Just a few months after being taken down by a group of cybersecurity companies , the Trickbot malware has resurfaced.

Starting out as a banking trojan, Trickbot evolved into a very popular form of malware among cybercriminals, due to its unique nature, which allowed it to be used in many different types of attacks.
These include stealing login credentials and the ability to propagate them across the network, further spreading the infection.
Trickbot was even used as a loader for other forms of malware, with cybercriminals exploiting machines already compromised by Trickbot as a means of delivering other malicious payloads.
Last October, a Microsoft-led operation managed to disrupt the infrastructure behind the Trickbot botnet malware. But it now appears to have resurfaced, as researchers at Menlo Security have identified malware that bears the hallmarks of previous Trickbot activity.
These attacks appear to be targeting exclusively legal and insurance companies in North America, via phishing emails. The emails encourage potential victims to click on a link that then redirects them to a server that downloads a malicious payload.
Many of these emails claim that the user has been involved in a breach and direct them to download “proof” of the breach. This is a social engineering, designed to scare the victim into clicking. In this case, the download is a zip file containing a malicious Javascript, which connects to a server to download the final malware payload.

According to the analysis, the payload is linked to the malicious software Trickbot, indicating that it is active again and could pose a threat to corporate networks.
"Where there's a will, there's a way. That adage certainly applies to the malicious actors behind Trickbot's operations," said Vinay Pidathala, director of security research at Menlo Security.
An update on Trickbot from the UK's National Cyber Security Centre (NCSC) recommends that organisations use the latest supported versions of operating systems and software and apply security patches to stop Trickbot or other malware that exploits known vulnerabilities from spreading.
It is also recommended that organizations implement two-factor authentication over the network, so that in the event that a computer is compromised by malware it is much harder to spread.
