Site navigation

Trickbot Malware has Infected 60 Major Global Firms Since 2020

David Paul

,

Trickbot malware
Companies including Microsoft, Amazon and Barlcays Bank have all been the target of malicious attacks to steal private info. Have you been affected?

Sophisticated Trickbot malware has infected over 140,000 machines of customers from 60 major corporations world-wide, according to Check Point Research (CPR).

The malware has been operating since November 2020, selectively going after high-profile targets to steal and compromise sensitive data.

Additionally, Trickbot’s infrastructure is being used by various malware families to cause more damage on infected machines.

CPR has urged the public to only open documents from trusted sources, as Trickbot’s authors are leveraging anti-analysis and anti-obfuscation techniques to persist on machines.

Researchers have said that customers from global corporations, including Amazon, Microsoft and JP Morgan Chase, will likely have been infected by Trickbot.

It was discovered that the most infected regions are APAC, Latin America, Europe, Africa, North America.

Cyber Security, Research and Innovation Manager at Check Point Software Technologies Alexander Chailytko commented: “Trickbot’s numbers have been staggering. We’ve documented over 140,000 machines targeting the customers of some of the biggest and most reputable companies in the world.

“We went onto observe that the Trickbot authors have the skills to approach malware development from a very low-level and pay attention to small details. Trickbot attacks high-profile victims to steal the credentials and provide its operators access to the portals with sensitive data where they can cause even more damage.

“At the same time, we know that the operators behind the infrastructure are very experienced with malware development on a high-level as well.”

Chailytko added: “The combination of these two factors is what allows Trickbot to remain a dangerous threat for more than five years already.

“I strongly urge people to only open documents from trusted sources and to use different passwords on different web-sites.”


Recommended


CPR released further details of the implementation of the well-known Trojan.

Threat actors receive a database of stolen emails and send malicious documents to the chosen addresses. Once sent, users download and open the document, allowing macro execution in the process.

Once downloaded, the main Trickbot payload is executed and establishes itself on the infected machine. Auxiliary malware modules can be uploaded to the infected machine on demand by the threat actors.

CPR said that the malware may be spreading via compromised corporate network, stealing credentials as well as grabbing login details to banking sites.

To combat the effects of the malware, researchers suggested that users only open documents received from trusted sources, and to not enable macro execution inside the documents.

Additionally, CPR said users should ensure they have the latest operating system and anti-virus updates up and running and use different passwords on different websites.


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

David Paul

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data