Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Malware

Trickbot (Banking Trojan) – Malware

June 30, 2023
Reading Time: 3 mins read
in Malware, Types of Malware
Name Trickbot
Type of Malware Banking Trojan
Associated Groups Wizard Spider, TA505
Date of Initial Activity 2016
Motivation Targets businesses and consumers for their data, perform lateral movement and reconnaissance on a targeted organization , delivering targeted ransomware attack
Attack Vectors Spearphishing campaigns, spam campaigns or other malware families such as Emotet and BazarLoader
Targeted System Windows

Overview

Trickbot is a modular banking Trojan, attributed to the WizardSpider cybercrime gang. Mostly delivered via spam campaigns or other malware families such as Emotet and BazarLoader. Trickbot sends information about the infected system and can also download and execute arbitrary modules from a large array of available modules, including a VNC module for remote control and an SMB module for spreading within a compromised network.

TrickBot has the reputation of being the successor of Dyreza, another credential stealer that first appeared in the wild in 2014.

Targets

Initially banking sites, all sectors later. Also private individuals.

Tools/ Techniques Used

TrickBot is an advanced Trojan that malicious actors spread primarily by spearphishing campaigns using tailored emails that contain malicious attachments or links, which—if enabled—execute malware. The phishing emails contain links that redirect to a website hosted on a compromised server. Once downloaded to the infected device, the user is prompted to enable macros, which installs the TrickBot binary.

The malware then uses various models to infect the network and steal data. To set the stage for future attacks, the TrickBot operators may also attempt to disable antivirus protection. As part of a secondary attack, TrickBot can spread the malware laterally throughout the network, usually by exploiting a Server Message Block (SMB) vulnerability.

A follow-on attack, such as a Ryuk ransomware attack, is deployed by the TrickBot group. The attackers manually delete or encrypt backup files and twins. Ryuk encrypts all system data and initiates the ransomware attack path.

References

  1. WHAT IS TRICKBOT MALWARE?
  2. TrickBot: Not Your Average Hat Trick – A Malware with Multiple Hats
  3. Advisory: Trickbot
  4. TrickBot
  5. TrickBot Malware
  6. What is TrickBot malware?
Tags: Banking TrojanBazarLoaderCyberattackCybersecurityEmotetMalwaremalware namePhishingPhishing Emailsspam campaignsSpearphishing campaignsTrickbotVulnerabilities
ADVERTISEMENT

Related Posts

Iranian Phishing Campaign (Scam) – Malware

Iranian Phishing Campaign (Scam) – Malware

March 2, 2025
Fake WalletConnect (Infostealer) – Malware

Fake WalletConnect (Infostealer) – Malware

March 2, 2025
SilentSelfie (Infostealer) – Malware

SilentSelfie (Infostealer) – Malware

March 2, 2025
Sniper Dz (Scam) – Malware

Sniper Dz (Scam) – Malware

March 2, 2025
TikTok Malware Scam (Trojan) – Malware

TikTok Malware Scam (Trojan) – Malware

March 2, 2025
Zombinder (Exploit Kit) – Malware

Zombinder (Exploit Kit) – Malware

March 2, 2025

Latest Alerts

Microsoft Defender Bug Allows SYSTEM Access

Uncanny Automator Bug Risks WordPress Sites

Devs Hit By PyPI Solana Token Secret Theft

Hackers Exploit Output Messenger Zero-Day

ASUS Fixes Critical Flaws in DriverHub

Apple Fixes Critical Bugs in iOS and MacOS

Subscribe to our newsletter

    Latest Incidents

    Alabama Cybersecurity Event Hits Services

    Andy Frain Data Breach Impacts 100k People

    Hong Kong DSC Hit By Ransomware Attack

    Alleged Steam Breach Exposes 89M Records

    Ulhasnagar Municipal Corporation Hacked

    Madison County Iowa Systems Disrupted

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial