New TrickBot tool targets telecommunications in U.S., Hong Kong
Full article701 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Researchers tell CyberScoop that the module is being used for espionage: "It's not random."
The criminals behind the TrickBot banking trojan have retooled it for targeting telecommunications organizations in the U.S. and Hong Kong, according to new research from BitDefender.
The new module, a malicious .dll file “rdpScanDll” allow attackers to run brute-forcing operations against Remote Desktop Protocols (RDPs).
It’s just the latest update to TrickBot, which by design is built to be enhanced over time. The developers behind the banking trojan have not rested since it first sprouted up in 2016, and just earlier this year started using a new backdoor, according to SentinelOne research. BitDefender first saw a version of the module being developed in August of last year, Liviu Arsene, a global cybersecurity researcher at BitDefender, told CyberScoop.
The multiple configurations TrickBot can take on will likely continue to be attractive for criminals’ and nation-states’ interests as they perpetually try to retool and maintain anonymity, according to Arsene.
“That’s the beauty of everything you do with TrickBot,” Arsene told CyberScoop. “Attackers could be using existing infrastructure for malware that has already been in the wild for years, tested and proven to be reliable. Attackers are going to be using this infrastructure to perform more targeted attacks.”
While BitDefender found IP addresses on several targeting lists that also look to be from the education and financial sectors, Arsene said the telecommunications addresses — the bulk of the targets — shows the use of the new TrickBot module is believed to be for espionage purposes.
“It targets a very specific list of IP address in a very narrow vertical, telecommunications,” Arsene, said. “It’s not random.”
Constantly improving
Since the new module popped up, developers have been updating and tweaking the scheme, sometimes as much as two or three times in one week, Arsene said.
The new plug-in’s three operations — “check,” “trybrute,” and “brute” — have varying levels of success. During “check,” TrickBot checks for RDP connections on the list of targets and checks the IP list the attackers have made. During “trybrute,” the attackers try to perform a brute-force operation on the list of targeted IPs.
But the “brute” mode is less functional and may be updated yet, BitDefender found. For now, “brute” does not consult a username list to run attacks, and instead relies on just null passwords and usernames.
While the attackers’ command and control infrastructure is primarily based in Russia, according to Arsene, it’s unclear who exactly the attackers are.
The telecommunications sector is a perennial target for hackers around the world, especially, as of late, for Chinese government-linked hackers, which have gone after call records data on multiple occasions in recent months, according to FireEye and Cybereason.
“Attribution is difficult,” Arsene said. “The module itself doesn’t leave behind forensic artifacts that can point to a specific region or someone who is talking a specific language or using Chinese or Cyrilic characters.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/trickbot-telecommunications-rdp-bitdefender/