Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Trojan Horse
Cyber Security

Trojan Horse

← Back to Glossary
By NHI Mgmt Group Updated September 17, 2026 Domain: Cyber Security

A Trojan horse is software that appears legitimate but contains hidden malicious behaviour. It usually depends on trust and user action to run, then performs unauthorised activity such as data theft, remote control, or payload delivery. The disguise is the core of the attack.

How Trojan Horses Work

A Trojan horse succeeds by borrowing credibility. The malicious code is packaged inside something that looks useful, familiar, or harmless, which lowers suspicion long enough for a user or process to execute it. That trust break is the central mechanic, not a technical exploit in the narrow sense.

Once executed, the payload can do very different things depending on the campaign, including credential theft, remote administration, downloading a second-stage payload, or quietly changing system settings. The disguise matters because it gives the attacker an initial foothold without needing obvious exploitation noise.

Trojan delivery often overlaps with other attack paths. It may arrive through phishing, software downloads, fake updates, compromised installers, or malicious macros. The common pattern is not the delivery channel itself, but that the user believes they are launching benign software while the hidden payload is activated at the same time.

Why Trojans Are Effective

Trojans exploit a basic security weakness, trust is easier to abuse than hardened controls are to bypass. When a file, application, or update looks legitimate, users may grant execution, elevated rights, or network access that the attacker can immediately use.

This makes Trojans useful as an initial access method and as a delivery vehicle for other malware. They can be built to blend into normal business activity, delay their malicious behaviour, or trigger only after install so that detection based on surface appearance is less effective.

From a defensive perspective, the threat is not limited to the malicious program itself. A Trojan can also be the first step in a larger intrusion chain, where stolen data, remote access, or a dropped payload becomes the real objective after the initial deception succeeds.

Security Implications

Trojan horses are especially dangerous because they shift the security problem from pure technical blocking to trust validation. If an organisation assumes that user-approved software is safe, the Trojan model breaks that assumption and turns routine execution into a compromise path.

They also create broad downstream exposure once they run. A Trojan that gains access to a workstation can steal local data, harvest browser sessions, inspect cached secrets, or pivot into internal systems if controls are weak. In that sense, the initial disguise is only the entry point to a wider access problem.

The OWASP API Security Top 10 is useful when a Trojan is paired with API abuse, while SLSA and CIS Benchmarks help reduce the chance that tampered software or weak configuration becomes an easy execution path.

How to Recognize and Reduce Trojan Risk

Trojan risk is highest where users can install or run unverified software, where update paths are weakly controlled, or where email and web filtering do not reliably block malicious attachments and downloads. The term should be read as a reminder that “looks legitimate” is part of the attack design.

Practical reduction usually comes from reducing trust in unverified code, tightening software sourcing, and limiting the damage a single execution can cause. Strong application allowlisting, code-signing checks, least privilege, and better scrutiny of downloaded installers all address the fact that the Trojan depends on successful execution more than on technical stealth alone.

For identity and secret-bearing environments, the most damaging Trojans are often the ones that quietly reach tokens, cached sessions, or administrator tools. The Ultimate Guide to Non-Human Identities is relevant here because malware frequently abuses stored secrets and overprivileged access once it gains a foothold, especially in environments where service credentials are exposed beyond their intended scope.

Risk and Threat Considerations

Trojan horses are a high-impact deception pattern because the attacker needs only one successful trust decision to convert ordinary execution into compromise. The risk rises when users, endpoints, or software supply chains accept unverified code as routine, since the malicious behaviour can begin after the software has already been allowed to run.

Failure mechanism: the attack succeeds when the victim executes or installs software that appears legitimate, then grants it the time and access needed to launch hidden payloads, steal information, or open a remote control channel.

Impact: the result can include data theft, credential or session capture, persistence, malware staging, and lateral movement if the Trojan reaches a system with useful privileges or reachable secrets.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS 2 — Inventory and Control of Software AssetsTrojans rely on untrusted software being installed or executed.
CIS 3 — Data ProtectionTrojans often aim to steal data, tokens, and other sensitive material.
CIS 8 — Audit Log ManagementTrojan activity is often detected through unusual execution and access traces.
Recommendation — Restrict and inventory approved software to block unauthorized Trojan execution. Classify sensitive data and control access paths that a Trojan could abuse. Collect and review endpoint and application logs for suspicious post-install behavior.
NIST CSF 2.0PR.AC-3 — Remote Access is ManagedTrojans can create unauthorized remote access channels after execution.
PR.DS-1 — Data-at-Rest is ProtectedTrojans commonly target stored information after gaining execution.
DE.CM-4 — Malicious Code is DetectedTrojan behavior is a form of malicious code activity that must be observed.
Recommendation — Manage remote access paths so malicious software cannot easily establish control. Protect stored data so a Trojan cannot easily harvest usable information. Detect malicious code behavior through endpoint and network monitoring.
OWASP Non-Human Identity Top 10NHI-01 — Secrets Sprawl and ExposureTrojans often abuse exposed secrets once they gain a foothold.
Recommendation — Limit secret exposure so malware cannot easily harvest credentials after execution.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org