HomeSecurityTrickBot: Exploits infected PCs to launch RDP brute-force attacks

TrickBot: Exploits infected PCs to launch RDP brute-force attacks

A new module for the TrickBot banking Trojan was recently discovered that allows attackers to exploit compromised systems to launch brute-force attacks against selected Windows systems running an RDP (Remote Desktop Protocol) connection exposed to the Internet.

The module, dubbed “rdpScanDll,” was discovered on January 30 and is said to still be in the environment, Bitdefender said in a report published in The Hacker.

According to the researchers, the rdpScanDll brute-forcing module has so far attempted to target 6,013 RDP servers belonging to enterprises in the telecommunications, education, and financial sectors in the US and Hong Kong.

The creators of the TrickBot malware specialize in releasing new modules and versions of the Trojan in an effort to expand and improve its capabilities.

"The flexibility allowed by the module design has turned TrickBot into a very complex and sophisticated malware capable of a wide range of malicious activities," the researchers said.

“From plugins to hide sensitive OpenSSH and OpenVPN data, to modules that perform SIM to take control of phone number , and even disable built-in Windows before the main modules are downloaded, TrickBot is fully featured.”

Bazar backdoor-Trickbot-trojan-campaigns

How does TrickBot RDP Brute-Force Module work?

When TrickBot starts executing, it creates a folder containing the encrypted payload and associated configuration files, which include a list of command-and-control (C2) servers that the plugin to retrieve the commands to be executed.

According to Bitdefender, the rdpScanDll plugin shares its configuration file with another module called “vncDll”, while also using a standard URL to communicate with the new C2 servers.

While the “check” function checks for an RDP connection from the list of targets, the “trybrute” function attempts a brute force operation on the selected target using a predefined list of usernames and passwords taken from the endpoints “/rdp/names” and “/rdp/dict” respectively.

The “brute mode,” according to the researchers, appears to be still in development. Not only does it include a set of executable functions that are not called, but the mode “does not retrieve the user list, causing the plugin to use null passwords and usernames to authenticate against the target list.”

Once the initial list of targeted IPs gathered via “/rdp/domains” is exhausted, then the plugin retrieves another set of new IPs using a second endpoint “/rdp/over”.

The two lists, comprising 49 and 5,964 IP addresses, included targets located in the US and Hong Kong and covering telecommunications, education, finance and scientific research.

A story of evolving possibilities

Spread via email phishing campaigns, TrickBot began life as a banking Trojan in 2016, facilitating financial theft. It has since evolved to deliver other types of malware, including the infamous Ryuk ransomware, act as an information stealer, hack Bitcoin wallets, and harvest emails and credentials.

The malspam campaigns that deliver TrickBot use branding that the recipient may be familiar with, such as invoices from accounting and finance companies.

The emails typically include an attachment, such as a Microsoft Word or Excel document, which, when opened, will prompt the user to enable macros – thus executing a VBScript to execute a PowerShell script to download the malware.

TrickBot is also dropped as a secondary payload by other malware, most notably the Emotet botnet-based spam campaign. To be persistent and evade detection, the malware has been found to create a scheduled task and service and even disable and delete Windows Defender antivirus.

This led Microsoft to develop a Tamper Protection feature to protect against malicious and unauthorized changes to security features last year.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS