Removing a Trojan That Sends Fake Email Replies
A Trojan that sends replies from your mailbox can make familiar conversations look genuine. It may answer messages, forward malicious links, alter email settings, or use stolen browser sessions without showing an obvious warning. The activity can affect Gmail, Outlook, Microsoft 365, Apple Mail, or a business account connected to the infected computer.
Treat the incident as both a malware problem and an account-security problem. The cleanup steps below suit Windows and Mac users in Australia, including people working from home over the NBN or managing customer email for a small business.
| Sign |
Likely cause |
Immediate response |
| Replies appear in Sent or conversation threads |
Trojan or stolen session |
Disconnect the device and review account activity |
| Unknown forwarding rule |
Mailbox compromise |
Remove the rule and change the password |
| Pop-ups, redirects, or slow performance |
Active malware |
Run an offline or Safe Mode scan |
| Contacts receive suspicious attachments |
Account or address-book abuse |
Warn contacts and secure every linked account |
Recognise The Warning Signs
Check the Sent folder, Drafts, Deleted Items, and unusual conversation threads for messages you did not create. A Trojan may copy the wording and signature you normally use, making a fake reply appear to come from the same thread. Look for odd times, unfamiliar attachments, shortened links, or replies written in an unusual tone.
Sign in to your email provider through its official website rather than an email link. Review recent sign-ins, connected applications, automatic forwarding, mailbox rules, recovery addresses, and app passwords. If the activity includes an Australian bank, myGov, Medicare, or a work mailbox, handle those accounts as a priority and contact the organisation through its published number.
Isolate The Infected Device
Disconnect Wi-Fi and unplug the Ethernet cable as soon as practical. This can stop the Trojan from contacting its command server or sending further messages, although it does not undo emails already delivered. Do not log in to banking, shopping, tax, or work services from the suspicious computer while it is still being examined.
Use a clean phone or another trusted computer to tell important contacts that recent replies may be fraudulent. Australians often describe suspicious activity as “dodgy”, but avoid forwarding the malicious message repeatedly because links and attachments can remain active. Preserve a copy of the email headers if your workplace or an incident-response provider needs evidence.
Secure The Email Account
Change the email password from a clean device and use a unique passphrase that has not appeared on another service. Enable multi-factor authentication through an authenticator app or security key where available. If the mailbox belongs to an employer, notify the administrator because an attacker may have created rules or stolen an access token that a password change alone will not remove.
Remove unknown sessions, third-party applications, app passwords, forwarding addresses, and rules that move or delete messages. Review the recovery phone number and email address as well. For Microsoft 365 or Google Workspace accounts, an administrator may need to revoke active sessions and inspect audit logs across the organisation.
Scan Windows And Mac Thoroughly
On Windows, start with Microsoft Defender and update its security intelligence before scanning. If normal Windows cannot complete a reliable check, use Microsoft Defender Offline or start in Safe Mode with Networking only when a trusted scanner requires it. Remove suspicious programs from installed apps, startup entries, scheduled tasks, and browser extensions.
On macOS, update macOS and run a reputable, current anti-malware scanner. Inspect Login Items, browser extensions, unfamiliar configuration profiles, and applications installed around the time the fake replies began. A Trojan may use a convincing name, so check the developer, installation date, and location before deleting anything.
Useful cleanup targets include:
- Recently installed programs and browser add-ons
- Unknown startup agents or scheduled tasks
- Modified proxy, DNS, or browser settings
- Files downloaded from unsolicited email
Remove Persistence And Leftovers
Do not open an attachment to identify the malware, and do not trust a pop-up offering a “cleaner” or “support” number. Uninstall software through the operating system, quarantine detected files, and restart only after the security tool reports that the threat has been handled. If the scanner identifies a banking Trojan, password stealer, or remote-access tool, assume saved passwords may be exposed.
Some infections survive a basic scan through scheduled tasks, launch agents, browser synchronisation, or a second payload. Run a second-opinion scan from a well-known vendor and examine browser sync on every connected device. A full reset or clean operating-system installation may be safer when detection keeps returning, especially on a computer used for payroll, invoicing, or client records.
Verify The Mailbox And Recover Data
After cleanup, sign in again and check that no fake replies, forwarding rules, filters, signatures, or delegated users remain. Ask trusted recipients whether they received messages from you and request deletion of suspicious attachments. Search for password-reset notifications, delivery failures, and alerts that could reveal further account misuse.
If the Trojan encrypted or deleted files, avoid repeatedly modifying the affected disk. Preserve backups and consider reputable file-recovery software or professional assistance. For broader security developments and current threat reports, consult security news, while remembering that educational guidance cannot replace an incident-response service for a business breach.
Prevent A Repeat Infection
Keep Windows, macOS, browsers, mail apps, and PDF readers patched. Use a password manager, turn on multi-factor authentication, and keep offline or versioned backups. Treat unexpected invoices, parcel notices, and shared-document alerts with caution, even when the sender name looks familiar.
Australian users should be especially wary of fake Australia Post deliveries, ATO-themed messages, NBN account warnings, and “missed call” texts that lead to credential-stealing pages. Scamwatch and the Australian Cyber Security Centre provide local reporting and safety information. Small operators in Sydney, Melbourne, Brisbane, Perth, and regional areas should also separate personal and business accounts and limit administrator access.
Practical habits that reduce exposure include:
- Verify unusual payment or password requests by phone
- Hover over links before opening them
- Disable automatic document macros
- Keep a tested backup disconnected from daily use
If you need another language reference for identifying and removing this type of infection, a German Trojan guide covers related malware-cleanup considerations. Once the device and mailbox are clean, continue monitoring sign-in alerts and sent messages for several days.