SECAI Core · phase 11 of 15
Trojan attack
A cyberattack that uses a malicious program disguised as legitimate software to trick users into installing it, after which it can create backdoors, steal data, download additional malware, or give attackers control of the compromised system.
The Explain card
- Plain English
- A trojan attack disguises a malicious program as legitimate software to trick users into installing it. Once inside, it can open backdoors, steal data, fetch more malware, or hand control to the attacker.
- Example
- A popular "free LLM desktop client" on a download site works as advertised but also exfiltrates every API key and conversation to a remote server.
- Why it matters
- AI tooling is young, fast-moving, and often installed from unofficial sources. Defenders vet software origins, verify signatures, and monitor outbound traffic from developer machines.
- Hook
- The gift horse with a hollow belly.
Where it sits in the deck
Phase 11: Threat Landscape: Attack Vectors and Adversarial Techniques
With defences named, learn what they must defend against — the full catalogue of attack techniques targeting AI systems, their inputs, outputs, training pipelines, and supply chains.