• CERTIFICATE
    • Eminent VARs of India
    • Best OEM 2023
  • SYNDICATION
    • AMD
    • DELL TECHNOLOGIES
    • HITACHI
    • LOGMEIN
    • MICROSOFT
    • RIVERBED
    • STORAGECRAFT
    • THALES
  • EVENTS
  • GO DIGITAL
  • INFOGRAPHICS
  • PRESS
    • Press Release PR News Wire
    • Press Release Business Wire
    • GlobeNewsWire
  • SPECIAL
    • WHITE PAPER
    • TECHNOMANIA
    • SME
    • SMART CITY
    • SERVICES
    • EDITOR SPEAK
    • CSR INITIATIVES
    • CHANNEL GURU
    • CHANNEL CHIEF
    • CASE STUDY
  • TECHTREND
    • VAR PANCHAYAT
    • TELECOM
    • SOFTWARE
    • POWER
    • PERIPHERALS
    • NETWORKING
    • LTE
    • CHANNEL BUZZ
    • ASK AN EXPERT
  • SUBSCRIBE
  • Apps
  • Gaming
  • KDS
  • Security
  • Telecom
  • WFH
  • Subscriber to Newsletter
  • April Issue
  • Blogs
  • Vlogs
  • Faceoff AI
    

HOME
NEWS

Trickbot Infects 140,000+ Machines of Customers from Amazon, Microsoft, Google and 57 other Corporations World-wide


By VARINDIA - 2022-02-17
Trickbot Infects 140,000+ Machines of Customers from Amazon, Microsoft, Google and 57 other Corporations World-wide

Check Point Research (CPR) discovers sophisticated details of the implementation of Trickbot, learning that the notorious banking trojan has infected over 140,000 machines of customers from Amazon, Microsoft, Google and 57 other corporations world-wide, since November 2020. Trickbot’s authors are selectively going after high-profile targets to steal and compromise their sensitive data. Additional, Trickbot’s infrastructure can be utilized by various malware families to cause more damage on infected machines. CPR urges the public to only open documents from trusted sources, as Trickbots authors are leveraging anti-analysis and anti-obfuscation techniques to persist on machines.

 

  • CPR provides a list of 60 corporations whose customers have been infected by Trickbot
  • Most infected regions in order: APAC, Latin America, Europe, Africa, North America
  • CPR recommends three security and safety tips from Trickbot

 

Check Point Research (CPR) has discovered new and sophisticated details of the implementation of Trickbot. A well-known banking Trojan, Trickbot steals and compromises the data of its victims, targeting high-profile victims. CPR counts over 140,000 machines infected by Trickbot since November 2020, many of which are customers of well-known corporations, such as Amazon, Microsoft, Google and PayPal. In total, CPR documented 60 corporations whose customers have fallen victim to Trickbot throughout the past 14 months.

 

Figure 1. Several companies whose customers are targeted by Trickbot

 

 

 

 

 

 

 

 

 

Key Implementation Details of Trickbot

  • Malware is very selective in how it chooses its targets
  • Various tricks – including anti-analysis and anti-Deobfuscation – implemented inside the modules show the authors’ highly technical background
  • Trickbots infrastructure can be utilized by various malware families to cause more damage on infected machines
  • Sophisticated and versatile malware with more than 20 modules that can be downloaded and executed on demand

 

How Trickbot Works:

  1. Threat actors receive a database of stolen emails and send malicious documents to the chosen addresses
  2. The user downloads and opens such a document, allowing macro execution in the process
  3. The first stage of malware is executed, and the main Trickbot payload is downloaded
  4. The main Trickbot payload is executed and establishes its persistence on the infected machine.
  5. Auxiliary Trickbot modules can be uploaded to the infected machine on demand by the threat actors, the functionality of such modules may vary: it may be spreading via compromised corporate network, stealing corporate credentials, grabbing login details to banking sites, etc.

