Skip to Content

Trojan horse: malicious software in disguise

A Trojan horse presents itself as a legitimate program, a utility, a game, or an expected file, while concealing malicious code that runs once installed, often to open remote access for the attacker.

Definition

Unlike a worm, a Trojan horse does not spread by itself: it relies on the victim's action, installing or running a booby-trapped program without realizing it. Once active, it can install a backdoor, exfiltrate data, or serve as an entry point for other malicious tools.

Modern Trojan horses are distributed through attachments, cracked software, or compromised websites offering a booby-trapped download. Their stealth is often their main strength: they seek to remain invisible for as long as possible.

Key points

Disguise, not propagation

The Trojan horse relies on the user's action to install itself, unlike a self-propagating worm.

Often an entry point

It frequently opens remote access that is then exploited for other malicious actions.

Designed to remain stealthy

Its value to the attacker depends on its ability to remain undetected for as long as possible.

How BCIT can support you

Awareness of common infection vectors is part of our cybersecurity awareness training.

Frequently asked questions ❓

How does a Trojan horse differ from a virus?

It does not replicate by itself: it depends on the victim's action, installing or running it without realizing it.

Can a Trojan horse remain undetected for a long time?

Yes, its stealth is often its main strength: some remain active for several months before being discovered.

Not ready to talk yet? Discover our cybersecurity assessment →

Do your teams know how to spot a booby-trapped file?

Regular awareness training remains one of the most effective protections against this infection vector.