BLACK FRIDAY: 2-for-1 offer NOVEMBER 20 - 26 See details

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

How to analyze Trojan with ANY.RUN

Top malware of this type

Family
Type
Trend changes
Tasks overall
  • 2

    Agent Tesla

    Trojan
    0,0,14,32,19,30,497,186,62,224,306,444,848,1799,1627,1950,1292,1634,1189,864,653,448,442,489,319,471,391,189,178,167,216,182,155,199,616,1304,1118,1073,1037,1291,707,342,325,721,1751,2606,4660,1257,1433,1643,2002,1921
    3
    35487
  • 3

    njRAT

    Trojan
    0,0,15,84,77,113,97,212,168,272,296,241,314,305,266,330,277,437,418,621,812,831,1103,1287,2034,2973,2869,1794,1996,1664,1215,1128,1607,1938,1825,1495,1394,670,737,612,627,765,652,682,772,611,571,516,832,530,299,349
    2
    40833
  • 4

    Netwire

    Trojan
    0,0,7,9,12,26,63,61,56,66,91,88,89,91,236,257,146,256,208,178,159,82,60,80,74,83,54,41,56,79,64,31,36,42,110,98,105,130,49,72,50,27,20,14,24,12,33,17,7,8,21,7
    24
    4090
  • 5

    Remcos

    Trojan
    0,0,42,49,65,157,139,179,130,185,228,231,276,366,272,313,148,318,330,218,297,388,260,343,449,696,430,320,315,460,461,289,353,322,346,350,424,439,367,381,555,686,649,670,513,338,1110,559,1141,668,898,666
    9
    19595
  • 6

    FlawedAmmyy

    Trojan
    0,0,0,3,29,10,49,19,12,42,43,57,159,97,6,4,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
    67
    624
  • 7

    Emotet

    Trojan
    1,0,374,277,811,1878,1847,1608,2284,3715,4287,4676,996,136,5433,6146,6586,5199,1580,1428,1547,8419,6792,2452,7916,946,432,243,206,236,881,1325,6399,3032,1008,481,342,371,229,209,181,573,146,32,49,63,137,131,172,140,185,133
    1
    108219
  • 8

    Nanocore

    Trojan
    0,0,10,85,137,243,251,432,349,538,650,960,838,831,794,780,570,673,813,672,443,367,533,397,593,909,767,877,634,725,531,579,575,383,383,442,486,372,255,317,206,169,128,164,150,134,141,182,93,44,51,75
    7
    22020
  • 9

    Adwind

    Trojan
    0,0,49,132,171,296,280,120,103,278,251,179,115,141,115,196,48,37,36,72,24,14,51,14,11,29,6,10,10,15,28,6,6,5,11,13,18,27,3,9,2,1,3,22,24,30,9,4,15,9,45,54
    25
    3983
  • 10

    Vidar

    Trojan
    0,0,0,0,0,0,0,0,0,77,96,71,25,79,182,120,117,125,138,155,138,97,80,65,146,219,281,310,408,565,575,424,276,231,206,93,35,11,582,629,377,90,408,597,360,280,471,107,156,134,394,187
    13
    8051
  • 11

    Danabot

    Trojan
    0,0,0,0,13,4,1,12,33,17,56,160,51,57,73,68,25,41,56,76,33,29,23,9,9,39,22,67,169,131,173,52,10,5,44,22,52,68,28,25,36,60,16,21,13,46,109,22,29,19,1,54
    35
    2318
  • Last Seen at

    Recent blog posts

    post image
    What Are the 3 Types of Threat Intelligence D...
    watchers 148
    comments 0
    post image
    Expert Q&A: Aaron Fillmore on his Cyberse...
    watchers 158
    comments 0
    post image
    Malware Trends Report: Q2, 2024 
    watchers 1628
    comments 0

    What is a trojan malware?

    According to the standard trojan malware definition, it is malicious software that pretends to be legitimate in order to deceive victims into downloading and executing it.

    However, attackers now frequently distribute trojans via loaders, and as a result, advanced disguises are unnecessary and may not go beyond simply mimicking the name of a legitimate process. Additionally, trojan attacks often make use of social engineering tactics, spoofing, and phishing to persuade the user to take the desired action.

    The most common purpose for these malicious programs is to gain unauthorized access to a user's computer and extract sensitive files and data, including credit card information and private email addresses. Trojans are often used to distribute other types of threats, including ransomware that encrypts users’ files and demanding payment for their decryption.

    Get started today for free

    Easily analyze emerging malware with ANY.RUN interactive online sandbox

    Register for free

    What can a trojan do to a computer?

    The core functionality of such malware can vary significantly depending on its type (e.g., remote access trojan or trojan spyware). However, the most common features include:

    • Data theft: Steals sensitive data from the infected computer, such as passwords, credit card numbers, and social security numbers.
    • Keylogging: Records all keystrokes typed on the infected computer.
    • Remote access: Lets attackers to remotely control the infected computer.
    • Downloading and installing other malware: Drops extra payloads on the infected computer.
    • Modifying system files: Modifies system files to disable security software, create backdoors, and perform other malicious activities.
    • Spreading through network connections: Spreads to other computers on the same network.

    Some types of this computer virus can target specific spheres. For instance, banking trojan malware is designed to steal banking credentials and other sensitive financial information, such as credit card and social security numbers. They can also be used to take over a user's online banking account and perform fraudulent transactions.

