New TrickBot Variant Targets Verizon, T-Mobile, and Sprint Users

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,154
A new Trickbot Trojan variant was spotted while focusing on stealing PIN codes from Verizon Wireless, T-Mobile, and Sprint users, marking a new step in this malware's development.

Secureworks Counter Threat Unit (CTU) researchers were the ones who spotted this new TrickBot version during August 2019 after discovering new dynamic webinjects targeting U.S. mobile users' information.

New modules were added to target Verizon Wireless users on August 5, T-Mobile customers on August 12, and Sprint clients on August 19.

The webinjects allow the threat group behind the TrickBot botnet — dubbed GOLD BLACKBURN by Secureworks — to inject additional code within its victims' websites via web sessions manipulation.

"When a victim navigates to the website of one of these organizations, the legitimate server response is intercepted by TrickBot and proxied through a command and control (C2) server," explain the researchers.
Read more below:
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top