A notorious banking Trojan is targeting customers of a major bank with a new email spam campaign, which directs victims to a fake login page that's indistinguishable from that of their real bank.
The credential-stealing Trickbot banking malware has been hitting the financial sector since last year and targets online banking customers in in the US, UK, Australia, and other countries.
But no matter how advanced malware gets, phishing remains a common attack vector for distributing malicious payloads.
Uncovered by security researchers at Cyren, the latest Trickbot distribution campaign sent over 75,000 emails in 25 minutes, all claiming to be from Lloyds Bank, one of the UK's biggest banks.
Emails were sent with the subject 'Incoming BACs', a reference to BACS, a system that allows users to make payments directly from one email account to another. The emails claim that the target needs to review and sign attached documents.
After downloading and opening the Excel attachment 'IncomingBACs.xlsm', the user is asked to enable macros to allow the document to be edited. As with many malicious email campaigns, however, it's this process that allows the malware payload to be deployed.
In this case, the Trojan uses PowerShell to download an executable file, which eventually runs as 'Pdffeje.exe', the main TrickBot process, which installs the malware onto the machine.
Once a computer is infected with Trickbot, the malware runs in the background and waits for the victim to visit their online bank.
When they do so, Trickbot redirects them to a malicious site, which in this case is a fake version of the Lloyds website that looked exactly like the real thing -- complete with the correct URL of the online bank and a legitimate SSL certificate, so a user may not suspect they're being tricked.
By doing this, the attacker is able to see and steal the victim's online banking credentials and security codes, and make off with their funds and data.
While the fake sites resemble the real thing -- even showing the user the correct URL of the online bank and a legitimate SSL certificate so the user doesn't see anything unusual -- there's one major giveaway that the email isn't from Lloyds: the email address it is sent from is spelled incorrectly.
Instead of being from lloydsbank.co.uk, the message is sent from lloydsbacs.co.uk, a domain hosted by a Dutch IP address and a known source of spam.
"The protection of our customers is of paramount importance to us, and we remain committed to being vigilant and ensuring that our cyber security controls remain effective," a Lloyds Bank spokesperson told ZDNet.
"We encourage any customer who believes that they have been the victim of fraud to contact us at the earliest opportunity so that we can provide the appropriate support."
At its core, TrickBot remains similar to its predecessor, the data-stealing Dyre Troja, with its signature browser manipulation techniques.
While it isn't as prolific as the likes of Zeus, Gozi, Ramnit, and Dridex, researchers warn that Trickbot will continue to be "formidable force" in future, as its authors look to add more potent capabilities to better distribute this dangerous malware.
"TrickBot evolves and changes almost every day and targets new banks all over the world, so all banks should be on alert," said Stefnission.
It's currently not clear who is behind Trickbot, but the way the malware is continually evolving suggests it's the work of a well-organised, well-funded cybercriminal group.
IBM X-Force researchers warn that this sophisticated malware family is fast becoming one of the most prevalent forms of data-stealing banking Trojans
The old Dyre crew appear to have contributed to a new Trojan with updated, more devastating features.
MORE ON CYBERCRIME
- Banking Trojan tests new attack techniques against high-profile targets
- Hackers robbed Russian banks, eyed global heist [CNET]
- WannaCry researcher denies creating banking malware at court hearing
- Cyberwar: The smart person's guide [TechRepublic]
- Watch out for this money stealing macOS malware which mimics your online bank