{"id":2909,"date":"2021-05-31T22:13:04","date_gmt":"2021-06-01T03:13:04","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2909"},"modified":"2021-05-31T22:13:04","modified_gmt":"2021-06-01T03:13:04","slug":"trickbot-malware-that-steals-banking-credentials","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/","title":{"rendered":"Trickbot malware that steals banking credentials"},"content":{"rendered":"\n<p>TrickBot is a type of Trojan banking malware designed to steal financial information from users by infecting computers. Many of its features were inspired by another banking Trojan called Dyreza. In fact, TrickBot was one of the first malicious programs that was able to steal data from Bitcoin wallets.<\/p>\n\n\n\n<p>The numerous tricks this Trojan has performed since its discovery in 2016 are attributed to the creativity and agility of its developers. In addition to stealing, TrickBot has been given capabilities to move laterally and entrench itself within an affected network using exploits, spread copies of itself via Server Message Block (SMB) shares, remove other malware such as Ryuk ransomware, and search documents and media. files on infected host machines.<\/p>\n\n\n\n<p>This threat has an email-based propagation module known as TrickBooster, which is executed once the threat is installed on the computer, sending emails from the compromised accounts and then deleting the messages sent from both the outbox and from sent item folders to avoid detection. Furthermore, it is commonly distributed in Spear Phishing attacks and can also exploit vulnerabilities in the Windows SMB protocol to spread rapidly to other computers within the local network.<\/p>\n\n\n\n<p>TrickBot uses a modular approach to allow attackers to quickly add functionality to the base Trojan as needed once a machine is infected. Attackers take advantage of the modules to add a variety of functionality and new attack vectors. The modules are downloaded from a Command and Control (C2) server to the infected machine in the form of DLL files and a configuration file. These C2 servers are generally hosted on hijacked routers and are constantly changing as updated lists of C2 servers are sent to TrickBot infected machines, making it difficult to use IP blocking rules and other mitigation techniques.<\/p>\n\n\n\n<p>TrickBot&#8217;s modular framework enables custom payloads that meet the specific requirements of an attack. This makes this threat a dangerous and adaptable tool for attackers, but at the same time it remains relatively stealthy because unnecessary modules are not included. This threat is evolving very quickly due to its modules which add functionality and flexibility to the malware.<\/p>\n\n\n\n<p>Related reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/bizarro-dangerous-new-banking-trojan\/\">Bizarro dangerous new banking Trojan<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/dridex-is-a-malware-that-targets-banking-credentials\/\">Dridex is a malware that targets banking credentials<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>TrickBot is a type of Trojan banking malware designed to steal financial information from users by infecting computers. Many of its features were inspired by another banking Trojan called Dyreza. In fact, TrickBot was one of the first malicious programs that was able to steal data from Bitcoin wallets. The numerous tricks this Trojan has [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2910,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2909","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Trickbot malware that steals banking credentials - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Cybercriminals are always after your bank information or at least the most, today we will see, Trickbot which targets bank credentials......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Trickbot malware that steals banking credentials - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Cybercriminals are always after your bank information or at least the most, today we will see, Trickbot which targets bank credentials......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-01T03:13:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Trickbot.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"667\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Trickbot malware that steals banking credentials\",\"datePublished\":\"2021-06-01T03:13:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/\"},\"wordCount\":373,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Trickbot.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/\",\"name\":\"Trickbot malware that steals banking credentials - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Trickbot.jpg\",\"datePublished\":\"2021-06-01T03:13:04+00:00\",\"description\":\"Cybercriminals are always after your bank information or at least the most, today we will see, Trickbot which targets bank credentials......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Trickbot.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Trickbot.jpg\",\"width\":1000,\"height\":667},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/trickbot-malware-that-steals-banking-credentials\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trickbot malware that steals banking credentials\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Trickbot malware that steals banking credentials - Truxgo Server Blog","description":"Cybercriminals are always after your bank information or at least the most, today we will see, Trickbot which targets bank credentials......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/","og_locale":"es_MX","og_type":"article","og_title":"Trickbot malware that steals banking credentials - Truxgo Server Blog","og_description":"Cybercriminals are always after your bank information or at least the most, today we will see, Trickbot which targets bank credentials......","og_url":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-06-01T03:13:04+00:00","og_image":[{"width":1000,"height":667,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Trickbot.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Trickbot malware that steals banking credentials","datePublished":"2021-06-01T03:13:04+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/"},"wordCount":373,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Trickbot.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/","url":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/","name":"Trickbot malware that steals banking credentials - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Trickbot.jpg","datePublished":"2021-06-01T03:13:04+00:00","description":"Cybercriminals are always after your bank information or at least the most, today we will see, Trickbot which targets bank credentials......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Trickbot.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Trickbot.jpg","width":1000,"height":667},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Trickbot malware that steals banking credentials"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2909","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2909"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2909\/revisions"}],"predecessor-version":[{"id":2927,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2909\/revisions\/2927"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2910"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2909"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2909"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2909"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}