
It seems that the creators of the infamous Trickbot Trojancontinue to evolve their malware, adding a new custom component derived from the BokBot code, which is used in web injection attacks and affects popular browsers.
BokBot, also known as IcedID, was first discovered by IBM's X-Force team in late 2017 and is also a banking trojan. It has the ability to redirect its victims to fake online banking websites, but also to attach itself to a browser and promote fake content on banking homepages.
Security researcher Brad Duncan recently saw Trickbot, which contains the new web injection component, being downloaded by the Ursnif (aka Gozi ISFB) malware.
The attack begins with a malicious Office Word file, which runs a PowerShell script to download the Ursnif trojan. The infected device also receives a variant of Trickbot containing the BokBot/IcedID component, which can monitor and modify web data flow.
A system infected with the new Trickbot variant was discovered on July 5th and contains its own configuration file.
Another security researcher, who also studied the new Trojan component, Vitali Kremez, found that it can attach to Google Chrome, Mozilla Firefox, Internet Explorer , and Microsoft Edge browsers .

Upon further analysis, their similarity to BokBot's man-in-the-browser tool, which is used to push fake data into the results the victim receives, was discovered.
In a Twitter thread , Kremez notes that the interesting part is that this component appears to be tailored specifically for TrickBot or other fraudulent banking transactions that rely on the installer of this malware family .
The malicious add-on acts as a local proxy server, located between the customer and the online banking service. From there, it can insert a fake profile of the bank the user searched for into the connection and collect financial information.
