Cyber Security Updated October 2026

What Is a Trojan Virus? How Trojan Horse Malware Works, and How to Remove It

A Trojan virus is malicious software disguised as something legitimate, from a free download to an invoice attachment, that gives an attacker access to a device once it's opened. This guide explains what a Trojan horse virus is on a computer and on a phone, the main types in circulation, the warning signs of infection, and the controls that stop them reaching your business.

Caleb Adoh
Caleb Adoh Growth Marketing Manager

Quick answer: what is a Trojan virus?

A Trojan virus, or Trojan horse, is malware disguised as legitimate software or a genuine file. Unlike a true computer virus, it cannot spread or replicate on its own; a person has to be tricked into running it. Once active, it opens a way in for an attacker to steal data, install further malware, or take control of the device.

  • Named after the wooden horse from Greek mythology used to smuggle soldiers into Troy, a term popularised in computing by the US Air Force's Daniel Edwards in a 1974 security report.
  • Common delivery methods: email attachments, cracked or pirated software, fake browser updates, malicious ads and infected USB drives.
  • On a computer: Trojans often act as a downloader for ransomware or a backdoor giving ongoing remote access.
  • On a phone: banking Trojans disguised as apps abuse Android's Accessibility service to read screens, log keystrokes and intercept one-time passcodes; Kaspersky recorded over 93,000 new banking Trojan packages in Q2 2026 alone.
Threat statistics and terminology checked against current vendor threat reports, October 2026.

1. What Is a Trojan Virus?

A Trojan virus, more accurately called a Trojan horse, is a type of malware that disguises itself as legitimate or desirable software to trick a person into installing or running it. The name comes directly from Greek mythology: the wooden horse the Greeks used to smuggle soldiers past the walls of Troy. In computing, the term was formalised in a 1974 US Air Force report by computer scientist Daniel Edwards, describing programs that appear harmless but carry a hidden, malicious function.

Once run, a Trojan can do any of a wide range of things depending on its purpose: steal login credentials and banking details, install further malware such as ransomware, open a backdoor for an attacker to control the device remotely, or quietly enrol the machine into a botnet. The disguise is the defining feature. A Trojan might arrive looking like an invoice, a software update, a cracked game, or an urgent delivery notification.

↑ Back to Contents

2. Trojan vs Virus vs Worm: What's the Difference?

"Trojan virus" is a common search term, but strictly speaking a Trojan is not a virus at all. The distinction matters because it decides how the malware behaves and spreads.

Malware Type Needs a Host File? Self-Replicates? How It Spreads
Virus Yes Yes, once triggered Attaches to a legitimate file or program; spreads when that file is shared or run
Worm No Yes, automatically Spreads across networks on its own, exploiting vulnerabilities, without any user action
Trojan No No Relies entirely on deception to get a person to run it; does not spread by itself

In everyday language, "Trojan virus" has become the common way people refer to this type of threat, and that usage is well understood even though it isn't technically precise. This guide uses "Trojan virus" and "Trojan horse virus" in that everyday sense throughout.

↑ Back to Contents

3. How a Trojan Horse Virus Spreads

Because a Trojan cannot replicate on its own, every infection starts with a person being persuaded to open, download or install something. The most common delivery routes are:

  • Email attachments and links disguised as invoices, delivery notices, HR documents or scanned files, often as part of a phishing campaign.
  • Pirated or cracked software downloaded from unofficial sites, a long-standing and reliable source of Trojan infections.
  • Fake software updates, particularly fake browser, Flash or codec update prompts shown on compromised or malicious websites.
  • Malicious or compromised adverts (malvertising) on otherwise legitimate websites.
  • Infected USB drives and removable media, especially in offices where devices are shared.
  • Apps from outside official app stores, a particularly common route for mobile Trojans, covered in section six.
↑ Back to Contents

4. Types of Trojan Horse Viruses

Trojans are usually classified by what they're built to do once installed, rather than by how they look to the victim.

Banking Trojans

Designed to steal online banking credentials, card details and one-time passcodes, often by overlaying fake login screens on top of real banking apps or websites.

Backdoor Trojans

Open a hidden route for an attacker to access and control the infected device remotely, often used to install further malware later.

Downloader Trojans

Have no payload of their own beyond fetching and installing additional malware, commonly ransomware, once they've gained a foothold.

Remote Access Trojans (RATs)

Give an attacker full remote control of a device, including the webcam, microphone, keystrokes and files, usually without any visible sign to the user.

Rootkit Trojans

Hide the presence of other malware or malicious activity from the operating system and security software, making infections much harder to detect.

Trojan droppers

Deliver and install a malware payload while evading detection, increasingly used by banking Trojan operators to slip past app store review processes.

