Updated: October 2026
Somebody on your team downloaded a PDF reader from the second search result, and now Defender is shouting about something called Wacatac. Nothing looks broken, which is the whole point of a trojan. Here's what a trojan virus is, how one gets onto a work laptop, what EDR sees when it runs, and what to do in the first hour after the click.
What Is a Trojan Virus?
A trojan is malware that pretends to be something you want. A free tool, an invoice, a browser update, a "verify you're human" box. You run it yourself, because it looks harmless, and it quietly does something else in the background.
The name comes from the wooden horse the Greeks left outside Troy. The city pulled it inside the walls, and the soldiers hidden in it opened the gates at night. Same trick, smaller horse.
"Trojan virus" is the phrase everyone searches, but it's technically wrong. The accurate names are trojan horse or trojan malware. A virus copies itself into other files, and a worm spreads across the network on its own. A trojan does neither. It waits for a person to launch it, then it opens the gates for whatever comes next.
| Virus | Worm | Trojan | |
|---|---|---|---|
| How it spreads | Copies itself into other files | Moves machine to machine by itself | Doesn't spread; a person runs it |
| Needs a click? | Yes, to start | No | Yes, every time |
| What it looks like | An infected file | Often nothing at all | Something useful |
| Typical job | Damage or spread | Spread fast | Steal, spy, or load more malware |
The distinction isn't pedantry. Worms get stopped with patching and segmentation. Trojans get stopped by controlling what users can run, and by spotting what the thing does once it starts.
How Trojans Get Onto Work Machines
A trojan needs a believable disguise and a person in a hurry. The routes in 2025 and 2026 look like this.
Fake installers from ads. Malvertising buys search ads for popular tools, so the top result for "Zoom download" or "7-Zip" can point to a lookalike site. The installer works, and it drops a trojan alongside.
Cracked and pirated software. Keygens and "free" versions of paid tools are a classic carrier. This r/msp thread is what it looks like from the MSP side: a client's vendor installed pirated diagnostic software, and SentinelOne raised 40+ alerts on the laptop before the MSP locked it onto guest Wi-Fi.
Email attachments and links. Invoices, shipping notices, shared-document alerts. Microsoft's Digital Crimes Unit found over 394,000 Windows computers infected with the Lumma infostealer between March 16 and May 16, 2025, delivered through spear-phishing and malvertising, before it took down Lumma's domains.
Fake updates and fake CAPTCHAs. A page claims your browser is out of date, or asks you to prove you're human. The newest version of this is ClickFix: the page copies a command to your clipboard and tells you to press Win+R, paste, and hit Enter. Microsoft Threat Intelligence described ClickFix in August 2025 as affecting thousands of devices a month, with Lumma as its most common payload.
ClickFix is sneaky because there's no file to download. The user types the attack in themselves. This r/sysadmin thread collects what admins are doing about it, from disabling the Run box through Intune to blocking PowerShell for everyone outside IT.
Types of Trojans
"Trojan" describes the disguise, not the job. Once it's running, it usually does one of these.
Remote access trojan (RAT). Gives the attacker a remote desktop they control: screen, keyboard, files, webcam. AsyncRAT, XWorm and NetSupport all show up as ClickFix payloads in Microsoft's write-up.
Infostealer. Grabs saved browser passwords, session cookies, crypto wallets and VPN configs, then sends them out straight away. Stolen session cookies let an attacker skip MFA, because the login already happened.
Banking trojan. Watches for banking sites and injects fake fields or redirects payments. Older families like Emotet started here before becoming loaders.
Downloader or loader. Small and quiet. Its only job is to fetch the next stage, often a RAT, a stealer, or ransomware.
Backdoor. Leaves a way back in, so the attacker can return after the first payload is cleaned up.
IBM Technology's short explainer walks through how a RAT gives an attacker hands-on control of a machine.
What EDR Sees When a Trojan Runs
Signature antivirus looks for known files. A new trojan build often isn't known yet, so modern endpoint tools watch behavior instead. Our guide to endpoint security covers where EPP ends and EDR starts.
Here's the trail a typical trojan leaves:
- An odd parent process. Explorer launching PowerShell right after a browser visit. Word spawning a command shell. An installer in the Downloads folder starting mshta.exe.
- Encoded or downloaded scripts. PowerShell running a long Base64 string, or pulling a file from a domain registered last week.
- Persistence. A new Run registry key, a scheduled task, or a service, so it survives a reboot.
- Credential access. Reads of browser password databases or the LSASS process.
- Beaconing. Small, regular outbound connections to the same server, which is the trojan checking in for orders.
When Microsoft Defender catches one, the alert name tells you a lot. Microsoft names malware as Type:Platform/Family.Variant, so "Trojan:Win32/Wacatac.B!ml" reads as a trojan, for 32-bit Windows, family Wacatac, variant B. Anything after the "!" is an internal Microsoft marker. Microsoft doesn't document "!ml", though admins widely read it as a machine-learning detection, which is why a generic family like Wacatac lands on so many files nobody has named yet.
What to Do After Someone Clicks
Speed matters more than perfection here. An infostealer sends what it grabs as soon as it runs, so assume credentials are gone and work from there.
For staff, the rule is short. Tell IT right away, even if nothing seems to have happened. Disconnect from Wi-Fi or unplug the cable, but leave the machine on, because a running machine keeps evidence a reboot wipes. Don't try to clean it yourself, and don't feel bad about reporting it. The fast report is the part that saves the day.
For techs, the order that works:
- Isolate the device through your EDR's network containment, so it can't talk to anything but the console.
- Find what ran. Pull the process tree, the file hash and the source: download URL, email, or pasted command.
- Reset credentials from a clean device. Passwords first, then revoke active sessions and tokens, since stolen cookies survive a password change.
- Hunt for the same file elsewhere. Search by hash or installer name across the fleet. In OpenFrame, the live device inventory shows which machines have it installed.
- Reimage rather than clean. Removal tools can miss a backdoor. A fresh install from a known-good image is faster than proving a machine is clean.
- Close the door it came through. Block the domain, tighten who can install software, and consider disabling Win+R for users who never need it.
A Trojan Is a Disguise, Not a Virus
A trojan virus is malware that gets a person to run it by looking useful. It doesn't spread on its own, so the defenses that matter are control over what users can run, EDR that watches behavior, and a fast, blame-free way to report a bad click.
Trojans are often how bigger incidents start. Our breakdown of a ransomware attack shows what happens when a loader's next stage is ransomware.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
