TrickBot operators continued to expand the malware’s modular toolkit with components for credential theft, Remote Desktop Protocol brute-forcing, and network reconnaissance. Reporting on the rdpscanDll module showed it could receive targets, usernames, password candidates, and operating modes from command-and-control servers, then generate tailored credential guesses by transforming usernames, domains, hostnames, and IP-derived data rather than relying on a static password list. Separate analysis of TrickBot’s password-grabber updates found the malware targeting browser credentials, cookies, Active Directory data, and PuTTY SSH secrets, while also attempting to collect OpenSSH private keys and OpenVPN credentials and configurations from infected Windows systems.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
By November 2020, the TrickBot gang was using a new PowerShell-based reconnaissance tool dubbed LightBot in phishing campaigns previously associated with BazarLoader. The malware profiled infected hosts and Active Directory environments to identify high-value targets for follow-on attacks.
As of 2020-08-14, analysis of Trickbot's rdpscanDll identified 91 transformation rules used to generate target-specific credential guesses from usernames, domains, hostnames, IP addresses, and other values.
Bitdefender had already published a report in March 2020 on Trickbot's rdpscanDll module, which brute-forces Remote Desktop Protocol servers.
In early November 2019, observers saw two new HTTP POST request types from Trickbot's pwgrab64 module indicating attempts to collect OpenSSH private keys and OpenVPN passwords and configurations. The functionality appeared incomplete or broken because the requests lacked actual stolen data even in lab tests.
Unit 42 described Trickbot as malware first seen in 2016 that steals system information, login credentials, and other sensitive data from Windows hosts using downloadable modules.
Cybereason observed a wave of targeted attacks against financial, manufacturing, and retail organizations in the US and Europe that began with TrickBot infections and escalated to deployment of the newly identified Anchor and Anchor_DNS malware. The campaign selectively targeted high-value victims, including point-of-sale systems, and showed overlap with FIN6 tradecraft.
The cyber.wtf researcher observed that Trickbot's RDP scanner module was again being distributed among bots and found its command-and-control behavior largely unchanged from earlier reporting. The analysis also determined that the module's password candidates were dynamically transformed rather than drawn from a static dictionary.
TrickBot operators mistakenly distributed a test version of grabber.dll that displayed a visible warning to infected users in their browser instead of remaining stealthy. Researcher Vitali Kremez assessed that the developers likely forgot to remove the test warning before release.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 28 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcelabs.bitdefender.com
Open sourcebleepingcomputer.com
Open sourcecyber.wtf
Open sourcebleepingcomputer.com
Open sourceunit42.paloaltonetworks.com
Open sourcecybereason.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.