A Trojan horse (Trojan, Trojan, Trojan horse) is a Malicious Program | Antivirus

A Trojan horse (Trojan, Trojan, Trojan horse) is a malicious program.


Trojan horse (Trojan, Trojan, Trojan horse) is a malicious program spread through infected sites, file sharing, attachments to e-mail messages or applications for operating systems downloaded from the Internet.




The main task of the Trojans is to establish the attacker's control over the user's infected computer.


Installing backdoors, a virus downloader, or stealing confidential data is the main purpose of Trojans.




Most Trojans disguise themselves as harmless or useful files or programs to be launched by the user on a PC.


The bait can be information files or tempting advertising files in MS Office formats, images and archives from the mailing list by e-mail.


Often, such emails do not contain attachments, but rather try to lure the victim to a malicious site that will try to infect the computer and place Trojans on it. Such mailings are often disguised as popular ones, from well-known sites, social networks, and other services with a large number of users.




Trojans also enter users' PCs through files downloaded from the Internet. The user himself searches for the program of interest to him, downloads it from an unsafe site, and receives a Trojan horse. Untested torrent distributions carry the threat of getting a Trojan on your PC.




The maximum risk of getting a Trojan horse on a PC is downloading it from a hacked site you visit. As an example, you can take any popular accounting site, from where forms and sample documents are massively downloaded, or a site containing instructions for something, stored in files of popular formats, such as MS Office or Adobe PDF documents.


An unsuspecting user downloads from such a site a legal (in his opinion) document, which was replaced by a Trojan program after the site was hacked.




Trojans are the simplest type of malware, the complexity of which depends only on the task at hand.


The most primitive Trojans (for example, those that open the download of other malicious software onto a computer) can contain several lines of code.




The Trojan horse can, to one degree or another, imitate or even fully perform the task for which it disguises itself if the malicious code is embedded into an existing program by an attacker.


Sometimes the use of Trojans is only part of a multi-stage attack on specific computers, networks or resources.






Trojan Ransomware




To date, ransomware Trojans have acquired a high level of threat.


Unlike traditional theft of credentials to e-mail, bank accounts, access to social networks, and other confidential information, such Trojans ensure the download and execution of malicious code on the victim's computer, which:




Blocks the bootloader of the operating system (Windows, Mac OS), threatens and requires the transfer of money to a phone number or wallet of the payment system.


Encrypts all user files with cryptographic strong algorithms. To decrypt files, it is proposed to buy a key for a lot of money.




In the first case, when the OS loader is blocked due to the actions of the Trojan, the problem is solved quite easily (unless there have been any global changes to the OS file system). This type, scheme and algorithms for the operation of fraudulent malicious programs are well known to specialists in the field of information security, and almost every antivirus laboratory offers tools to eliminate both the consequences of malicious actions and the Trojan itself.




In the second case, everything is much more complicated. If the malicious code downloaded by the Trojan has completed its work completely, it leaves no chance to "save" its files without buying a key from the cybercriminals. Such an attack is a serious and painstaking work of hackers at a very high level.




In most cases, a personal account is opened for the victim on a website specially created by cybercriminals to pay and receive a key that will decrypt the files. Also, a Bitcoin (or any other cryptocurrency) wallet is opened for the victim to transfer money.


The Trojan leaves detailed information on the victim's desktop on how to buy a key, convert and pay cryptocurrencies, and more.


The ransom amount is usually high, from $ 100 and more, and depends on the number and type of files encrypted by the malware.


For example, if a Trojan encrypted 1C files of the accounting department of a commercial structure, the ransom amount can reach ten thousand dollars or more.


In this case, all actions for selling, invoicing, issuing keys, etc. are automatic.


Hacker sites are based on anonymous networks (* .onion) and work with cryptocurrency minimizes the risk of hackers being calculated by law enforcement officers.




Antivirus laboratories, today, do not have universal solutions to the problem of file encryption by modern ransomware Trojans.




Trojan horse protection


Use modern anti-virus protection, regularly update databases.


Under no circumstances should you open and run attachments (files) received by e-mail from unknown sources.


Check any files downloaded from the Web or received by e-mail with antivirus software.


Do not visit or download anything from questionable sites.


For the owner of a popular resource, taking care of the safety of its visitors should be one of the top priorities.


Such sites must be reliably protected from hacking to prevent the spread of malicious code to user computers.

Comments

Popular posts from this blog

Why Not to Restart Your Computer if It Is Infected With the Ransomware | Total Security

What Is a Ransomware Virus and How Do You Protect Your Computer From It | Total Security

What is a zero-day threat? Free Antivirus Software