Back in the day when the Greeks wanted to invade the city of Troy, the only way their army could get past the fortified gates was by trickery.
They built a colossal wooden horse statue, which just happened to have a hollow belly. Then they hid a small fighting force in the horse’s belly and pretended to abandon the battle field (all while convincing the Trojans that said horse was both a gift and a blessing).
Of course, once the Trojans had wheeled the ‘gift’ inside, the Greek soldiers emerged from their hiding place, threw open the gates to the rest of their army and voilà – the defenders of Troy found themselves outsmarted and overrun.
Fast forward to 2024, and trickery is still in fashion…
The Trojan Horse concept is alive and well, entrenched as part of the hacker fraternity’s regular bag of tricks.
While the horse part of the description has been abandoned, “Trojan” is the term given to a destructive program that gets onto your device because it mimics benign applications.
Trojans are often found within macros in Word or Excel files, as it can easily be attached to an email and sent to you.
How does it work?
You receive an email (and it might well be from someone you consider to be a trusted source). The email has a Word document or an Excel file attached to it. When you download the file to open it, a message, something like the following, pops up: “Macros have been disabled. Do you want to make this a trusted document?”
If you answer “Yes”, you enable the macros embedded in the document to function, as well as any Trojan they contain. This may then result in malware such as keystroke logging software installing itself on your device, ready to record and share sensitive information such as passwords that you enter via your keyboard.
By now, I hope your alarm bells are clanging.
Because, just as you should never click on a suspicious link in an email, you should also stop and think twice before downloading and opening any document that is attached to an email.
Here’s what to do if you receive an email with an attachment:
- Call the supposed sender directly and ensure that the email is genuine.
- Check that they have indeed sent you an attached file.
- Check whether the attached file contains macros and whether they are enabled or disabled.
- If it all checks out with a bona fide contact, you can go ahead and download the file and “trust” it.



0 Comments