"You have been infected with a Trojan Horse."

"Pay in Bitcoin immediately."

If you've received an email like this demanding payment in crypto assets (also known as virtual currencies) and you're now researching whether it's real, this article is for you.

The short answer: emails like this are almost certainly a "scam," and you do not need to follow the instructions.

The fact that Bitcoin is specified is itself a classic extortion tactic, and the likelihood that your device is actually infected with malicious software is extremely low.

This article explains what's really behind these Bitcoin (and other crypto assets) extortion emails that falsely claim a "Trojan Horse" infection, and how to respond to them.

[Conclusion] "Trojan Horse" + Bitcoin demand emails are almost always scams

Emails that claim your device has been infected with a Trojan Horse and demand crypto assets such as Bitcoin are almost certainly scams.

In fact, the Japan Cybercrime Control Center has publicly reported that numerous similar extortion emails have been confirmed.

These emails typically claim that:

  • A Trojan Horse has been installed on your device
  • Your email account or computer has been accessed without authorization
  • An explicit video of you has been recorded
  • You must send Bitcoin, or the material will be made public

These tactics are reported to be used to create fear and pressure the recipient into sending crypto assets.

These extortion emails are mass-distributed, fabricated demands sent to an unspecified large number of people, and cases where the recipient's device has actually been infected with a Trojan Horse or their activity is genuinely being monitored are extremely rare.

In recent years, advances in AI have made it possible to generate natural-sounding, highly specific emails in Japanese, so recipients need to be careful.

That said, the moment a demand specifies payment in a crypto asset such as Bitcoin, it is safe to conclude it is a typical scam.

If you receive an email like this, there is no need to pay Bitcoin or reply — the best response is simply to ignore it.

What exactly is a "Trojan Horse"?

A Trojan Horse is malware (malicious software) that disguises itself as an ordinary file or program while secretly performing harmful actions in the background.

If a device becomes infected with a Trojan Horse, it can lead to:

  • Theft of information stored on a computer or smartphone
  • Remote control of the device by a third party
  • Other viruses being installed without the user's knowledge

These are real risks that a Trojan Horse infection can cause.

However, devices generally do not become infected on their own without any action by the user.

In most cases, infection is triggered by opening a suspicious attachment or installing unauthorized software.

The phrase "you have been infected with a Trojan Horse," as used in extortion emails like the one described here, is in most cases simply a stock phrase designed to create fear.

What you should absolutely never do when you receive a crypto-related extortion email

If you receive a scam email claiming your device is infected with a Trojan Horse and demanding crypto assets such as Bitcoin, you should never do any of the following:

  • Open any file or link attached to the email
  • Install any software or app as instructed in the email
  • Reply to the scam email
  • Send Bitcoin or any other crypto asset

Opening a file or link attached to the email

The most dangerous action you can take with this type of scam email is opening an attached file or link.

In general, simply receiving the email does not mean your device has been infected with malware.

However, opening an attached file or link can trigger the installation of actual malware hidden inside it.

These emails are carefully crafted to get you to click, often using phrases such as:

  • "Click here for the video evidence"
  • "Check your Trojan Horse infection status"
  • "Download a tool to remove the Trojan Horse"

Clicking on these can result in an actual virus infection the moment you open them.

Opening a link or attachment is the action that turns a scam attempt into a real security incident.

Even if the content makes you curious, never open it — delete the email as is.

Installing software as instructed in the email

Some extortion emails instruct you to install a specific piece of software or app, describing it as a "verification tool" or "security software."

However, the moment such software is recommended through an unsolicited email, it is almost never legitimate.

If your device genuinely has a problem, a notification would come from your OS or a genuine, trusted security program — not from an unsolicited email.

You should never trust a third party instructing you via email that "installing this software will solve the problem."

Once installed, this can lead to real damage.

Cases resulting in leaked personal information or remote control of the device, with irreversible consequences, have been reported.

Words like "remove" or "protect" used in these extortion emails are nothing more than language designed to create fear.

Consider the act of installing software prompted by such an email to be inherently dangerous.

Replying to the scam email

With this type of scam email, even replying can create risk.

Even if your intent is to dispute the claim or verify the facts, you should not reply.

Replying can lead to the sender learning that:

  • Your email address is active and in use
  • You are someone who "reacts when anxious"
  • Replying often leads to more aggressive threats or a different variation of the scam email being sent to you

Scammers may also expect a reply and use it as an opportunity to send more specific threats or fabricated "evidence" to increase your fear — this is not uncommon.

Even if the content makes you curious, the safest response is not to reply and simply ignore it.

Sending Bitcoin or other crypto assets

Everything demanded in these extortion emails is false.

For that reason, you should never send Bitcoin or any other crypto asset, no matter what is demanded.

Bitcoin is specified precisely because transactions cannot be reversed and it is difficult to identify the recipient.

If you do send a payment, it cannot be refunded, and at that point the financial loss becomes final.

In addition, once you pay, you may be identified as someone who "complies," leading to additional demands for money or further extortion under a different pretext.

In short, sending even a single payment marks you as a target, opening the door to secondary victimization.

Scammers rely on making you believe that "paying will make it stop" or "just this once won't hurt."

Not paying is the only correct response, so please make sure never to send any payment.

How to check whether your device is actually infected with a Trojan Horse

Emails mentioning "Trojan Horse" and "Bitcoin" are almost always scams.

If you follow the precautions described above, you generally will not become infected.

That said, if you're still concerned about a possible infection, check the following three things.

Run a full scan with security software

This checks whether your device has actually been compromised.

Use a commercial antivirus program or the security features built into your OS to run a full scan.

If the scan detects nothing, there is no need to suspect a serious malware infection at that point.

At the very least, you can conclude that your device is not in the state described in the email — "fully controlled" by an attacker.

What matters here is comparing the scan results with the claims made in the email.

If the email claims that "a Trojan Horse has been installed" or "all of your activity is being monitored," but your security software detects nothing, then those claims have no basis in reality.

Check for any unusual behavior on your device

Check your computer or smartphone for any obvious abnormal behavior.

What you should look at here is simply whether anything feels off compared to your normal daily use.

For reference, unusual behavior might look something like this:

If your device operates normally, the screen doesn't move on its own, and you're not seeing frequent unfamiliar warnings, it's safe to conclude that the likelihood of real harm is low.

If a device is genuinely being remotely controlled or having information stolen via a Trojan Horse, some kind of ongoing abnormality will typically appear.

If your security software scan comes back clean and you see no clear abnormal behavior on your device, it's fine to conclude at this point that "no real harm has occurred."

Check whether the email content is a generic threat that "applies to anyone"

Most extortion emails are designed to be sent to an unspecified large number of recipients.

In other words, they only contain language generic enough to apply to anyone.

For example, phrases such as:

  • "I installed a Trojan Horse"
  • "I am monitoring all of your activity"
  • "I recorded an explicit video"

At first glance, these can feel alarming.

However, if no objective evidence is provided — such as a specific date and time, an actual file name, or a photo or video — the threat does not hold up.

If the sender genuinely had compromising material, some kind of specific, concrete detail would be presented.

An email lacking any such element is, from the start, a form letter designed solely to create fear.

If the content is vague and worded so that any reader might feel "this could be about me," it's safe to conclude that it is exactly this kind of mass-distributed extortion email.

Once you've confirmed all of the above and found no issues, there's no need to worry further about the email.

You can safely ignore it, delete it, and continue using your device as normal.

Summary

Any scam email containing the words "Trojan Horse" and "Bitcoin" is, almost without exception, a scam.

Even if you receive an email like this, following these four rules will bring your risk of actual harm close to zero:

  • Don't open any file or link attached to the email
  • Don't install any software or app as instructed in the email
  • Don't reply to the scam email
  • Don't send Bitcoin

What matters most is not letting the content of the email dictate your actions.

The fact that you're researching this calmly right now already puts you outside the typical pattern of someone who falls victim to this kind of scam.

This type of extortion email should simply be ignored and deleted — you can safely continue using your device as before.

This article is for informational purposes only and does not constitute financial or investment advice. Please consult a qualified professional before making investment decisions.