EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsEasy
A security analyst discovers a malicious program that, when executed, attempts to disable security software, modify system registry settings, and establish persistent communication with a command-and-control server. This program appears legitimate to the user and requires user interaction to execute. Which category of malware best describes this behavior?
- ARootkit
- BWorm
- CVirus
- DTrojan
Show answer & explanationAnswer & explanation
Correct answer: D. Trojan
The description of a program that appears legitimate, requires user interaction, and then performs malicious actions like disabling security software, modifying settings, and communicating with a C2 server, is a classic definition of a Trojan horse.
Why the other options are wrong
- A. A rootkit focuses on hiding its presence and maintaining privileged access, not necessarily on initially deceiving the user into execution through a legitimate-looking facade.
- B. Worms are self-replicating and spread independently, not typically relying on appearing legitimate or user interaction for initial execution.
- C. Viruses attach to legitimate programs and self-replicate, but the primary characteristic here is deception and hidden malicious functionality, not just replication.
Trojan Horse
A type of malware that disguises itself as legitimate software or a harmless file to trick users into installing and executing it, then performs malicious actions in the background.
- Relies on deception and user interaction for initial infection.
- Does not self-replicate like viruses or worms.
- Can create backdoors, steal data, or install other malware.
Memory trick: The 'Trojan' horse looks like a gift, but hides a malicious force.