GCSE · Computer Science · AQA · Spec 8525
Trojan
Someone offers you a brilliant game for free. It downloads, it installs, it plays perfectly. So what’s the problem? The problem is what else it’s doing while you play.
Trojans · Follow the download
A free game you really want. Where does it lead?
Pick where the game comes from, then decide what to do with it. Walk every route — the endings are where the lesson is.
Where it comes from → What you do with it → What was hidden inside
7 possible endings.
Notice what every harmful ending has in common: someone chose to run a program that came from a place they couldn’t trust.
WHAT YOU'VE LEARNED
A quick recap of today's lesson.
It doesn’t break in. You let it in.
What you need to know
- Malware (malicious software) is software written to harm a computer system, its data or its users. A trojan is one type of malware.
- A trojan is disguised as legitimate, useful or harmless software — a free game, a handy tool, a file — so the user is tricked into installing or running it themselves.
- Once it’s running, a trojan carries out a hidden harmful action: stealing data, deleting or damaging files, installing further malware, or opening a backdoor that lets an attacker access or control the computer remotely.
- Unlike a virus, a trojan does not replicate itself or attach itself to other files to spread. It relies on deceiving the user.
- To reduce the risk: only download and install software from trusted sources, scan files with anti-malware before running them, and don’t open unexpected email attachments.
The big picture
A trojan is malware disguised as software you’d actually want, so you install or run it yourself. Once it’s running, it carries out a hidden harmful action. Unlike a virus, it doesn’t copy itself to spread — which is why the best defence is being careful about what you let in.
Key points
Worked example
Problem
A student downloads a free ‘homework helper’ app from a website they’ve never used before, and runs it. The app works as described. A week later, an attacker is able to control the student’s computer remotely. Identify the type of malware most likely involved, and explain your answer.
⚠ Watch out
Saying a trojan ‘spreads itself’ or ‘infects other files’. That’s a virus. A trojan doesn’t copy itself — it relies on fooling the user into installing or running it.
Memory hook
Remember the Trojan horse. Nobody broke down the city gates — the people of Troy pulled the wooden ‘gift’ inside themselves, with soldiers hidden in it. A trojan works the same way: the danger is hidden in the gift, and you carry it in.
Check yourself
Cover the page. Why could a program that works perfectly still be a trojan? And for each of the three protective habits, what does it stop the user doing?
Flashcards
(11)What is malware?
What is a trojan?
Why does a trojan need a disguise?
Name four hidden harmful actions a trojan might carry out once it’s running.
What is a backdoor?
Trojan vs virus: what’s the difference in how they spread?
A free program works exactly as promised. Can it still be a trojan?
A trojan has been downloaded but not yet run. Has it done any harm?
How does downloading only from trusted sources reduce the risk of trojans?
When should you scan a downloaded file with anti-malware — and why then?
Why shouldn’t you open unexpected email attachments?
Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.
Learning with Lightbulb is opening soon
You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.
Keep me postedMore AQA GCSE Computer Science topics
How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 29 September 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.