Trojan Horse
A trojan horse is malware disguised as legitimate software, relying on the user to install it — deception rather than self-replication.
A trojan horse (or simply trojan) is malicious software disguised as something legitimate or desirable — an installer, a document, a game mod, a cracked application, a browser update. Named after the wooden horse of Greek legend, a trojan does not spread by itself the way a worm does and does not attach to other programs the way a classic virus does. It relies on social engineering: the victim is persuaded to invite it in.
How it works
The attacker wraps a malicious payload in a plausible container and puts it where the target will find it — an email attachment, a poisoned search result or ad, a fake software-download site, a compromised update mechanism, or a message from a hijacked account. The user runs the file believing it is the thing it claims to be; the visible program may even work as advertised while the payload installs silently in the background. What the payload does varies by goal: a banking trojan intercepts financial sessions, an infostealer trojan harvests saved passwords, cookies and crypto wallets, a remote access trojan gives the attacker interactive control of the machine, and a dropper or loader simply establishes a foothold and fetches whatever the attacker wants next — frequently ransomware. Modern lures increasingly skip the file entirely: fake "verification" pages talk victims into pasting commands into their own terminal, a trojan technique in everything but the download.
How to defend against it
Because a trojan's propagation mechanism is human trust, defense is as much behavioral as technical. Technically: allow software installation only from managed, vetted sources; strip or sandbox executable email attachments; use behavior-based endpoint protection that catches payload activity after the disguise has worked; and apply least privilege so one bad double-click does not carry administrator rights. Behaviorally: train employees that unsolicited software, unexpected "updates," and too-good-to-be-free tools are standing red flags, and verify the reflex with realistic phishing simulations that deliver attachment and download lures, not just credential links. The habit that defeats trojans — pausing before running anything you did not deliberately seek out from a trusted source — is buildable, and measurably so.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo