← All terms

Trojan Horse

A trojan horse is malware disguised as legitimate software, relying on the user to install it — deception rather than self-replication.

A trojan horse (or simply trojan) is malicious software disguised as something legitimate or desirable — an installer, a document, a game mod, a cracked application, a browser update. Named after the wooden horse of Greek legend, a trojan does not spread by itself the way a worm does and does not attach to other programs the way a classic virus does. It relies on social engineering: the victim is persuaded to invite it in.

How it works

The attacker wraps a malicious payload in a plausible container and puts it where the target will find it — an email attachment, a poisoned search result or ad, a fake software-download site, a compromised update mechanism, or a message from a hijacked account. The user runs the file believing it is the thing it claims to be; the visible program may even work as advertised while the payload installs silently in the background. What the payload does varies by goal: a banking trojan intercepts financial sessions, an infostealer trojan harvests saved passwords, cookies and crypto wallets, a remote access trojan gives the attacker interactive control of the machine, and a dropper or loader simply establishes a foothold and fetches whatever the attacker wants next — frequently ransomware. Modern lures increasingly skip the file entirely: fake "verification" pages talk victims into pasting commands into their own terminal, a trojan technique in everything but the download.

How to defend against it

Because a trojan's propagation mechanism is human trust, defense is as much behavioral as technical. Technically: allow software installation only from managed, vetted sources; strip or sandbox executable email attachments; use behavior-based endpoint protection that catches payload activity after the disguise has worked; and apply least privilege so one bad double-click does not carry administrator rights. Behaviorally: train employees that unsolicited software, unexpected "updates," and too-good-to-be-free tools are standing red flags, and verify the reflex with realistic phishing simulations that deliver attachment and download lures, not just credential links. The habit that defeats trojans — pausing before running anything you did not deliberately seek out from a trusted source — is buildable, and measurably so.

Related terms

Remote Access Trojan (RAT)A remote access trojan is malware that gives an attacker covert, ongoing control of a victim's device — keyboard, files, camera and credentials included.InfostealerAn infostealer is malware that silently harvests saved passwords, cookies and session tokens from a device and sells them into the criminal economy.SpywareSpyware is malicious software that covertly monitors a device — harvesting credentials, messages, and activity — and feeds social-engineering attacks.Drive-by DownloadA drive-by download infects a device through a compromised or malicious web page, with little or no user action beyond visiting the site.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo