Trojan

Malicious program masquerading as something innocuous or useful

A trojan (or Trojan horse) is a malicious program masquerading as something innocuous or even useful. Trojans use social engineering to convince victims to execute their code, and often act in a clandestine manner, sometimes even providing the useful functionality promised while running malicious actions in secret.

The great majority of malware takes the form of trojans - software such as adware and spyware also falls into this category, as actions which are not revealed during the installation process are carried out in a clandestine manner once installed. Trojan infections can come from malicious or hijacked websites, either using social engineering to persuade victims to install the file or exploiting vulnerabilities to carry out silent drive-by downloads. Trojans may also be sent out via email spam, with the email either including an attachment (the trojan file itself), or including links to the malicious or hijacked sites mentioned previously, again using social engineering to persuade readers to visit the site. Trojans can also be spread via other communication methods such as IM or P2P filesharing, or even dropped by self-replicating malware.

Many trojan infestations involve a variety of files, each providing different functionality. Typical types of trojan include downloaders, keyloggers, backdoors, clickers and diallers.

Related news articles

Microsoft issues emergency patch

Out-of-cycle update fixes serious, wormable flaw.

24 October 2008

Malware reaches space station

Autorun worm found on non-critical systems.

29 August 2008

Best Western database hack exposes info on 8m customers

Hotel chain data heist latest in string of major security leaks.

26 August 2008

Storm mails bring spoof World War 3 news

US-Iran war story used as hook for malware barrage.

10 July 2008

Macs under attack from trojan double whammy

Two new threats in a week spark worries of approaching Mac malware era.

30 June 2008

  see all related news stories


Poll

How should software and OS patching/security updates be managed?
Manually, at the user's discretion
Automatically via an optional, user-defined schedule
Automatically via a fixed, but optional schedule
Automatically via a fixed schedule, on by default with opt-out system
Automatically and silently, with no option to run unpatched

Leave a comment
View 19 comments

Jobs Career Sidebar

VB100 certification

VB100 This month's comparative review tackles the 64-bit version of Windows Server 2003 - with the platform bringing out quite a number of quirks and oddities in several of the products under test.
See full results.

Virus Bulletin currently has 165,653 registered users.