TrickBot Malware Gets UEFI/BIOS Bootkit Feature to Remain Undetected – Tempemail

TrickBot, one of the most notorious and adaptable malware botnets in the world, is expanding its toolset to set its sights on firmware vulnerabilities to potentially deploy bootkits and take complete control of an infected system. The new functionality, dubbed “TrickBoot” by Advanced Intelligence (AdvIntel) and Eclypsium, makes use of Continue Reading

TrickBot Linux Variants Active in the Wild Despite Recent Takedown – Tempemail

Efforts to disrupt TrickBot may have shut down most of its critical infrastructure, but the operators behind the notorious malware aren’t sitting idle. According to new findings shared by cybersecurity firm Netscout, TrickBot’s authors have moved portions of their code to Linux in an attempt to widen the scope of Continue Reading

Microsoft and Other Tech Companies Take Down TrickBot Botnet – Tempemail

Days after the US Government took steps to disrupt the notorious TrickBot botnet, a group of cybersecurity and tech companies has detailed a separate coordinated effort to take down the malware’s back-end infrastructure. The joint collaboration, which involved Microsoft’s Digital Crimes Unit, Lumen’s Black Lotus Labs, ESET, Financial Services Information Continue Reading

TrickBot Mobile App Bypasses 2‐Factor Authentication for Net Banking Services – Tempemail

The malware authors behind TrickBot banking Trojan have developed a new Android app that can intercept one-time authorization codes sent to Internet banking customers via SMS or relatively more secure push notifications, and complete fraudulent transactions. The Android app, called “TrickMo” by IBM X-Force researchers, is under active development and Continue Reading

TrickBot Now Exploits Infected PCs to Launch RDP Brute Force Attacks – Tempemail

A new module for TrickBot banking Trojan has recently been discovered in the wild that lets attackers leverage compromised systems to launch brute-force attacks against selected Windows systems running a Remote Desktop Protocol (RDP) connection exposed to the Internet. The module, dubbed “rdpScanDll,” was discovered on January 30 and is Continue Reading