Perfect Camouflage

Trojan disguises proxy traffic as standard HTTPS web browsing by emulating real TLS handshakes and HTTP traffic patterns. Censorship systems cannot distinguish it from legitimate connections to websites like Google or Facebook.

High Performance

Minimal protocol overhead means Trojan delivers near-native speeds. Simple design with TLS 1.3 encryption provides excellent throughput and low latency—ideal for streaming, gaming, and bandwidth-intensive applications.

Anti-Detection Design

Unlike other protocols with identifiable patterns, Trojan's traffic is statistically identical to regular HTTPS. No protocol signatures, no behavioral anomalies—making machine learning detection systems completely ineffective.

Why Trojan Protocol?

The stealth specialist for maximum undetectability in 2026

Unblockable by Nature

Trojan's genius lies in simplicity: it looks exactly like HTTPS traffic because it IS legitimate TLS. Blocking Trojan means blocking all HTTPS, which would disable the entire modern web. Censors physically cannot target it.

Lightweight Protocol

Trojan has minimal overhead compared to VMess or Shadowsocks. The protocol header is tiny, encryption is handled by TLS, and there's no unnecessary packet manipulation—resulting in excellent speed and low CPU usage.

Password Authentication

Simple SHA-224 hashed password authentication instead of complex UUID or certificate systems. Easy to configure, impossible to brute force, and the authentication happens inside the encrypted TLS tunnel.

Proven in GFW

Trojan was specifically designed to defeat China's Great Firewall and has succeeded where many protocols failed. Its effectiveness in the world's most sophisticated censorship environment proves its capabilities.

Technical Specifications

✓
Protocol

Trojan over WebSocket

✓
Encryption

TLS 1.3 (ECDHE-RSA)

✓
Port

443 (HTTPS)

✓
Authentication

SHA-224 password hash

✓
Bandwidth

Unlimited (10Gbps)

✓
Active Period

3 days

Best Applications

  • Bypassing sophisticated censorship (GFW, etc)
  • Maximum stealth on monitored networks
  • High-speed streaming without throttling
  • Gaming with minimal latency overhead
  • Environments where other VPNs are blocked
  • Corporate networks with aggressive DPI

The Trojan Protocol Advantage

Trojan represents a fundamentally different approach to censorship circumvention. While most proxy protocols try to hide themselves through obfuscation or disguise, Trojan achieves invisibility by being completely transparent. It doesn't try to look like HTTPS traffic—it actually IS normal TLS traffic carrying legitimate-looking data. This philosophical difference makes Trojan uniquely effective against modern detection systems.

The protocol works by establishing a genuine TLS 1.3 connection to the server, exactly as a web browser would when visiting an HTTPS website. Inside this encrypted tunnel, Trojan sends a SHA-224 hashed password for authentication. If the password is correct, the server proxies your traffic. If incorrect, the server responds exactly as if it were a normal web server receiving garbage data—making active probing attacks futile. To an observer, even incorrect authentication attempts look like normal HTTPS noise.

This design philosophy makes Trojan immune to statistical analysis and machine learning detection. There are no packet size patterns to analyze, no timing signatures to fingerprint, and no protocol-specific behaviors to identify. Every aspect of Trojan traffic is statistically identical to regular HTTPS connections. Even if censors capture and analyze thousands of Trojan connections, they cannot build a detection model without also flagging countless legitimate HTTPS sessions.

Performance-wise, Trojan excels due to its minimalist design. The protocol adds only a tiny header (56 bytes) before forwarding traffic through the TLS tunnel. All encryption is handled by standard TLS 1.3, meaning you benefit from hardware-accelerated AES-NI on modern CPUs. The result is throughput and latency very close to a direct connection—significantly faster than protocols like VMess that add additional encryption layers.

Our Trojan WebSocket servers run on Xray-core with WebSocket transport for maximum compatibility across different network environments. Each server features 10Gbps connections, NVMe SSD storage, and supports unlimited bandwidth for 3 days. Compatible with v2rayNG, Clash, Shadowrocket, and all clients that support Trojan protocol. Includes fallback website configuration so the server appears as a legitimate web service when accessed directly.