Skip to main content

TrickBot banking trojan updated with new module


Forum|alt.badge.img+48


 
It's baaaaaaack.
 
Since inception in late 2016, the TrickBot banking trojan has continually undergone updates and changes in attempts to stay one step ahead of defenders. While TrickBot has not always been the stealthiest trojan, its authors have remained consistent in the use of new distribution vectors and development of new features for their product. On March 15, 2018, Webroot observed a module (tabDll32 / tabDll64) being downloaded by TrickBot that has not been seen in the wild before this time.
 
It appears that the TrickBot authors are still attempting to leverage MS17-010 and other lateral movement methods coupled with this module in an attempt to create a new monetization scheme for the group.
 
We go in depth on our blog into the behavioral analysis of TrickBot and provide insight into what might happen next. 
 
Sound off in the comments! We want to hear from you and what you've heard about TrickBot. What do you think?
 
 

14 replies

Forum|alt.badge.img+9
  • New Voice
  • 25 replies
  • March 22, 2018
Don't know much about this virus but thanks for the important info.

Forum|alt.badge.img+48
  • Author
  • Retired Webrooter
  • 1550 replies
  • March 22, 2018
Happy to share, @
 
We will keep monitoring it as this will continue to morph and change throughout the coming days. 
 
 

Forum|alt.badge.img+9
  • New Voice
  • 25 replies
  • March 22, 2018
It's easy for me to get lost throughout the Internet and in fact, the best way for me to communicate Aphasia to the layperson is; imagine the need to call 911 but you did not know how...the brain damage to my left, right hemisphere as well as its posterior was sever. I was a teacher and playing professionally but no more. 
Why do I write this? Rehab...learning how to move around, via the Internet.

Forum|alt.badge.img+9
  • New Voice
  • 25 replies
  • March 24, 2018
So, are you saying that this virus is going, specifically, after bank accounts? 
 
Thanks...

Baldrick
Gold VIP
  • Gold VIP
  • 16060 replies
  • March 24, 2018
@ wrote:
So, are you saying that this virus is going, specifically, after bank accounts? 
 
Thanks...
Essentially, 'Yes', but I would precise on that slightly by saying that it is more a case of going after ways to access bank accounts.
 
The trojan is most usually linked to phishing campaigns which aim to trick users into entering their credentials into fake banking websites, that in some case very carefully & cleverly designed to appear as legitimate services.
 
The new twist is that  in addition to it's primary objective, as stated above, it can now lock an infected system in a way that is very similar to more 'traditional' ransomware. So what we are seeing is a 'blending' of malware techniques.
 

Forum|alt.badge.img+9
  • New Voice
  • 25 replies
  • March 24, 2018
But wouldn't you have to be an idiot to give this type of info, to anyone? I see these spam emails once in a while. It's like the IRS impostor. 

Baldrick
Gold VIP
  • Gold VIP
  • 16060 replies
  • March 24, 2018
You would indeed...but you would be surprised how many idiots there are out there. :@

Forum|alt.badge.img+9
  • New Voice
  • 25 replies
  • March 24, 2018
Having brain damage to my left, right hemisphere as well as it posterior, I know there is a difference between brain damage and stupidity.
 
:D  

Baldrick
Gold VIP
  • Gold VIP
  • 16060 replies
  • March 24, 2018
But most of the idiots I am referring to do not have those mitigating circumstances...they are just plain ignorant and/or just do not care.

Forum|alt.badge.img+9
  • New Voice
  • 25 replies
  • March 24, 2018
I see nothing in the 'options' how to delete all messages...so, how is this done?

Baldrick
Gold VIP
  • Gold VIP
  • 16060 replies
  • March 24, 2018
@ wrote:
I see nothing in the 'options' how to delete all messages...so, how is this done?
Apologies...but which 'options' are you referring to?

Baldrick
Gold VIP
  • Gold VIP
  • 16060 replies
  • March 25, 2018
One cannot delete all messages in a thread but can delete one's own posts individually by clicking on the 3 vertical dots that are found in the top right hand corner of each post.

Forum|alt.badge.img+9
  • New Voice
  • 25 replies
  • March 25, 2018
Yes, I just found that out. Thanks. Another question I have; what is the advantage or disadvantage of making Att.net my Home Page? There is a list of things it will do for me but I'm not sure I want to go there. Changing all the data on my homepage is one thing it will do. I use Att.net all the time but have not made it my Home Page. In fact, I don't think I have a Home Page.

Baldrick
Gold VIP
  • Gold VIP
  • 16060 replies
  • March 25, 2018
Well, as far as I can see there should be no issue with setting ATT.net as your homepage. As one might expect the URL Lookup from Brightcloud gives it a 'Trustworthy' rating. And, further, it is very easy to change one's homepage setting as and when one gets tired of the ATT page.
 
The only changes that it should be making are to the homepage settng of the browser that you are using at the time you click on the 'Set as Homepage' link.
 
Hope that helps?
 
Baldrick

Reply