↑ Back to Contents

5. What Is a Trojan Virus on a Computer?

On a Windows or Mac computer, a Trojan virus typically arrives as an email attachment, a download from an unofficial site, or bundled inside pirated software. Once run, it may install itself quietly in the background, modify startup settings so it runs every time the computer boots, and attempt to disable or evade antivirus software.

On business networks, computer Trojans are frequently the first stage of a much larger incident. A downloader Trojan might sit unnoticed for days or weeks, used by an attacker to map the network and identify valuable systems, before deploying ransomware across every connected device at once. This is why a single infected laptop is rarely treated as an isolated problem in a managed environment; the response has to assume the attacker may already have a wider foothold.

↑ Back to Contents

6. What Is a Trojan Virus on a Phone?

Mobile Trojans, overwhelmingly targeting Android devices, have grown into one of the fastest-moving areas of cyber crime. Kaspersky reported more than 2.6 million mobile malware attacks in the first quarter of 2026 alone, with banking Trojans the single largest category, and detected over 93,500 new banking Trojan installation packages in the second quarter of the year.

Most mobile banking Trojans share a common technique: abusing Android's Accessibility service, a feature built to help users with disabilities, to read what's on screen, log keystrokes, and even tap buttons automatically on the device's behalf. Once granted, this permission can let a Trojan overlay a fake banking login screen on top of a genuine app, intercept SMS one-time passcodes, and in some documented cases, search through notes apps for passwords or card details users have stored there.

Sideloading is the biggest risk factor

The large majority of mobile Trojan infections involve apps installed from outside the Google Play Store, often via a link in a text message or email. Downloading apps only from official app stores remains the single most effective protection against mobile Trojans, even though it doesn't eliminate the risk entirely.

iPhones are not immune to malware generally, but Apple's more restricted app installation model has made Trojan infections far less common on iOS than on Android, where sideloading is both possible and, for many of the apps distributing these Trojans, the primary delivery method.

↑ Back to Contents

7. Warning Signs of a Trojan Infection

Many Trojans are built to stay hidden, so signs of infection are often subtle rather than obvious.

  • Unexpected slowdowns or a device running hot, especially when idle.
  • Unfamiliar programs or apps appearing that you don't remember installing.
  • Browser changes such as a new homepage, unfamiliar toolbars, or search results redirecting unexpectedly.
  • Pop-ups and ads appearing outside of a browser, or far more frequently than normal.
  • Disabled security software, or antivirus that won't update or run a scan.
  • Unusual account activity, such as login alerts, password reset emails, or transactions you didn't make.
  • Unexpected permission requests on a phone, particularly Accessibility Service access requested by an app that has no obvious reason to need it.
↑ Back to Contents

8. How to Remove a Trojan Virus

1

Disconnect from the network

Switch off Wi-Fi or unplug the network cable immediately to stop a backdoor Trojan communicating with an attacker or spreading to other devices.

2

Run a full scan with up-to-date security software

Use a reputable antivirus or endpoint protection tool, fully updated, and run a complete system scan rather than a quick scan, since Trojans often hide outside the usual quick-scan locations.

3

Remove or quarantine what's found

Follow your security software's guidance to quarantine or delete detected files, and restart the device to let any boot-level changes take effect.

4

Change passwords from a clean device

Assume credentials typed on the infected device may have been captured, and change important passwords, especially banking and email, from a device you know is clean.

5

Get a professional assessment on a business device

For a business laptop or any device that touches company data, treat the infection as a potential wider incident rather than a one-off clean-up, since the Trojan may have already been used to access other systems.

↑ Back to Contents

9. Preventing Trojan Infections in a Business

✔ Controls that reduce the risk

  • Email filtering that scans attachments and links before they reach an inbox.
  • Endpoint detection and response (EDR) that catches suspicious behaviour, not just known malware signatures.
  • Application allow-listing so only approved software can run on company devices.
  • Regular staff awareness training covering phishing and social engineering, the entry point for most Trojans.
  • Mobile device management (MDM) restricting app installation sources on company phones.

✘ Habits that increase the risk

  • Downloading software from unofficial sites or installing cracked versions of paid applications.
  • Sideloading apps on Android from outside the Play Store, particularly via links sent in texts or emails.
  • Running outdated operating systems or delaying security updates.
  • Sharing local admin rights broadly, which lets a Trojan make deeper system changes once run.
  • Treating mobile devices as lower-risk than laptops, when banking Trojan volumes now suggest the opposite.

Most of these controls sit within a wider managed cyber security programme rather than as one-off purchases, which is why we build them as a combined service for clients rather than selling isolated tools. Our managed cyber security service covers email filtering, endpoint protection and user training together, and our managed EDR service specifically targets the kind of behavioural detection that catches a Trojan a traditional antivirus signature would miss.

