New TrickBot Module BruteForce RDP Connections Attacks Telecommunication Industry

A New TrickBot module discovered brute-forcing RDP connections on selected targets, mostly the telecom industry.

TrickBot is a well-know trojan for credential-harvesting, it is active since 2016, and it’s mainly focused on stealing financial data.

TrickBot RDP Scan Module

Security researchers from Bitdefender observed the new TrickBot module (rdpScanDll) that specifically built for brute-forcing RDP connections.

Trickbot trojan primarily distributed through spam emails, also known for its aggressive network spreading capabilities.

Once the Trickbot got executed on the machine it downloads the plugin and its configuration file from the C&C server. The plugin includes a list containing servers and the set of commands to be executed.

The plugin attacks RDP connections in three different modes;

Check Mode – Checks for RDP connection on the list of targets repeatedly.

TryBrute Mode – Will perform brute force attack on the list of targeted IPs.

Brute Mode – Seems the module still in the development phase.

If the Trickbot RDP module found a host online it reports to the C&C server & main module about the status of the host and it’s working credentials.

Researchers able to find “lists contained 49 IP addresses (/rdp/domains) and 5,964 IP addresses (/rdp/over). Most of these targets are located in the United States and Hong Kong.”

Geographical Distribution

The module mainly targets telecommunication industries, here is the list of affected industries

Targets

“We were able to retrieve 3,460 IP addresses, divided into 2,926
command and control servers and 556 servers dedicated to downloading new plugins, and 22 IPs serving both roles.”

The rdpScanDll is the new attachment to the TrickBot Trojan, the threat actors behind TrickBot module continues to expand its capabilities.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Authorities Seize $31 Million Linked to Crypto Exchange Hack

U.S. authorities announced the seizure of $31 million tied to the 2021 Uranium Finance decentralized…

14 minutes ago

Google, Meta, and Apple Power the World’s Biggest Surveillance System

Imagine a government that tracks your daily movements, monitors your communications, and catalogs your digital…

19 minutes ago

Docusnap for Windows Flaw Exposes Sensitive Data to Attackers

A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt sensitive…

2 hours ago

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows privilege…

2 hours ago

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under limited,…

4 hours ago

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems to…

5 hours ago