GCSE · Computer Science · AQA · Spec 8525

Trojan

Someone offers you a brilliant game for free. It downloads, it installs, it plays perfectly. So what’s the problem? The problem is what else it’s doing while you play.

Trojans · Follow the download

A free game you really want. Where does it lead?

Pick where the game comes from, then decide what to do with it. Walk every route — the endings are where the lesson is.

Where it comes from → What you do with it → What was hidden inside

7 possible endings.

On A free game you really want. 3 branches to choose from.

Notice what every harmful ending has in common: someone chose to run a program that came from a place they couldn’t trust.

Watch out: “It works fine” tells you nothing. A trojan can do exactly what it promised while doing harm in secret.

Trojan vs virus: how does it get in?

TrojanvsVirus

People mix these two up more than anything else in this topic. Read the first row twice.

Focus

How it gets onto a computer

Trojan

The user installs or runs it themselves, fooled by its disguise

Virus

It attaches itself to other files to spread

The insight

This is the difference to learn. A trojan relies on deceiving the user; a virus relies on copying itself.

Does it copy itself?

Trojan

No — a trojan does not replicate

Virus

Yes — a virus replicates itself

What kind of software is it?

Trojan

Malware — software written to harm a computer system, its data or its users

Virus

Malware too

Trojans · What do you really think?

What went wrong for Jay?

Jay installs a free photo editor from a link on a forum. It works brilliantly. A few days later, someone else is logging in to Jay’s online accounts.

Which is closest to what you think happened?
How sure are you?

Trojans · Your turn to write

Put it in your own words

Explain how the risk of a computer being infected by a trojan can be reduced. [6 marks]

0 words · your answer stays on this page and is not sent anywhere.

WHAT YOU'VE LEARNED

A quick recap of today's lesson.

It doesn’t break in. You let it in.

What you need to know

  • Malware (malicious software) is software written to harm a computer system, its data or its users. A trojan is one type of malware.
  • A trojan is disguised as legitimate, useful or harmless software — a free game, a handy tool, a file — so the user is tricked into installing or running it themselves.
  • Once it’s running, a trojan carries out a hidden harmful action: stealing data, deleting or damaging files, installing further malware, or opening a backdoor that lets an attacker access or control the computer remotely.
  • Unlike a virus, a trojan does not replicate itself or attach itself to other files to spread. It relies on deceiving the user.
  • To reduce the risk: only download and install software from trusted sources, scan files with anti-malware before running them, and don’t open unexpected email attachments.

The big picture

A trojan is malware disguised as software you’d actually want, so you install or run it yourself. Once it’s running, it carries out a hidden harmful action. Unlike a virus, it doesn’t copy itself to spread — which is why the best defence is being careful about what you let in.

Key points

1The disguise is the attack: a trojan gets in because someone chooses to run it.
2It can work exactly as promised while doing harm in secret.
3It doesn’t copy itself — that’s what separates it from a virus.
4Every defence stops the user running it: trusted sources, scanning first, leaving unexpected attachments unopened.

Worked example

Problem

A student downloads a free ‘homework helper’ app from a website they’ve never used before, and runs it. The app works as described. A week later, an attacker is able to control the student’s computer remotely. Identify the type of malware most likely involved, and explain your answer.

⚠ Watch out

Saying a trojan ‘spreads itself’ or ‘infects other files’. That’s a virus. A trojan doesn’t copy itself — it relies on fooling the user into installing or running it.

🧠

Memory hook

Remember the Trojan horse. Nobody broke down the city gates — the people of Troy pulled the wooden ‘gift’ inside themselves, with soldiers hidden in it. A trojan works the same way: the danger is hidden in the gift, and you carry it in.

✓

Check yourself

Cover the page. Why could a program that works perfectly still be a trojan? And for each of the three protective habits, what does it stop the user doing?

Flashcards

(11)
What is malware?
Malicious software: software written to harm a computer system, its data or its users.
What is a trojan?
Malware disguised as legitimate, useful or harmless software, so the user is tricked into installing or running it themselves.
Why does a trojan need a disguise?
Because it can’t get in on its own. It only reaches a computer when a user chooses to install or run it — so it has to look like something they want.
Name four hidden harmful actions a trojan might carry out once it’s running.
Stealing data; deleting or damaging files; installing further malware; opening a backdoor.
What is a backdoor?
A hidden way in that lets an attacker access or control the computer remotely.
Trojan vs virus: what’s the difference in how they spread?
A virus replicates itself and attaches to other files to spread. A trojan doesn’t copy itself — it relies on deceiving the user into installing it.
A free program works exactly as promised. Can it still be a trojan?
Yes. A trojan can do what it claims while also carrying out a hidden harmful action in the background.
A trojan has been downloaded but not yet run. Has it done any harm?
Not yet. A trojan can’t carry out its hidden action until someone runs it — so there’s still time to stop it.
How does downloading only from trusted sources reduce the risk of trojans?
It makes it much less likely that you’ll be handed malware disguised as genuine software.
When should you scan a downloaded file with anti-malware — and why then?
Before you run it. If it’s recognised as a trojan, it can be deleted before it ever carries out its hidden action.
Why shouldn’t you open unexpected email attachments?
An attachment can be a trojan in disguise, and it can only act once you open it. Left unopened, it can’t do anything.

Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.

Learning with Lightbulb is opening soon

You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.

Keep me posted

More AQA GCSE Computer Science topics

See the full AQA Computer Science curriculum →

How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 29 September 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.