TrickBot turns 100: Latest malware released with new features

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,143
The TrickBot cybercrime gang has released the hundredth version of the TrickBot malware with additional features to evade detection. [...]

This latest build was discovered by Advanced Intel's Vitali Kremez, who found that they added new features to make it harder to detect.
With this release, TrickBot is now injecting its DLL into the legitimate Windows wermgr.exe (Windows Problem Reporting) executable directly from memory using code from the 'MemoryModule' project.
 

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,143
Just to inform people who don't know what's the legitimate process "wermgr.exe" (Windows Problem Reporting), this system process is signed by Microsoft.
Windows Error Reporting is a crash reporting manager for Windows operating systems. Wermgr.exe runs the error reporting software, and does not pose a threat to your computer.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top