 

Scope of Impact

Below is a heat-map with the percentage of organizations that were affected by Trickbot in each country according to our data of telemetry:

 

Figure 2. Percentage of impacted organizations by Trickbot (the darker the color – the higher the impact)

 

 

Below is a table that shows the percentage of organizations affected by Trickbot in each region:

Region

Organizations affected

Percentage

World

1 of every 45

2.2%

APAC

1 of every 30

3.3%

Latin America

1 of every 47

2.1%

Europe

1 of every 54

1.9%

Africa

1 of every 57

1.8%

North America

1 of every 69

1.4%

 

Quote: Alexander Chailytko, Cyber Security, Research & Innovation Manager at Check Point Software Technologies,

“Trickbot’s numbers have been staggering. We’ve documented over 140,000 machines targeting the customers of some of the biggest and most reputable companies in the world. We went onto observe that the Trickbot authors have the skills to approach malware development from a very low-level and pay attention to small details. Trickbot attacks high-profile victims to steal the credentials and provide its operators access to the portals with sensitive data where they can cause even more damage. At the same time, we know that the operators behind the infrastructure are very experienced with malware development on a high-level as well. The combination of these two factors is what allows Trickbot to remain a dangerous threat for more than 5 years already. I strongly urge people to only open documents from trusted sources and to use different passwords on different web-sites.”

 

Security Tips

1. Only open documents you receive from trusted sources. Do not enable macro execution inside the documents.
2. Make sure you have the latest operating system and anti-virus updates up and running.
3. Use different passwords on different web-sites.

 

Appendix – The list of targeted companies

Company

Field

Amazon

E-commerce

AmericanExpress

Credit Card Service

AmeriTrade

Financial Services

AOL

Online service provider

Associated Banc-Corp

Bank Holding

BancorpSouth

Bank

Bank of Montreal

Investment Banking

Barclays Bank Delaware

Bank

Blockchain.com

Cryptocurrency Financial Services

Canadian Imperial Bank of Commerce

Financial Services

Capital One

Bank Holding

Card Center Direct

Digital Banking

Centennial Bank

Bank Holding

Chase

Consumer Banking

Citi

Financial Services

Citibank

Digital Banking

Citizens Financial Group

Bank

Coamerica

Financial Services

Columbia Bank

Bank

Desjardins Group

Financial Services

E-Trade

Financial Services

Fidelity

Financial Services

Fifth Third

Bank

FundsXpress

IT Service Management

Google

Technology

GoToMyCard

Financial Services

HawaiiUSA Federal Credit Union

Credit Union

Huntington Bancshares

Bank Holding

Huntington Bank

Bank Holding

Interactive Brokers

Financial Services

JPMorgan Chase

Investment Banking

KeyBank

Bank

LexisNexis

Data mining

M&T Bank

Bank

Microsoft

Technology

Navy Federal

Credit Union

paypal

Financial Technology

PNC Bank

Bank

RBC Bank

Bank

Robinhood

Stock Trading

Royal Bank of Canada

Financial Services

Schwab

Financial Services

Scotiabank Canada

Bank

SunTrust Bank

Bank Holding

Synchrony

Financial Services

Synovus

Financial Services

T. Rowe Price

Investment Management

TD Bank

Bank

TD Commercial Banking

Financial Services

TIAA

Insurance

Truist Financial

Bank Holding

U.S. Bancorp

Bank Holding

UnionBank

Commercial Banking

USAA

Financial Services

Vanguard

Investment Management

Wells Fargo

Financial Services

Yahoo

Technology

ZoomInfo

Software as a service

 

See What’s Next in Tech With the Fast Forward Newsletter

SECURITY
View All
Zscaler announces AI innovations to its Data Protection Platform
Technology

Zscaler announces AI innovations to its Data Protection Platform

by VARINDIA 2024-05-20
SHIELD to enhance Swiggy’s fraud prevention and detection capabilities
Technology

SHIELD to enhance Swiggy’s fraud prevention and detection capabilities

by VARINDIA 2024-05-20
Axis Communications announces its first thermometric camera designed for Zone/Division 2
Technology

