TrickBot Malware Uses Highly Personalized Fake Sexual Harassment Complaints as Phishing Bait

Stu Sjouwerman | Nov 12, 2019
sample-trickbot-phish

Fake sexual harassment complaints appearing to come from the U.S. Equal Employment Opportunity Commission (EEOC) are the latest baits used by attackers to disseminate TrickBot banking Trojan payloads onto computers of unsuspecting employees of large companies.

The EEOC is a federal agency responsible for investigating and enforcing federal laws against workplace discrimination.

As part of this campaign, the malware operators use information collected for each target such as their names, the company they work for, their job titles, and even their phone numbers to customize the phishing emails in order to make them a lot more convincing.

For instance, everything from the email's subject and the message content to the malicious attachment each of the malspam emails come with contains the potential victim's name as MalCrawler discovered. By adding a "personal touch" to their phishing emails, the attackers greatly increase the chance of their TrickBot payloads being dropped and infecting their victims computers. Source and more technical detail at Bleepingcomputer: https://www.bleepingcomputer.com/news/security/trickbot-malware-uses-fake-sexual-harassment-complaints-as-bait/

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.