TrickBot attention, replaces SIM cards

Administrators of the TrickBot trojan - one of the most active and widespread malware today - are now able to carry out SIM replacement attacks (SIM swapping attacks).

This has been noticed in the last month, as the developers of TrickBot seem to have developed a new version that can block login credentials and PINs for accounts from various mobile providers.

The data collected by TrickBot can allow malicious application administrators to carry out so-called SIM replacement attacks by transferring a victim's phone number to a SIM card under their control.

This of course allows TrickBot administrators to bypass two-factor authentication using SMS and reset passwords to bank accounts, email accounts or cryptocurrencies.

For the past two years, SIM replacement attacks have been one of the favorite techniques of hackers targeting financial services.

It is worth mentioning that TrickBot was developed as a targeted trojan simple banking operations in 2016. Today it has evolved into an Access-as-a-Service model. What does this mean; The scammers behind TrickBot also allow other malicious programmers to develop malware on computers that are already infected.

Discover more articles in search results.

This allowed TrickBot authors to develop close ties with many other cybercrime "colleagues" and Secureworks (the security company that revealed the latest action of the trojan) fears that they could use these relationships to share or sell the data they have managed to collect in the last month.

_________________________


Google preferences

Leave a Comment

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).