and configure it as securely as possible.

Why is my antivirus flagging riskware?

Antivirus software may flag apps as riskware because their capabilities could create security risks or be abused by attackers. For example, a legitimate remote-access tool could allow someone to control your device if they gain unauthorized access. A riskware alert allows you to review the program without necessarily classifying it as malware.

Is riskware a virus or malware?

Riskware isn’t usually a virus or a type of malware. Instead, the term generally refers to legitimate software with features or permissions that could create security risks if misused, exploited, or configured improperly. However, definitions vary between security providers, and some may classify potentially unwanted or dual-use software as riskware too.

How do I remove riskware from my Android?

If you decide to remove riskware from your Android device, uninstall the flagged app through your device settings. Then, use a trusted Android security app to scan your device and check for any residual or additional security threats.

On which platforms is riskware the most common?

Riskware can appear on any major platform, including Windows, macOS, Android, and Linux. The level of risk depends less on the operating system and more on the software you install, where it comes from, the permissions and access it has, and how securely your device is configured and maintained.

Crissy Joshua
Crissy Joshua is a staff editor for Norton, whose work focuses on online scams. She started her tech career creating how-to guides on device performance for CCleaner and Avast.

Editors’  note: Our articles offer educational information and are written to raise awareness about important topics in Cyber Safety. Norton products and services may not protect against every type of threat, fraud, or crime we write about. For more details about how we research, write, and review our articles, see our Editorial Policy.


Want more?

Follow us for all the latest news, tips, and updates.

Help protect against riskware

Download Norton 360 Deluxe to help protect devices from riskware, adware, and other online threats.

Help protect against riskware

Install Norton 360 Deluxe to help protect devices from riskware, adware, and other online threats.

Norton

360 Deluxe