↑ Back to Contents

10. Why Trojans Are a Business Risk, Not Just a Personal One

It's easy to think of a Trojan as a problem for one unlucky laptop or phone, but in a business context a single infection rarely stays contained. A banking Trojan on a finance team member's device can expose company accounts directly. A downloader Trojan on any device connected to the company network can quietly spread ransomware across every shared drive and server it can reach, turning a single infected endpoint into a company-wide outage.

The cost of that escalation is usually measured in downtime and recovery time as much as in any ransom demand. Rebuilding infected machines, restoring from backup, investigating how far an attacker travelled through the network, and notifying customers or regulators if personal data was exposed, all add up well beyond the initial point of infection. For businesses handling client data, financial records or regulated information, a Trojan that goes undetected for even a few days can turn into a reportable data breach.

This is also why Trojan protection rarely works as a single product bought once. Email filtering stops the initial message, endpoint protection catches the file if it still gets through, and staff awareness training reduces the chance someone opens it in the first place. Removing any one of those layers tends to be where infections slip through, which is why we build Trojan and malware protection as a managed, ongoing service rather than a one-off tool.

↑ Back to Contents

11. Notable Trojans in History

A handful of Trojans have had an outsized effect on how the industry defends against them, and they illustrate how the threat has evolved.

Trojan First Seen What It Did
Zeus (Zbot) 2007 A banking Trojan that stole credentials via keystroke logging and form-grabbing; its leaked source code went on to spawn dozens of variants.
Emotet 2014 Began as a banking Trojan before evolving into a malware-delivery platform, distributing ransomware for other criminal groups.
Anatsa 2020 An Android banking Trojan repeatedly smuggled onto the Google Play Store disguised as PDF readers and utility apps.
Mamont 2025 An Android banking Trojan that dominated detections through 2025 and into 2026, accounting for the majority of new banking Trojan packages found by Kaspersky.
Sources: Trojan statistics referenced in this guide are drawn from publicly reported vendor threat research, including Kaspersky's Q1 and Q2 2026 mobile malware reports, checked October 2026. Figures are cited to illustrate scale and trend, not as live statistics; always check a vendor's current reporting for the latest numbers.
↑ Back to Contents

12. Frequently Asked Questions

What is a Trojan virus?

A Trojan virus, or Trojan horse, is malware disguised as legitimate or desirable software. Unlike a true virus, it cannot replicate or spread on its own; a person has to be tricked into running it, after which it can steal data, install further malware or give an attacker remote access.

What is the difference between a Trojan and a virus?

A virus attaches itself to a legitimate file and can self-replicate once triggered. A Trojan does not attach to other files and cannot replicate on its own; it relies entirely on deceiving a user into installing or running it. "Trojan virus" is common everyday usage even though the two are technically different categories of malware.

What is a Trojan virus on a computer?

On a computer, a Trojan virus typically arrives as an email attachment, a fake software update or a download bundled with pirated software. Once run, it may install quietly in the background, disable security software, and act as a backdoor or downloader for further malware such as ransomware.

What is a Trojan virus on a phone?

On a phone, a Trojan virus is usually a malicious app, most often on Android, disguised as a legitimate tool and installed from outside the official app store. Many abuse Android's Accessibility service to read the screen, log keystrokes and intercept one-time passcodes, particularly to target banking apps.

How does a Trojan horse virus spread?

A Trojan cannot spread on its own. It relies on a person opening an infected email attachment or link, downloading pirated software, installing a fake update, clicking a malicious advert, or sideloading an app from outside an official app store.

What are the signs of a Trojan infection?

Common signs include unexpected slowdowns, unfamiliar programs or apps appearing, browser settings changing without explanation, increased pop-ups, security software that won't run or update, unusual account login activity, and unexpected permission requests on a phone.

How do I remove a Trojan virus?

Disconnect the device from the network, run a full scan with up-to-date security software, quarantine or remove anything detected, and change important passwords from a separate, clean device afterward. For a business device, treat the infection as a possible wider incident rather than a simple clean-up.

Can iPhones get a Trojan virus?

It's possible, but far less common than on Android, largely because Apple's app installation model makes it much harder to sideload apps from outside the App Store. The large majority of mobile banking Trojan activity currently targets Android devices.

Why is it called a Trojan horse virus?

The name references the wooden horse used in Greek mythology to smuggle soldiers past the walls of Troy. The computing term was formalised in a 1974 US Air Force security report, describing software that looks harmless but carries a hidden, malicious function.

↑ Back to Contents

Make Sure Your Business Is Protected Against Trojans

As a Microsoft Solutions Partner and managed IT services provider, we can assess your current defences and put the email filtering, endpoint protection and staff training in place to stop Trojan infections before they start.

Speak With Our Security Team 0161 834 9345