    How do trojans spread?

    Attackers have devised a variety of methods for infiltrating computers to deploy a trojan virus, including email attachments, infected websites, and file sharing platforms. When a user interacts with these sources by downloading and executing a malicious file, the trojan can be installed on their device without their knowledge.

    Email phishing campaigns remain the most common vector of infection. Social engineering plays a significant part in how criminals manage to carry out successful attacks involving trojans.

    Their tactics may include sending out thousands of spam emails on the part of a trusted entity, such as an actual brand or government organization, or using intimidation to scare the victim and persuade them to perform harmful actions.

    For instance, criminals behind one of the phishing campaigns aimed at spreading the STRRAT trojan targeted individuals on behalf of the MAERSK shipping corporation.

    How can a trojan gain access to a computer?

    A typical trojan malware infection chain follows these steps:

    1. Initial access: Typically, an unknowing user downloads a trojan as an email attachment or a file from a website.
    2. Execution: Once the trojan is delivered to the victim's computer, it typically installs itself by exploiting a vulnerability in the operating system or in other software applications.
    3. Persistence: Once installed, the trojan tries to persist on the system to continue running even after the victim reboots their computer. This may be done by modifying the system registry or by installing itself as a system service.
    4. Privilege escalation and lateral movement: The malware then attempts to gain higher permissions on an infected system by exploiting security gaps. In many cases, the malicious program manages to disseminate across the entire network through lateral movement.
    5. Collection and exfiltration: In this stage, the trojan gathers the information from targeted systems and exfiltrates it to a remote server called the command-and-control center (C2). It may also communicate with the C2 to download additional malware or receive commands.
    6. Impact: Some trojans may disrupt organizations’ operations by tampering with data and interrupting internal processes. For instance, ransomware trojans can encrypt files and, thus, prevent a targeted company from functioning.

    Remcos process tree Execution processes of Remcos displayed by the ANY.RUN malware sandbox

    Using the Remcos trojan as an example, we can trace this entire process in action by uploading a sample of this malware to the ANY.RUN interactive malware sandbox.

    The Remcos trojan can be delivered in different forms. In our case, the entire infection chain starts with an executable file, which, once launched, initiates a VBS script that runs a command line and drops an executable file. This file is the main payload, which carries out malicious activities such as stealing information, changing the autorun value in the registry, and connecting to the C2 server.

    What are examples of the most persistent trojans today?

    The threat landscape is changing by the hour and the popular trojans today may be gone forever tomorrow. To stay in the know about the latest trends in malware, as well as collect fresh indicators of compromise and samples, use ANY.RUN’s Tracker.

    Here are some of the most active trojan families according to the service:

    • RedLine: This trojan poses a significant threat to users by collecting their private information and distributing various damaging programs. The versatility of the software means that it can cause considerable harm to both personal and enterprise devices, leading to financial loss and data breaches.
    • NjRAT: One of the most readily available RATs in current operation. There are plenty of educational resources providing guidance to aspiring attackers on how to use it.
    • Agent Tesla: It is a program that is marketed as legitimate software but is actually a trojan spyware that collects sensitive information about its victims. It records users’ keystrokes and interactions to obtain personal data without their knowledge.

    How can I detect a trojan?

    Despite the prevalence of trojan viruses, detecting them can be extremely challenging. They often use sophisticated techniques to evade detection from antivirus programs, making them a serious threat to cybersecurity.

    Yet, uploading any suspicious file or link to the ANY.RUN malware sandbox can help you quickly discover if the sample under inspection is a trojan, another type of malware, or a completely safe file. The service also shows the entire execution path of the sample and displays its network traffic activity.

    Additionally, ANY.RUN enables you to interact with files, links, and the infected system in a safe VM environment like you would on a normal computer.

    You can also use the sandbox to gain the information needed to ensure timely malware trojan removal.

    Try ANY.RUN for free – request a demo!

    HAVE A LOOK AT

    Adwind screenshot
    Adwind
    adwind trojan
    Adwind RAT, sometimes also called Unrecom, Sockrat, Frutas, jRat, and JSocket, is a Malware As A Service Remote Access Trojan that attackers can use to collect information from infected machines. It was one of the most popular RATs in the market in 2015.
    Read More
    Agent Tesla screenshot
    Agent Tesla
    agenttesla trojan rat stealer
    Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.
    Read More
    Crimson RAT screenshot
    Crimson RAT
    crimson rat trojan
    Crimson is a Remote Access Trojan — a malware that is used to take remote control of infected systems and steal data. This particular RAT is known to be used by a Pakistani founded cybergang that targets Indian military objects to steal sensitive information.
    Read More
    Danabot screenshot
    Danabot
    danabot trojan stealer
    Danabot is an advanced banking Trojan malware that was designed to steal financial information from victims. Out of the Trojans in the wild, this is one of the most advanced thanks to the modular design and a complex delivery method.
    Read More
    Dridex screenshot
    Dridex
    dridex trojan banker
    Dridex is a very evasive and technically complex banking trojan. Despite being based on a relatively old malware code, it was substantially updated over the years and became capable of using very effective infiltration techniques that make this malware especially dangerous.
    Read More
    Emotet screenshot
    Emotet
    emotet trojan loader banker
    Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.
    Read More

    Our website uses cookies. By visiting the pages of the site, you agree to our Privacy Policy