Trojan Horse
In plain terms
A program that does what it claims — and something else besides. You installed it yourself, voluntarily, because it looked useful.
Definition
A trojan horse is malicious software hidden inside an apparently legitimate program, which the user installs themselves. Unlike a virus or a worm, it doesn't reproduce: it doesn't need to spread, since it gets itself run by the targeted person.
How it works
The mechanism isn't technical, it's editorial: making the installation desirable. Normally paid software offered for free, a utility promising to speed up a slow device, a modified version of a well-known app, a player a site claims is necessary to display its content. The downloaded program generally does what it claims, which dispels suspicion, while also carrying out its real payload: opening remote access, installing other components, collecting credentials. The practical consequence is that the decisive moment isn't execution but download — it's the only step where the decision is still entirely yours.
Warning signs
- Normally paid software offered for free, or an "unlocked" version of a well-known app
- Download offered from a third-party site, an email link or an ad rather than from the publisher
- Installation requesting administrator rights with no connection to its stated purpose
- Program presented as essential to play a video or open a document
- Apps or icons that appeared after installation, which you didn't choose
How to verify
Before installing: start from the publisher's name and reach their site through an independent search rather than the link you're offered, then download from there. On a phone, stick to the official app store. Afterwards, verification is far less reliable — a program designed not to be noticed is hard to spot — which is precisely why checking beforehand matters.
What to do
Only install from the original source, even when an intermediary seems more convenient. Refuse software presented to you as necessary to view content: it's a pretext, not a technical requirement.
If it already happened
Disconnect the device from the network. Treat any credentials entered or saved on this machine as exposed and change them from another device, starting with the email account used to reset your other accounts. Uninstalling the program isn't enough to establish that the machine is clean: on a device holding important data, reinstalling the system is the only reset you can vouch for. Report the incident to cybermalveillance.gouv.fr.
Frequently asked questions
- What's the difference with a virus?
- Reproduction. A virus copies itself to spread; a trojan horse doesn't copy itself, because it gets from you what a virus has to steal — its execution. It's also why there's nothing to "catch": there was an installation.
- The software I installed works normally. Is that reassuring?
- No, that's the whole point of the method. A trojan program that failed to perform its stated function would be uninstalled within minutes. Normal operation is an argument for discretion, not proof of harmlessness.
Related attacks
Official sources
Also known as: trojan, trojan virus, trojan malware, trojan program.
This article is part of the Malware family. Last updated: 2026-09-03.