Security researchers have identified a new module of the Trickbot malware that can identify local networks . The new module, called masrv , incorporates a copy of the open-source utility Masscan to scan local networks for other systems with open ports that it can then attack at a later stage.

What masrv essentially does is place the component on newly infected devices , send a series of Masscan commands, let the component scan the local network, and upload the scan results to a Trickbot command and control server
If the scan finds systems with sensitive ports or management ports open within an internal network, the Trickbot gang can then deploy other units specialized in exploiting these gaps and move laterally to infect new systems.
"It's not generally innovative – but it's strange to include it in Trickbot," Suweera DeSouza , a malware analyst at Kryptos Logic and the discoverer of masrv, told ZDNet
DeSouza said she believes the new module is still being tested, something Trickbot has done in the past with other modules, which often ended up being added to the malware's large arsenal of components.
“We only found one variation of this module,” DeSouza said.
“The most recent module that was compiled was on December 4, 2020. We have not encountered the functional module again since then.”

A technical analysis on the new Masrv Trickbot module, written by DeSouza and her colleagues, is available on the Kryptos Logic blog
Other malware strains have also been known to include network recognition modules in the past, but such modules are not common.
After law enforcement agencies managed to take down the Emotet malware botnet last week, Trickbot is now considered the main de-facto threat to corporate environments.
Trickbot also survived a takedown attempt last fall. After many ups and downs, the botnet was revived in late January.
