EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsEasy

A security analyst discovers a malicious program that, when executed, attempts to disable security software, modify system registry settings, and establish persistent communication with a command-and-control server. This program appears legitimate to the user and requires user interaction to execute. Which category of malware best describes this behavior?

  1. ARootkit
  2. BWorm
  3. CVirus
  4. DTrojan
Show answer & explanation

Correct answer: D. Trojan

The description of a program that appears legitimate, requires user interaction, and then performs malicious actions like disabling security software, modifying settings, and communicating with a C2 server, is a classic definition of a Trojan horse.

Why the other options are wrong

  • A. A rootkit focuses on hiding its presence and maintaining privileged access, not necessarily on initially deceiving the user into execution through a legitimate-looking facade.
  • B. Worms are self-replicating and spread independently, not typically relying on appearing legitimate or user interaction for initial execution.
  • C. Viruses attach to legitimate programs and self-replicate, but the primary characteristic here is deception and hidden malicious functionality, not just replication.

Trojan Horse

A type of malware that disguises itself as legitimate software or a harmless file to trick users into installing and executing it, then performs malicious actions in the background.

  • Relies on deception and user interaction for initial infection.
  • Does not self-replicate like viruses or worms.
  • Can create backdoors, steal data, or install other malware.

Memory trick: The 'Trojan' horse looks like a gift, but hides a malicious force.

More Malware Threats questions