January 21, 2020 By David Bisson 2 min read

Security researchers observed that TrickBot has begun using a User Account Control (UAC) bypass to quietly infect machines running Windows 10 without displaying any prompts.

According to Bleeping Computer, security researcher Vitali Kremez observed a new sample of TrickBot analyzing the machine’s OS upon execution. It used the CMSTPLUA UAC bypass if it determined that the machine was running Windows 7. If the computer was running Windows 10, the malware employed the Fodhelper UAC bypass.

Discovered in 2017, the Fodhelper UAC bypass uses C:\Windows\system32\fodhelper.exe, a legitimate Microsoft executable, to execute other programs with administrative privileges. The malware turned to this technique because of its ability to bypass UAC via the registry method. Subsequently, the Trojan used the bypass to launch itself on a machine running Windows 10 without displaying a UAC prompt. In so doing, it did not alert the user, allowing it to quietly discharge its malicious functions.

A Glimpse at TrickBot’s Recent History

The bypass described above is just the latest advancement in TrickBot’s ongoing development. Back in August 2019, for instance, Secureworks discovered that the Trojan had added the ability to solicit PIN codes from mobile customers. These codes could have then allowed the malware to access victims’ voice and text communications via SIM swap fraud.

Several months later, at the beginning of January 2020, SentinelLabs revealed that the malware had added a stealthy backdoor known as PowerTrick to its arsenal. It was just a few weeks later when Bleeping Computer detected an Emotet campaign targeting email addresses at the United Nations with secondary malware payloads such as TrickBot.

How to Defend Against a TrickBot Infection

Security professionals can help their organizations defend against a TrickBot infection by using penetration tests to reveal weak spots in their network defenses. They should also leverage security awareness training and simulated phishing engagements to bolster their email defenses. Doing so will help minimize the risks associated with one of TrickBot’s most common delivery vectors.

More from

Hive0137 and AI-supplemented malware distribution

12 min read - IBM X-Force tracks dozens of threat actor groups. One group in particular, tracked by X-Force as Hive0137, has been a highly active malware distributor since at least October 2023. Nominated by X-Force as having the “Most Complex Infection Chain” in a campaign in 2023, Hive0137 campaigns deliver DarkGate, NetSupport, T34-Loader and Pikabot malware payloads, some of which are likely used for initial access in ransomware attacks. The crypters used in the infection chains also suggest a close relationship with former…

Unveiling the latest banking trojan threats in LATAM

9 min read - This post was made possible through the research contributions of Amir Gendler.In our most recent research in the Latin American (LATAM) region, we at IBM Security Lab have observed a surge in campaigns linked with malicious Chrome extensions. These campaigns primarily target Latin America, with a particular emphasis on its financial institutions.In this blog post, we’ll shed light on the group responsible for disseminating this campaign. We’ll delve into the method of web injects and Man in the Browser, and…

Crisis communication: What NOT to do

4 min read - Read the 1st blog in this series, Cybersecurity crisis communication: What to doWhen an organization experiences a cyberattack, tensions are high, customers are concerned and the business is typically not operating at full capacity. Every move you make at this point makes a difference to your company’s future, and even a seemingly small mistake can cause permanent reputational damage.Because of the stress and many moving parts that are involved, businesses often fall short when it comes to communication in a crisis.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today