HomeSecurityTrickBot: New feature allows SIM swapping attacks!

TrickBot: New feature allows SIM swapping attacks!

The TrickBot trojan is one of the most active and widespread malware. According to researchers, hackers have improved the trojan to be able to carry out “ SIM swapping attacks .”TrickBot

The new version of TrickBot can steal login credentials and PINs for Sprint, T-Mobile, and Verizon Wireless accounts

TrickBot collects datathat enables hackers to carry out a SIM swapping attack, i.e. transfer a victim's phone number to a SIM card they control.

Through this attack, hackers can bypass SMS-based multi-factor authentication solutions and proceed to reset the passwords of victims' bank accounts, email accounts , or cryptocurrency exchange portals.

In the last two years, SIM swapping attacks have become very popular. They are mainly used to steal money.

TrickBot was originally used as a banking trojan but evolved into an Access-as-a-Service model. This means that other hackers can deploy malware on computers previously infected with TrickBot.

This automatically creates a collaboration between the team behind TrickBot and other criminal groups. This is very worrying because they could join forces to carry out larger attacks. For example, the operators of TrickBot could give other hackers the data they collect, so that they can exploit it in other ways.

How can you tell if you have become a victim of TrickBot?

It's hard to tell if you've been affected by malware unlessyou're using a top-notch antivirus program. However, there are some things that can help you figure out if something strange is going on.

TrickBot uses a technique known as “web injects.” Essentially, it enters legitimate sites that a user visits and installs malicious content.

According to researchers, TrickBot began affecting the Verizon Wireless login page on August 5, when it added two new fields for users' PIN code in Verizon's login form.

Verizon does not typically ask for this PIN on its website, so TrickBot was able to steal the credentials and PIN of users who logged in this way.

TrickBot: New feature allows SIM swapping attacks!

The attacks on T-Mobile and Sprint took place on August 12 and August 19 respectively. In these attacks the hackers followed a different procedure.

They did not add the PIN field to the regular login form, but to a separate page that appeared after the successful login, as shown below.

TrickBot: New feature allows SIM swapping attacks!

If Sprint, T-Mobile, and Verizon Wireless users have seen these pages, then likely computers been infected with TrickBot.

If this has happened, they should take care of the «cleaning» of their computer as well as the change of the credentials and the PIN codes.

The operators of TrickBot have proven that they are ruthless and that they constantly find new ways to evolve the malicious software, such as now that they have given it the ability to carry out SIM swapping attacks. Therefore, we must be very careful!

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS