Trojan
Malware disguised as legitimate software, which relies on the user choosing to install it.
Definition
A trojan is malware disguised as legitimate or desirable software. Unlike a worm it does not spread by itself; it depends on a person choosing to install or run it, which is why it is fundamentally a social engineering technique.
The defining characteristic is deception rather than technical propagation. A trojan presents itself as something the user wants or expects: a document viewer, an invoice, a delivery receipt, a cracked application, a system update. The user installs it deliberately, believing they are getting something else.
Common categories include banking trojans that intercept credentials and one-time passcodes, remote access trojans (RATs) that give an attacker interactive control of the device, droppers whose only job is to install further malware, and information stealers that harvest saved credentials and session cookies.
In Indonesia the dominant form is the malicious Android install file distributed through WhatsApp, disguised as an invitation, delivery receipt or tax document. It is a textbook banking trojan: it requests SMS and notification access, intercepts one-time passcodes, and enables account takeover. The disguise is the whole attack, which is why the defence is behavioural rather than technical.
At a glance
- Severity
- High
- Prevalence
- Very common, and the dominant mobile threat in Indonesia
- Primary targets
- Android users, finance and operations staff, anyone with banking access
How it works
- 1
Disguise: the payload is packaged as something legitimate and expected
- 2
Delivery: it arrives by message, email attachment, download site or app store listing
- 3
Installation: the user runs it deliberately, often granting permissions during setup
- 4
Execution: the real function begins, whether interception, remote access or credential theft
- 5
Persistence: it survives reboots and hides from casual inspection
Warning signs
- A document or receipt that requires installing an application to view
- An installer arriving through a messaging app rather than an official store
- Permission requests unrelated to the stated purpose, such as SMS access for an invitation
- A device becoming hot, slow, or draining battery shortly after an install
- Security software or update mechanisms unexpectedly disabled
How to defend
- Never install an application in order to view a document; this single rule blocks the dominant Indonesian variant
- Restrict installation from unknown sources on managed devices
- Keep the number of people with both banking access and unmanaged devices as small as possible
- Use phishing-resistant MFA so intercepted SMS codes are not sufficient
- Train the specific scenarios in circulation rather than generic malware awareness
Real-world example
An Indonesian bank employee receives a wedding invitation file on WhatsApp from an unfamiliar number. Installing it grants SMS access, and within hours the attacker intercepts an authentication code and empties a personal account. No technical control was bypassed; the employee installed the malware themselves, believing it was an invitation viewer.
How Claro helps
A trojan requires a person to install it, so it is defeated at the decision point rather than the detection point. Claro measures whether staff would take that action, including WhatsApp-delivered file scenarios that mirror the campaigns currently running in Indonesia, and trains the specific rule that stops them: never install an application to view a document.
Frequently asked questions
What is a trojan?
Malware disguised as legitimate or desirable software. Unlike a worm it does not spread on its own; it relies on a person choosing to install or run it, which makes it a social engineering technique as much as a technical one.
What is the difference between a trojan and a virus?
A virus attaches itself to files or programs and spreads through them. A trojan does not self-replicate at all; it relies entirely on deceiving the user into installing it. The disguise is the mechanism.
What is a banking trojan?
A trojan designed to steal financial credentials and intercept authentication codes, usually by requesting SMS and notification access. The malicious APK files circulating on WhatsApp in Indonesia are the most common current example.
Can antivirus software stop a trojan?
Sometimes, when the sample is known. New and repackaged variants routinely evade detection, and on mobile the user grants permissions explicitly during install. Because the attack depends on a human decision, awareness is the more reliable control.
Related terms
Malware
Any software intentionally designed to damage, disrupt, or gain unauthorized access to a device or network.
Spyware
Software that secretly monitors a user's activity and collects information such as browsing habits, keystrokes, or credentials without consent.
Keylogger
A type of spyware that records every keystroke a user types, capturing passwords, messages, and other sensitive input.
Account Takeover
When an attacker gains unauthorized control of a user's online account, typically through stolen credentials, and uses it for fraud or further attacks.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo