Skip to content

Trojan Horse

Risk Level

A Trojan horse is malware disguised as legitimate, useful software. Unlike viruses and worms, Trojans do not self-replicate — they rely on social engineering to trick users into executing them. Once active, they open backdoors, steal data, download additional malware, or grant remote control.

MilestoneYearDetails
Term coined1974Daniel Edwards, US Air Force report; from Homer’s Iliad
AIDS Trojan1989First ransomware; floppy disks to AIDS researchers
Back Orifice1998First widely known Windows RAT; cDc
Zeus/Zbot2007Banking Trojan; $100M+ stolen
Emotet2014Evolved into malware delivery platform
Agent TeslaOngoingModern RAT; BEC campaigns
1. DISGUISE
└─ Presents as desirable program (game, tool, crack, update)
2. EXECUTION
└─ User willingly runs it → same permissions as user
3. PAYLOAD ACTIVATION
└─ Malicious component runs silently in background
4. BACKDOOR INSTALLATION
└─ RAT for persistent remote access
5. DATA EXFILTRATION
└─ Keylogging, screenshots, webcam, credentials
6. DOWNLOADER FUNCTION
└─ Contact C2 → download additional malware
TrojanYearTypeImpact
Back Orifice1998RATFirst Windows RAT; cDc
Zeus / Zbot2007Banking$100M+ stolen
SpyEye2009BankingForm grabbing + keylogging
Emotet2014LoaderMalware delivery platform
Agent TeslaOngoingRATBEC campaigns
  • ✅ Only download from official, reputable sources
  • ✅ Scrutinise email attachments; sandbox suspicious files
  • ✅ Use standard (non-admin) account for daily use
  • ✅ Enable UAC and application sandboxing
  • ✅ EDR for behavioural detection
  • ✅ Email filtering + web proxies
  • ✅ Audit running processes and connections
TechniqueIDDescription
User ExecutionT1204User runs malicious file
Remote Access SoftwareT1219RAT installation
Data StagedT1074Local staging before exfil
Exfiltration Over C2 ChannelT1041Data theft via C2