EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsEasy

A security auditor is evaluating the security posture of an organization's software development environment. They discover that developers are frequently downloading third-party libraries and tools from unverified sources. During a code review, a malicious function is found embedded within a seemingly legitimate open-source library, designed to exfiltrate source code whenever the library is compiled into an application. This malicious library was intentionally disguised as harmless. Which type of malware best describes this scenario?

  1. ATrojan Horse
  2. BVirus
  3. CRootkit
  4. DWorm
Show answer & explanation

Correct answer: A. Trojan Horse

A Trojan horse is a type of malware that disguises itself as legitimate software or a harmless file, but once activated, it performs malicious actions. The scenario describes a 'malicious function is found embedded within a seemingly legitimate open-source library, designed to exfiltrate source code', which is classic Trojan horse behavior.

Why the other options are wrong

  • B. A virus attaches to legitimate programs and requires execution to spread; while it can be disguised, the primary characteristic here is deceitful packaging.
  • C. A rootkit focuses on hiding its presence and maintaining access, not primarily on initial deceptive delivery.
  • D. A worm is self-replicating and spreads autonomously, which is not the primary characteristic of this scenario.

Trojan Horse

Malware that disguises itself as legitimate software to gain access to a system, then performs malicious actions once executed.

  • Relies on social engineering to trick users into installing it.
  • Does not self-replicate.
  • Can deliver various payloads (e.g., backdoors, data theft, ransomware).

Memory trick: Trojans Trick You with a Gift.

More Malware Threats questions