A Trojan horse is malicious software disguised as something legitimate

A Trojan horse is a program that looks like something safe or useful—a game, a video player, a document—but actually contains hidden malware that can damage your computer, steal your information, or give someone else control of your machine. Unlike a worm or virus, a Trojan does not spread itself. You have to run it. The attacker's job is to trick you into opening it.

The name comes from the ancient Greek story: soldiers hid inside a wooden horse that the city of Troy rolled through its gates, thinking it was a gift. Once inside the walls, the soldiers emerged and attacked. A Trojan horse virus works the same way—it enters your computer hidden inside something you thought was safe.

Trojans are one of the most common ways attackers break into personal computers. They do not require you to click a link in an email or visit a dangerous website, though those are common delivery methods. They can also arrive through file-sharing sites, fake software updates, or downloads from compromised websites.

Key Takeaways

  • A Trojan horse looks like legitimate software but contains hidden malware that runs when you open it.
  • Trojans do not spread on their own—you must read and run the infected file for the attack to work.
  • Once inside your computer, a Trojan can steal passwords, install other malware, delete files, or let an attacker control your machine remotely.
  • The most common delivery methods are email attachments, fake software updates, and downloads from untrusted websites.
  • Antivirus software can detect many Trojans, but the strongest defense is not opening files or programs from sources you do not recognize.

How a Trojan horse gets onto your computer

Trojans arrive through methods that rely on your action. An attacker sends you an email with an attachment that looks like a resume, an invoice, or a photo—but when you open it, the Trojan runs. Another common method is a fake software update: you see a pop-up saying your browser or media player needs updating, you click it, and you read the Trojan instead of the real update.

File-sharing sites and torrent networks are frequent sources. Someone uploads a movie or game that is actually a Trojan wrapped inside. Compromised websites can also serve Trojans: you visit what looks like a normal site, and malicious code on that site tries to read the Trojan to your computer without your knowledge—though modern browsers block many of these attempts.

Social engineering is the core of every Trojan delivery. The attacker needs you to believe the file is worth opening. That might mean impersonating someone you know, creating urgency ("Your account will be locked"), or offering something you want.

What a Trojan horse can do once it is running

The damage depends on what the Trojan was designed to do. Some Trojans are info-stealers: they record your keystrokes, capture screenshots, or steal passwords and credit card numbers. Others are backdoors that give an attacker remote access to your computer—they can then use your machine to send spam, launch attacks on other computers, or install additional malware.

A ransomware Trojan encrypts your files and demands payment to unlock them. A banking Trojan specifically targets login credentials for financial accounts. Some Trojans straightforward delete or corrupt files, or disable your antivirus software so other malware can move in.

The danger is that you may not notice a Trojan is running. An info-stealer or backdoor can operate silently in the background for months while the attacker harvests your data or uses your computer for their own purposes. By the time you realize something is wrong, significant damage may have occurred.

The difference between a Trojan, a virus, and a worm

These three terms are often used interchangeably, but they describe different types of malware. A virus is code that attaches itself to a legitimate program and spreads when you run that program—it needs a host file to survive. A worm is self-replicating malware that spreads across networks on its own, without needing you to run anything or without needing a host file.

A Trojan does neither. It does not attach to other files, and it does not replicate itself. It straightforward sits on your computer and performs whatever malicious task it was programmed to do. The only way it spreads is if someone tricks another person into downloading and running it.

In practice, a single piece of malware might have characteristics of more than one type. A Trojan might also contain a worm component, or a virus might carry a Trojan payload. The distinction matters mainly for understanding how the malware moves—but the defense is the same for all of them.

Signs your computer may have a Trojan

Many Trojans run invisibly, but some leave traces. Your computer may slow down noticeably, especially if the Trojan is using your processor or internet connection for the attacker's purposes. You might see unexpected pop-ups, or your browser homepage might change without your action. Files may disappear or become corrupted.

Your antivirus software might alert you to a detection—this is the best-case scenario, because it means the software caught the Trojan before it could cause major damage. If you notice your bank or email account has been accessed from an unfamiliar location, or if you see charges you did not make, a Trojan may have stolen your credentials.

Some Trojans disable your antivirus or firewall, so a lack of alerts does not mean your computer is clean. If your antivirus software stops working or you cannot turn it back on, that is a warning sign.

How to protect your computer from Trojans

The strongest defense is skepticism. Do not open email attachments from people you do not know. Be cautious about attachments from people you do know if the message seems out of character or if they did not mention sending you a file. Do not click links in unsolicited emails, even if they appear to come from your bank or a service you use.

Keep your operating system and software updated. Attackers often use known security flaws to deliver Trojans. When Microsoft, Apple, or your software vendor releases a security update, install it promptly. Be wary of pop-up notifications asking you to update software—go directly to the official website instead of clicking the pop-up.

Use antivirus or anti-malware software and keep it current. No antivirus catches everything, but it will detect many known Trojans. Run regular scans. Use a firewall, which your operating system likely includes by default. Avoid downloading files from untrusted websites or peer-to-peer networks.

Use strong, unique passwords for important accounts like email and banking. If a Trojan steals one password, the attacker cannot use it to access your other accounts. Consider using a password manager to generate and store complex passwords.

What to do if you think you have a Trojan

If your antivirus software detects a Trojan, follow its instructions to quarantine or remove the threat. Quarantine means the software isolates the file so it cannot run, but keeps it for analysis. If removal fails, restart your computer in Safe Mode (a limited version of your operating system that loads only essential programs) and try again.

If you suspect a Trojan has stolen financial information, contact your bank and credit card companies when ready. Ask them to monitor your accounts for unauthorized activity and consider placing a fraud alert on your credit report. Change passwords for important accounts from a different, clean computer if possible.

For serious infections that your antivirus cannot remove, you may need to wipe your hard drive and reinstall your operating system. This is a last resort, but it guarantees the Trojan is gone. Back up your important files first—though be careful not to back up the infected files themselves.

Frequently Asked Questions

Can a Trojan spread to other computers on my network?

Some Trojans can spread across a network, especially if they have worm-like capabilities or if they exploit network vulnerabilities. However, most Trojans focus on the infected computer itself. To be safe, assume any Trojan on one device could potentially affect others on the same network, and scan all devices if you find one.

Will restarting my computer get rid of a Trojan?

Restarting alone will not remove a Trojan. The malware will still be on your hard drive and will run again when your computer starts up. Restarting in Safe Mode and running antivirus software is more effective, because Safe Mode loads fewer programs and gives antivirus a better chance to detect and remove the threat.

Can I get a Trojan from visiting a website?

You can get a Trojan from a compromised website if the site tries to read malware to your computer. Modern browsers block many of these attempts automatically. However, if your browser is outdated or unpatched, the risk is higher. Visiting a website alone will not infect you—the malware has to actually read and run.

Is a Trojan the same as spyware?

Spyware is a category of malware that monitors your activity and steals information. A Trojan is a delivery method—it is how the spyware gets onto your computer. Many Trojans are designed to install spyware, but not all Trojans are spyware, and not all spyware arrives via Trojan.

Can antivirus software detect all Trojans?

No. Antivirus software detects Trojans by comparing files against a database of known malware signatures and by analyzing suspicious behavior. New Trojans that have not been catalogued yet may slip through. This is why defense-in-depth—combining antivirus, a firewall, careful browsing habits, and regular updates—is more effective than relying on any single tool.