A Trojan horse is malware disguised as legitimate, useful software . Unlike viruses and worms, Trojans do not self-replicate — they rely on social engineering to trick users into executing them. Once active, they open backdoors, steal data, download additional malware, or grant remote control.
Milestone Year Details Term coined 1974 Daniel Edwards, US Air Force report; from Homer’s Iliad AIDS Trojan 1989 First ransomware; floppy disks to AIDS researchers Back Orifice 1998 First widely known Windows RAT; cDc Zeus/Zbot 2007 Banking Trojan; $100M+ stolen Emotet 2014 Evolved into malware delivery platform Agent Tesla Ongoing Modern RAT; BEC campaigns
└─ Presents as desirable program (game, tool, crack, update)
└─ User willingly runs it → same permissions as user
└─ Malicious component runs silently in background
└─ RAT for persistent remote access
└─ Keylogging, screenshots, webcam, credentials
└─ Contact C2 → download additional malware
Trojan Year Type Impact Back Orifice 1998 RAT First Windows RAT; cDc Zeus / Zbot 2007 Banking $100M+ stolen SpyEye 2009 Banking Form grabbing + keylogging Emotet 2014 Loader Malware delivery platform Agent Tesla Ongoing RAT BEC campaigns
✅ Only download from official, reputable sources
✅ Scrutinise email attachments; sandbox suspicious files
✅ Use standard (non-admin) account for daily use
✅ Enable UAC and application sandboxing
✅ EDR for behavioural detection
✅ Email filtering + web proxies
✅ Audit running processes and connections
Technique ID Description User Execution T1204 User runs malicious file Remote Access Software T1219 RAT installation Data Staged T1074 Local staging before exfil Exfiltration Over C2 Channel T1041 Data theft via C2