Trickbot steals credentials and recently released ransomware. ESET Research contributed to the success of the operations with technical analysis
ESET researchers participated in an operation to counter the Trickbot botnet, which has infected over one million computing devices since 2016. In collaboration with Microsoft, Lumen's Black Lotus Labs Threat Research, NTT and other vendors, the operation stopped Trickbot by identifying the command and control servers. ESET contributed to the result with statistical and technical analyzes on the domain names and IPs of the Command & Control servers. The Trickbot malware is known for stealing credentials from hacked computers and has more recently been observed being used as a delivery vehicle for more malicious, ransomware-type attacks.
ESET Research has been monitoring Trickbot since it was first discovered in late 2016. In 2020 alone, ESET's botnet tracking platform analyzed more than 125,000 pieces of malicious code and downloaded and decrypted more than 40,000 configuration files used by different Trickbot modules, providing a powerful vantage point into the different C&C servers used by this botnet.
"Over the years, we have consistently monitored and reported Trickbot's activities, making it one of the largest and longest-running botnets in existence. Trickbot is one of the most widespread banking malware, and this strain poses a threat to internet users globally," he points out. Jean-Ian Boutin, Head of Threat Research di ESET.
Throughout its existence this malware has been spread in different ways. Recently, a chain where Trickbot is left on systems already compromised by Emotet, another botnet, has been observed more frequently. In the past, Trickbot malware was mostly used as a banking Trojan to steal credentials from online accounts with the aim of making fraudulent money transfers.
One of the older plugins developed for the platform allows Trickbot to use Web injects, a technique that allows malware to dynamically change what the user of a compromised system sees when visiting specific websites. "With our monitoring of Trickbot campaigns we have collected tens of thousands of different configuration files, and this has allowed us to identify the websites targeted by Trickbot operators. The URLs involved mostly belong to banking institutions," adds Boutin.
“Trying to stop this insidious threat is very challenging because it has various fallback mechanisms and its interconnection with other very active cyber threats makes the operation extremely difficult,” concludes ESET's Boutin.
More technical information on Trickbot is available in the post "ESET participates in a worldwide operation to stop Trickbot" his WeLiveSecurity.






