July 31, 2017 By Shane Schick 2 min read

The addition of a worm module in the banking Trojan known as TrickBot suggests that cybercriminals are taking a page from the recent WannaCry ransomware and Petya cyberattacks.

Worm Spreads Locally Through SMB

Researchers at security firm Flashpoint first drew attention to the worm module in TrickBot, which would allow it to spread much more easily than similar threats targeting the financial service sector.

Here’s how it works: Windows has a networking protocol called Server Message Block (SMB), which was exploited by a vulnerability dubbed EternalBlue in the WannaCry outbreak. TrickBot’s creators used SMB to identify all the computers in a network that connect via the lightweight directory access protocol (LDAP). The Trojan can also be disguised as setup.exe and delivered through a PowerShell script to spread through interprocess communication.

Testing the Worm Module

While WannaCry and Petya triggered international headlines, it may not be time to panic about TrickBot just yet. ZDNet said that the threat actors who created the malware appear to be testing the worm module rather than unleashing it in the wild. For now, the Flashpoint report is more of a warning about how cybercriminals are learning from one another and beefing up the capabilities of their attacks accordingly.

As Bleeping Computer pointed out, the concept of a worm module is relatively uncommon in banking Trojans. Traditionally, malware such as Gozi or Zeus have been better known for lying low and stealing credentials rather than self-spreading across a larger pool of potential victims.

There are exceptions, however. Emotet, for instance, conducted brute-force attacks on users via a RAR file that essentially extracted itself once it landed on an initial target.

The Bright Side

Fortunately, the worm module in TrickBot seems to use SMB in very deliberate searches for other places to spread, the International Business Times reported. That’s in contrast to WannaCry, which was seemingly able to look almost anywhere for external addresses online. And no matter how prevalent such malware becomes, it still depends largely on phishing schemes to fool users into granting access to their systems.

Just remember that even as the rest of world tries to figure out how the most successful cyberattacks work, the larger cybercriminal community is probably doing the same thing.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today