News

Banking Trojan TrickBot learned to spam and has already collected 250 million email addresses

Malicious program TrickBot, designed to steal credentials and contacts of victims, received an additional module “TrickBooster”.

This module allows sending malicious emails on behalf of an infected user.

“TrickBooster gives TrickBot a highly-effective way to spread infection. By sending emails from trusted addresses within an organization TrickBot increases the odds that a would-be victim will open one of its trojanized attachments”, — writes Forbes IS reviewer Lee Mathews.

At the same time, TrickBot acts very carefully – after sending letters, the malware removes them from the “sent” folder. By doing this, he manages to avoid detection.

Researchers at Deep Instinct, who discovered servers associated with TrickBot spam campaigns, claim that to date, malware operators have managed to collect more than 250 million email addresses.

Among them is considerable amount of Gmail, Yahoo and Hotmail mailboxes, but there are also several emails owned by governmental agencies.

“U.S.-based accounts caught up in TrickBot’s web include staff from the Department of Justice, Department of State, Homeland Security, the Postal Service, as well as the FAA, ATF, IRS and NASA. Email accounts belonging to numerous Canadian and British agencies were also found in the database”, — reported Deep Instinct specialists.

If the user’s computer is already infected with TrickBot, the malware can download the TrickBooster component separately. After that, malware will send a list of victim’s contacts to attackers.

Reference:

At its core, TrickBot is a banking Trojan. The malware is typically distributed via spearphishing emails — like bogus resumes sent to human resources or invoices sent to accounts staff. Those are typically attached in the form of weaponized Microsoft Word or Excel files.

Polina Lisovskaya

I works as a marketing manager for years now and loves searching for interesting topics for you

Recent Posts

Remove Thi-tl-310-a.buzz Pop-up Ads

About Thi-tl-310-a.buzz Thi-tl-310-a.buzz pop-ups can not expose out of the blue. If you have clicked…

1 day ago

Remove Toreffirmading.com Pop-up Ads

About Toreffirmading.com Toreffirmading.com pop-ups can not open out of the blue. If you have clicked…

1 day ago

Remove News-xboveho.site Pop-up Ads

About News-xboveho.site News-xboveho.site pop-ups can not introduce out of the blue. If you have actually…

1 day ago

Remove Glayingly.com Pop-up Ads

About Glayingly.com Glayingly.com pop-ups can not open out of the blue. If you have clicked…

1 day ago

Remove News-xcexive.live Pop-up Ads

About News-xcexive.live News-xcexive.live pop-ups can not expose out of nowhere. If you have clicked some…

1 day ago

Remove News-xcabufe.info Pop-up Ads

About News-xcabufe.info News-xcabufe.info pop-ups can not expose out of the blue. If you have actually…

1 day ago