Skip to main content
Malware & AttacksUpdated September 3, 2026

Trojan

A Trojan is malware that disguises itself as legitimate software to trick users into installing it. Unlike viruses, Trojans do not self-replicate; they rely on social engineering. Once installed, they may install backdoors, steal credentials, or drop additional malware.

A Trojan gets in because someone lets it in. The lure is a cracked installer, a fake update, an invoice with a macro, a browser extension; the payload is whatever the operator wants running on the machine. The name describes the delivery, not the behaviour, which is why the category is so wide: remote access tools, bankers, downloaders and infostealers are all usually Trojans.

For a defender the useful facts are downstream of the install. A Trojan needs to fetch its next stage and report home, so it resolves domains and connects to addresses, and those are observable on the network long after the file has been renamed or repacked.

File hashes catch the exact sample; network indicators catch the family. A campaign rebuilds its binary daily and keeps the same command infrastructure for weeks, so the C2 domain is the more durable indicator of the two.

Example

A user installs a “PDF converter”. The binary’s hash is unknown to every source, but the domain it contacts on first run has been listed as a RAT C2 for two weeks. The lookup on the domain, not the file, is what identifies the infection.

In isMalicious

The file hash lookup at /threat-intel/file-hash checks a sample against the malware hash sources isMalicious aggregates; a report on the domain or address the sample contacts is where the family and its infrastructure show up.

Frequently Asked Questions

What is Trojan?

A Trojan is malware that disguises itself as legitimate software to trick users into installing it. Unlike viruses, Trojans do not self-replicate; they rely on social engineering. Once installed, they may install backdoors, steal credentials, or drop additional malware.

How is Trojan related to Malware?

Trojan and Malware are both key concepts in threat intelligence. Malware is any software designed to harm, exploit, or gain unauthorized access to a system. It includes viruses, worms, trojans, ransomware, spyware, adware, rootkits, and more. Detection relies on file hashes, behavioral signatures, and threat intelligence feeds.

Related Terms

Put this intelligence to work

Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.

Check any indicator free
← Back to Glossary