
A phishing campaign is currently underway that sends emails to victims asking them to vote anonymously for “Black Lives Matter .” The purpose of the phishing emails is to distribute TrickBot malware .
TrickBot started as a banking Trojan, but has now evolved greatly and is used in various businesses to steal information.
The malware can spread across the victim's network and steal stored credentials, Active Directory databases, cookies, OpenSSH keys, RDP, VNC, PuTTY credentials, and more.
TrickBot is often used in conjunction with other malware, especially ransomware. It is used primarily to gain access to a compromised network for ransomware deployment.
Exploitation of the “Black Lives Matter” movement for phishing and distribution of TrickBot
A common tactic of hackers is to use important current events as bait to trick people into opening phishing emails.
This tactic is being followed in this phishing campaign, discovered by security firm Abuse.ch. The phishing emails claim to come from the “Country Administration” and ask recipients to “Vote anonymously for Black Lives Matter.”
The email below says: “Leave a review, confidentially, for “Black Lives Matter,” and then asks recipients to fill out an attached document named “e-vote_form_3438.doc” and send it back.

When victims open the Word document, they will see a message saying that they need to click “Enable Editing” and “Enable Content” to view the contents properly.

If they click on the above, the Word document will execute macros, which will download a malicious DLL to the computer.
This DLL is the TrickBot trojan which, when executed, will start stealing files, passwords, security , etc. It will also spread throughout the network and may allow other criminals to install ransomware.
TrickBot is very dangerous. Therefore, we should all be extremely careful with the emails we receive, especially those that are politically or socially motivated, as they may be malware.
