Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Somebody on your team downloaded a PDF reader from the second search result, and now Defender is shouting about something called Wacatac. Nothing looks broken, which is the whole point of a trojan. Here's what a trojan virus is, how one gets onto a work laptop, what EDR sees when it runs, and what to do in the first hour after the click.

What Is a Trojan Virus?

A trojan is malware that pretends to be something you want. A free tool, an invoice, a browser update, a "verify you're human" box. You run it yourself, because it looks harmless, and it quietly does something else in the background.

The name comes from the wooden horse the Greeks left outside Troy. The city pulled it inside the walls, and the soldiers hidden in it opened the gates at night. Same trick, smaller horse.

"Trojan virus" is the phrase everyone searches, but it's technically wrong. The accurate names are trojan horse or trojan malware. A virus copies itself into other files, and a worm spreads across the network on its own. A trojan does neither. It waits for a person to launch it, then it opens the gates for whatever comes next.

VirusWormTrojan
How it spreadsCopies itself into other filesMoves machine to machine by itselfDoesn't spread; a person runs it
Needs a click?Yes, to startNoYes, every time
What it looks likeAn infected fileOften nothing at allSomething useful
Typical jobDamage or spreadSpread fastSteal, spy, or load more malware

The distinction isn't pedantry. Worms get stopped with patching and segmentation. Trojans get stopped by controlling what users can run, and by spotting what the thing does once it starts.

How Trojans Get Onto Work Machines

A trojan needs a believable disguise and a person in a hurry. The routes in 2025 and 2026 look like this.

Fake installers from ads. Malvertising buys search ads for popular tools, so the top result for "Zoom download" or "7-Zip" can point to a lookalike site. The installer works, and it drops a trojan alongside.

Cracked and pirated software. Keygens and "free" versions of paid tools are a classic carrier. This r/msp thread is what it looks like from the MSP side: a client's vendor installed pirated diagnostic software, and SentinelOne raised 40+ alerts on the laptop before the MSP locked it onto guest Wi-Fi.

Email attachments and links. Invoices, shipping notices, shared-document alerts. Microsoft's Digital Crimes Unit found over 394,000 Windows computers infected with the Lumma infostealer between March 16 and May 16, 2025, delivered through spear-phishing and malvertising, before it took down Lumma's domains.

Fake updates and fake CAPTCHAs. A page claims your browser is out of date, or asks you to prove you're human. The newest version of this is ClickFix: the page copies a command to your clipboard and tells you to press Win+R, paste, and hit Enter. Microsoft Threat Intelligence described ClickFix in August 2025 as affecting thousands of devices a month, with Lumma as its most common payload.

ClickFix is sneaky because there's no file to download. The user types the attack in themselves. This r/sysadmin thread collects what admins are doing about it, from disabling the Run box through Intune to blocking PowerShell for everyone outside IT.

Types of Trojans

"Trojan" describes the disguise, not the job. Once it's running, it usually does one of these.

Remote access trojan (RAT). Gives the attacker a remote desktop they control: screen, keyboard, files, webcam. AsyncRAT, XWorm and NetSupport all show up as ClickFix payloads in Microsoft's write-up.

Infostealer. Grabs saved browser passwords, session cookies, crypto wallets and VPN configs, then sends them out straight away. Stolen session cookies let an attacker skip MFA, because the login already happened.

Banking trojan. Watches for banking sites and injects fake fields or redirects payments. Older families like Emotet started here before becoming loaders.

Downloader or loader. Small and quiet. Its only job is to fetch the next stage, often a RAT, a stealer, or ransomware.

Backdoor. Leaves a way back in, so the attacker can return after the first payload is cleaned up.

IBM Technology's short explainer walks through how a RAT gives an attacker hands-on control of a machine.

What EDR Sees When a Trojan Runs

Signature antivirus looks for known files. A new trojan build often isn't known yet, so modern endpoint tools watch behavior instead. Our guide to endpoint security covers where EPP ends and EDR starts.

Here's the trail a typical trojan leaves:

  • An odd parent process. Explorer launching PowerShell right after a browser visit. Word spawning a command shell. An installer in the Downloads folder starting mshta.exe.
  • Encoded or downloaded scripts. PowerShell running a long Base64 string, or pulling a file from a domain registered last week.
  • Persistence. A new Run registry key, a scheduled task, or a service, so it survives a reboot.
  • Credential access. Reads of browser password databases or the LSASS process.
  • Beaconing. Small, regular outbound connections to the same server, which is the trojan checking in for orders.

When Microsoft Defender catches one, the alert name tells you a lot. Microsoft names malware as Type:Platform/Family.Variant, so "Trojan:Win32/Wacatac.B!ml" reads as a trojan, for 32-bit Windows, family Wacatac, variant B. Anything after the "!" is an internal Microsoft marker. Microsoft doesn't document "!ml", though admins widely read it as a machine-learning detection, which is why a generic family like Wacatac lands on so many files nobody has named yet.

What to Do After Someone Clicks

Speed matters more than perfection here. An infostealer sends what it grabs as soon as it runs, so assume credentials are gone and work from there.

For staff, the rule is short. Tell IT right away, even if nothing seems to have happened. Disconnect from Wi-Fi or unplug the cable, but leave the machine on, because a running machine keeps evidence a reboot wipes. Don't try to clean it yourself, and don't feel bad about reporting it. The fast report is the part that saves the day.

For techs, the order that works:

  1. Isolate the device through your EDR's network containment, so it can't talk to anything but the console.
  2. Find what ran. Pull the process tree, the file hash and the source: download URL, email, or pasted command.
  3. Reset credentials from a clean device. Passwords first, then revoke active sessions and tokens, since stolen cookies survive a password change.
  4. Hunt for the same file elsewhere. Search by hash or installer name across the fleet. In OpenFrame, the live device inventory shows which machines have it installed.
  5. Reimage rather than clean. Removal tools can miss a backdoor. A fresh install from a known-good image is faster than proving a machine is clean.
  6. Close the door it came through. Block the domain, tighten who can install software, and consider disabling Win+R for users who never need it.

A Trojan Is a Disguise, Not a Virus

A trojan virus is malware that gets a person to run it by looking useful. It doesn't spread on its own, so the defenses that matter are control over what users can run, EDR that watches behavior, and a fast, blame-free way to report a bad click.

Trojans are often how bigger incidents start. Our breakdown of a ransomware attack shows what happens when a loader's next stage is ransomware.

Kristina Shkriabina

Content Marketing Lead

Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Trojans

Not technically. A virus copies itself into other files, and a trojan doesn't copy itself at all. It relies on a person running it because it looks like something useful. "Trojan virus" is the common name, but security tools classify it as a trojan, a separate type of malware.
Look for an alert from Microsoft Defender or your EDR with a name that starts with "Trojan:", new programs or scheduled tasks you didn't add, PowerShell windows flashing open, or unexpected sign-in alerts on your accounts. Many trojans show no visible symptoms, so the security tool's alert is often the only sign.
Yes. Infostealer trojans such as Lumma grab saved browser passwords and session cookies and send them to the attacker as soon as they run. Stolen session cookies can let an attacker skip MFA, so reset passwords from a clean device and revoke active sessions.
Tell IT immediately and disconnect the device from the network, but leave it powered on. Don't try to clean it yourself. IT should isolate the device, find what ran, reset credentials and revoke sessions, check other devices for the same file, and reimage the machine.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.