Wednesday, February 26, 2025
HomeComputer SecurityNew TrickBot Module BruteForce RDP Connections Attacks Telecommunication Industry

New TrickBot Module BruteForce RDP Connections Attacks Telecommunication Industry

Published on

SIEM as a Service

Follow Us on Google News

A New TrickBot module discovered brute-forcing RDP connections on selected targets, mostly the telecom industry.

TrickBot is a well-know trojan for credential-harvesting, it is active since 2016, and it’s mainly focused on stealing financial data.

TrickBot RDP Scan Module

Security researchers from Bitdefender observed the new TrickBot module (rdpScanDll) that specifically built for brute-forcing RDP connections.

Trickbot trojan primarily distributed through spam emails, also known for its aggressive network spreading capabilities.

Once the Trickbot got executed on the machine it downloads the plugin and its configuration file from the C&C server. The plugin includes a list containing servers and the set of commands to be executed.

The plugin attacks RDP connections in three different modes;

Check Mode – Checks for RDP connection on the list of targets repeatedly.

TryBrute Mode – Will perform brute force attack on the list of targeted IPs.

Brute Mode – Seems the module still in the development phase.

If the Trickbot RDP module found a host online it reports to the C&C server & main module about the status of the host and it’s working credentials.

Researchers able to find “lists contained 49 IP addresses (/rdp/domains) and 5,964 IP addresses (/rdp/over). Most of these targets are located in the United States and Hong Kong.”

TrickBot RDP Scan
Geographical Distribution

The module mainly targets telecommunication industries, here is the list of affected industries

TrickBot RDP Scan
Targets

“We were able to retrieve 3,460 IP addresses, divided into 2,926
command and control servers and 556 servers dedicated to downloading new plugins, and 22 IPs serving both roles.”

The rdpScanDll is the new attachment to the TrickBot Trojan, the threat actors behind TrickBot module continues to expand its capabilities.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Silver Fox APT Hackers Target Healthcare Services to Steal Sensitive Data

A sophisticated cyber campaign orchestrated by the Chinese Advanced Persistent Threat (APT) group, Silver...

Ghostwriter Malware Targets Government Organizations with Weaponized XLS File

A new wave of cyberattacks attributed to the Ghostwriter Advanced Persistent Threat (APT) group...

LCRYX Ransomware Attacks Windows Machines by Blocking Registry Editor and Task Manager

The LCRYX ransomware, a malicious VBScript-based threat, has re-emerged in February 2025 after its...

Threat Actors Using Ephemeral Port 60102 for Covert Malware Communications

Recent cybersecurity investigations have uncovered a sophisticated technique employed by threat actors to evade...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Silver Fox APT Hackers Target Healthcare Services to Steal Sensitive Data

A sophisticated cyber campaign orchestrated by the Chinese Advanced Persistent Threat (APT) group, Silver...

Ghostwriter Malware Targets Government Organizations with Weaponized XLS File

A new wave of cyberattacks attributed to the Ghostwriter Advanced Persistent Threat (APT) group...

LCRYX Ransomware Attacks Windows Machines by Blocking Registry Editor and Task Manager

The LCRYX ransomware, a malicious VBScript-based threat, has re-emerged in February 2025 after its...