A malware known as TrickBot has been infecting victims since 2016. It’s still very powerful – in fact, many in the cybersecurity world consider it the top threat targeting businesses right now. Experts believe TrickBot may have used 250 million email accounts so far.

Researchers at DeepInstinct have been monitoring TrickBot activity. In recent years, they have seen the malware evolve and add new capabilities that make it even more dangerous.
One of these additions is something DeepInstinct refers to as TrickBooster. Its job: to send spam emails in order to increase the spread of TrickBot.
At its core, TrickBot is a banking Trojan. The malware is typically distributed via email (spearphishing) – such as fake resumes sent to HR departments or invoices sent to accounts staff. These are usually attached to Microsoft Word or Excel.
TrickBot can spread through several ways. One way is by exploiting vulnerabilities in SMB, a protocol that allows Windows to easily share and access files and folders on other systems on the same network.
Malware spread via SMB can spread quickly in an organization where hardware and software tend to be fairly homogeneous. This uniformity tends to lead to a large number of computers being vulnerable to the same exploits, which makes it much easier for malware like TrickBot to spread.
“Plan B”
TrickBooster gives TrickBot a second highly effective way to spread its “infection.” By sending emails from trusted addresses within an organization, TrickBot increases the chances that a victim will open one of its attachments.
It seems to be working, too. The company's researchers discovered a total of 250 million email addresses that had been compromised by the TrickBot campaign.
DeepInstinct reported that these addresses do not appear to be from previous known breaches. They appear to be a new batch.
Among them, more than 25 million come from Gmail, 21 million from Yahoo, and 11 million from Hotmail. Another 10 million belong to AOL and MSN users. DeepInstinct also identified many addresses belonging to government employees.
The US -based accounts included in the TrickBot network include personnel from the Department of Justice, the Department of State, Homeland Security, the Postal Service, as well as the FAA, ATF, IRS and NASA . Email accounts belonging to Canadian and British organizations were also found in the database.
