HomeSecurityTrickBot hackers create new backdoor for VIP targets

TrickBot hackers create new backdoor for VIP targets

The notorious cyberattack group TrickBot has developed a new backdoor to monitor its victims' systems after an exploit attack.

trickbot new backdoor for vip targets

The ultimate goal of the tool after the attack is to “bypass security restrictions and controls to adapt to the new era of cybersecurity and exploit the most protected and secure high-value networks,” SentinelLabs.

TrickBot's cyberattacks specialize in stealing banking credentials worldwide, often from businesses. The trojans associated with the group are constantly evolving, with new modules and tools to stay one step ahead of cybersecurity teams in their aim to extract and preserve data.

In the second half of last year, researchers warned that alongside trojans, backdoors, and web injection applications, developers were expanding their arsenal with tools designed for SIM attacks. The TrickBot malware has also been linked to crypto-based thefts.

The new tool was likely launched via Windows PowerShell, researchers say. A TrickBot module called “NewBCtest” has been modified to accept commands to execute, including creating a larger backdoor during the attack.

SentinelLabs says the method used is similar to the PowerShell called Empire, but to remain hidden, TrickBot chose to design PowerTrick to be “flexible” and to allow for scaling up the attack “on the fly.”

Scans are performed to log the infected system and the information is returned along with a unique user ID, which is sent through the backdoor to a command and control server controlled by the attackers.

PowerTrick also leverages the Metasploit framework and various PowerShell utilities to navigate networked drives and systems in order to deploy additional malware.

“They remove existing files that did not execute properly and move on to a different target of their choice, or perform lateral movement in the environment in high-value systems such as financial trading points,” the team says.

The second scenario concerns businesses. As we have seen with the recent Travelex incident, malware can spread and encrypt – or steal – data in a networked environment and can prove devastating.

TrickBot has also recently been linked to “Anchor,” a set of tools that appears to provide a link between North Korean operators and hacking groups.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS