Trojan Horse
A type of malicious software that disguises itself as legitimate software or is hidden within legitimate software to deceive users into running it. Once activated, Trojans can create backdoors or allow attackers to steal sensitive information.
Trojans do not self-replicate like viruses or Worm. Instead, they rely on users to unknowingly download and execute them, often by disguising them as something harmless or desirable.
- Remote Access Trojan (RAT)
- Backdoor Trojans
- Rootkit Trojans
- Botnet Trojans
- E-Banking Trojans
- Point-of-Sale Trojans
- Defacement Trojans
- Service Protocol Trojans
- Mobile Trojans
- IoT Trojans
- Security Software Disabler Trojans
- Destructive Trojans
- DDoS Attack Trojans
- Command Shell Trojans

Examples
Ports
| Port | Trojan |
|---|---|
| 80 | Necurs, NetWire, Ismdoor, Poison Ivy, Executer, Codered, APT 18, APT 19, APT 32, BBSRAT, Calisto, Carbanak, Carbon, Comnie, Empire, FIN7, InvisiMole, Lazarus Group, MirageFox, Mis-Type, Misdat, Mivast, MoonWind, Night Dragon, POWERSTATS, RedLeaves, S-Type, Threat Group-3390, UBoatRAT |
| 20/22/80/ 443 | Emotet |
| 8080 | Zeus, APT 37, Comnie, EvilGrab, FELIXROOT, FIN7, HTTPBrowser, Lazarus Group, Magic Hound, OceanSalt, S-Type, Shamoon, TYPEFRAME, Volgmer |
| 11000 | Senna Spy |
| 13000 | Senna Spy |