Trend Micro reported that the TrickBot banking trojan added a new password-grabber module, extending the malware’s capabilities beyond its established role in financial fraud and post-compromise activity. The module was designed to harvest stored credentials from infected systems, giving operators another way to steal account access and deepen persistence inside victim environments.
The update underscored TrickBot’s continued evolution as a modular malware platform, with new components allowing attackers to tailor infections for credential theft and broader follow-on intrusion. By adding password collection to its toolkit, TrickBot increased the risk of account compromise across enterprise and consumer systems and strengthened its value as a flexible malware service for cybercriminal operations.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Trend Micro published research describing a new TrickBot capability: a password grabber module. The reference indicates the module was observed by the time of the report, but provides no additional dated milestones in the supplied content.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.