New Trickbot Malware Component Performs Local Network Reconnaissance | Cyware Alerts – Hacker News

New Trickbot Malware Component Performs Local Network Reconnaissance | Cyware Alerts - Hacker News
Trickbot malware was one of the most prolific malware in 2020, gaining popularity for several malicious operations related to COVID-19 lures. After several ups and downs during a takedown effort in October 2020, Trickbot recently introduced a new module to scan local network systems with open ports for quick lateral movement.

Diving into details

The latest component named masrv was first compiled on December 4, 2020, and it is still under testing. So far researchers have been only able to encounter one variant of this module.

The invincible Trickbot

Trickbot has become the primary de-facto threat to corporate environments after surviving the takedown attempt.
The additional module for the local network reconnaissance demonstrates the forthcoming plans of the Trickbot malware operators. The threat actors are eager to infect more systems with sophisticated tricks for future attacks.

This content was originally published here.

Laat een reactie achter

Het e-mailadres wordt niet gepubliceerd.