Axis Communications announces its first thermometric camera designed for Zone/Division 2

by VARINDIA 2024-05-20
SOFTWARE
View All
Hitachi Vantara and Veeam announce Global Strategic Alliance
Technology

Hitachi Vantara and Veeam announce Global Strategic Alliance

by VARINDIA 2024-05-16
Adobe launches Acrobat AI Assistant for the Enterprise
Technology

Adobe launches Acrobat AI Assistant for the Enterprise

by VARINDIA 2024-05-11
Oracle Database 23ai offers the power of AI to Enterprise Data and Applications
Technology

Oracle Database 23ai offers the power of AI to Enterprise Data and Applications

by VARINDIA 2024-05-10
START - UP
View All
Data Subject Access Request is an integrated module within ID-REDACT®
Technology

Data Subject Access Request is an integrated module within ID-REDACT®

by VARINDIA 2024-04-30
SiMa.ai Secures $70M Funds from Maverick Capital
Technology

SiMa.ai Secures $70M Funds from Maverick Capital

by VARINDIA 2024-04-05
Sarvam AI collaborates with Microsoft to bring its Indic voice LLM to Azure
Technology

Sarvam AI collaborates with Microsoft to bring its Indic voice LLM to Azure

by VARINDIA 2024-02-08

Tweets From @varindiamag

Nothing to see here - yet

When they Tweet, their Tweets will show up here.

CIO - SPEAK
Automation has the potential to greatly improve efficiency and production

Automation has the potential to greatly improve efficiency and production

by VARINDIA
Various approaches are followed to enhance efficiency, productivity, and cost-effectiveness

Various approaches are followed to enhance efficiency, productivity, and cost-effectiveness

by VARINDIA
Technology can be leveraged in several ways to boost efficiency, productivity and reduce cost

Technology can be leveraged in several ways to boost efficiency, productivity and reduce cost

by VARINDIA
Start-Up and Unicorn Ecosystem
GoDaddy harnesses AI power for new domain name recommendations

GoDaddy harnesses AI power for new domain name recommendations

by VARINDIA
UAE’s du Telecom selects STL as a strategic fibre partner

UAE’s du Telecom selects STL as a strategic fibre partner

by VARINDIA
JLR and Dassault Systèmes extend partnership for All Vehicle Programs worldwide

JLR and Dassault Systèmes extend partnership for All Vehicle Programs worldwide

by VARINDIA
Rapyder partners with AWS to accelerate Generative AI led innovation

Rapyder partners with AWS to accelerate Generative AI led innovation

by VARINDIA
ManageEngine integrates its SIEM solution with Constella Intelligence

ManageEngine integrates its SIEM solution with Constella Intelligence

by VARINDIA
Elastic replaces traditional SIEM game with AI-driven security analytics

Elastic replaces traditional SIEM game with AI-driven security analytics

by VARINDIA
Infosys and ServiceNow to transform customer experiences with generative AI-powered solutions

Infosys and ServiceNow to transform customer experiences with generative AI-powered solutions

by VARINDIA
Crayon Software Experts India inaugurates its ISV Incubation Center in Kolkata

Crayon Software Experts India inaugurates its ISV Incubation Center in Kolkata

by VARINDIA
Dassault Systèmes to accelerate EV charging infrastructure development in India

Dassault Systèmes to accelerate EV charging infrastructure development in India

by VARINDIA
Tech Mahindra and Atento to deliver GenAI powered business transformation services

Tech Mahindra and Atento to deliver GenAI powered business transformation services

by VARINDIA
×

Reproduction in whole or in part in any form or medium without express written permission of Kalinga Digital Media Pvt. Ltd. is prohibited.

  • Distributors & VADs
  • Industry Associations
  • Telco's in India
  • Indian Global Leaders
  • Edit Calendar
  • About Us
  • Advertise Us
  • Contact Us
  • Disclaimer
  • Privacy Statement
  • Sitemap

Copyright varindia.com @1999-2024 - All rights reserved.