It relies on deception and the trust or authorization of whoever invokes it. Unlike a virus or worm, the label does not require a Trojan horse to replicate or propagate.
A Trojan horse may appear as an installer, update, document, utility, mobile application, or modified program. Once invoked, it may steal data, establish remote access, change settings, or install malware. Those actions can add classifications; “Trojan horse” primarily describes how its malicious nature is concealed at delivery or execution.
Key points
DeliveryPhishing, unsafe downloads, compromised distribution, misleading advertisements, and unauthorized bundles can present a Trojan horse to a user or automated process.
Trust abuseA convincing name, interface, signature, or source can influence execution but does not establish provenance. Installation may inherit the invoker’s permissions.
InvestigationDetermine what was represented, what ran, its source and integrity, privileges, persistence, communications, installed components, and distribution.
Important limitation“Trojan” does not describe one payload or prove that a user knowingly enabled an attack. A deceptively named file is not a Trojan horse unless it contains or launches hidden malicious functionality.