
FBI and CISA are warning about a new spear-phishing campaign that attempts to infect victims' computers with one of the most well-known malware, Trickbot.
See also: Trickbot: New module uses Masscan for local network identification
Trickbot started as a simple banking trojan, but has now evolved into one of the most powerful tools used by cybercriminals. Typically, hackers infect systems with Trickbot to gain access to machines and deliver other malware, including various ransomware variants.

According to a joint report by the FBI and CISA, the creators of Trickbot are now using a new tactic to deliver it to victims’ systems. They send phishing emails with the subject line “proof of a traffic violation.” The criminals hope that the victim will be scared and open the email to learn more.
Useful information: Phishing attacks: What are they and how do hackers usually attack?
The malicious emails contain a link that takes users to a website hosted on a server that has been compromised by the attackers. The site tells the victim to click on a photo to see the proof. If the victim clicks on the photo, it will download a JavaScript file, which when opened, connects to a command and control server that downloads Trickbot to their system.
Trickbot creates a backdoor on Windows computers, which allows attackers to steal sensitive information. In fact, some versions of Trickbot can spread to entire networks.
Trickbot's modular nature makes it highly adaptable and allows it to infect the system with additional malware (e.g. Ryuk or Conti ransomware). It is also often used to install the Emotet malware, and can exploit infected machines for cryptomining.
See also: Microsoft: "Don't relax your defenses. Emotet may return"
Security companies tried to shut down Trickbot in October last year, but a few months later, criminals started using it again.
“The takedown efforts in October were unlikely to permanently disable this highly capable malware that has been active in the threat landscape for years. It has a robust infrastructure and so can continue to operate,” said Sherrod DeGrippo, senior research executive at Proofpoint.
“Completely removing Trickbot from the threat landscape would be extremely difficult and would likely require a coordinated international effort. In fact, following the actions of October 2020, we saw Trickbot campaigns resume within a few weeks,” he added.

Trickbot remains a powerful tool for criminals and poses one of the biggest risks to businesses and organizations of all sizes.
However, the FBI and CISA offer some advice to protect organizations from Trickbot and other malware.
Training employees to recognize phishing emails is one of the most basic steps.
Also, regularly updating systems and applications prevents criminals from exploiting potential vulnerabilities.
Source: ZDNet
