Skip to main content

TrickBot returns with new attack that compromised 250 million email addresses

The TrickBot malware, which earlier this year worked in tandem with the Ryuk ransomware to siphon millions of dollars for hackers, is back with a new attack that may have compromised as many as 250 million email accounts.

In a report by Deep Instinct, the cybersecurity company revealed a new variant of TrickBot that teams it up with a malicious, email-based infection and distribution module dubbed TrickBooster.

Recommended Videos

The new attack starts the same as in previous methods, with TrickBot infiltrating a victim’s computer. The malware then forces the machine to download TrickBooster, which reports back to a dedicated command and control server with lists of email addresses and log-in credentials harvested from the victim’s inbox, outbox, and address book. Afterwards, the TrickBooster server instructs the infected machine to send out malicious infection and spam emails, with the emails deleted from the outbox and trash folder to remain hidden from the victim.

In Deep Instinct’s investigation of TrickBooster and its associated network infrastructure, the cybersecurity firm discovered a database containing 250 million email accounts that were harvested by TrickBot operators. The addresses were likely also targeted with the malicious emails.

The recovered email dump includes about 26 million addresses on Gmail, 19 million on Yahoo, 11 million on Hotmail, 7 million on AOL, 3.5 million on MSN, and 2 million on Yahoo U.K. The compromised accounts also involved many government departments and agencies in the United States, including but not limited to the Department of Justice, the Department of Homeland Security, the Department of State, the Social Security Administration, the Internal Revenue Service, the Federal Aviation Administration, and the National Aeronautics and Space Administration. Others affected include government organizations and universities in the United Kingdom and Canada.

Deep Instinct spot checked a few thousands of the compromised email accounts against previously recorded security breaches, and found that the database is a new batch of addresses that has not been previously seen or reported.

The discovery of TrickBooster “highlights the success and sophistication of TrickBot,” according to Deep Instinct, while the model was described as “a powerful addition to TrickBot’s vast arsenal” of methods of attack.

Deep Instinct said that it continuing its research and analysis into TrickBooster, and that it is in the process of reporting the details of the new TrickBot attack to the authorities.

Aaron Mamiit
Aaron received an NES and a copy of Super Mario Bros. for Christmas when he was four years old, and he has been fascinated…
Early Black Friday deals under $25 — Speakers, keyboards, smart light bulbs, and more
The Amazon Echo Pop on a desk.

Update 11/25/24: If you're looking for dirt cheap items that don't skimp on quality this year — don't worry because we've found 'em. This early selection shows exactly what we're looking forward to as the deals season progresses. We'll continue to update this list throughout the Black Friday sale event.

As you know, Black Friday is coming up on November 29th. Luckily, you don't have to wait until then to start getting great deals — early Black Friday deals are already here. That means you can get early Black Friday TV deals, early Black Friday laptop deals, and even early Black Friday Keurig deals. But what if you just have a few dollars to spare on your shopping or if your major purchase didn't cover all of your shopping budgets for the season? That's where these little pick-me-ups, items under $25, really come in handy. They're all things you need or might want and just might go well with your other purchases this season. Plus, with the low prices available now, you can come away feeling like you got a great bargain.
Amazon Echo Pop — $18 $40 55% off

Read more
Elon Musk’s Neuralink to test if its brain implant can control a robotic arm
A robotic arm.

Elon Musk’s Neuralink company has said it’s about to begin testing a technology that could enable someone with paralysis to control a robotic arm with their thoughts.

“We’re excited to announce the approval and launch of a new feasibility trial to extend brain-computer interface (BCI) control using the N1 Implant to an investigational assistive robotic arm,” Neuralink said in a post on X on Monday.

Read more
Nvidia may have found a new way to bypass GPU export restrictions
The RTX 4090 graphics card sitting on a table with a dark green background.

Chinese gamers are expected to have limited access to Nvidia's best graphics card due to strict export restrictions. However, Nvidia may have found a way around it without cutting down its flagship GPU. A new leak suggests that the RTX 5090D will have the same hardware specifications as the worldwide version, and the solution lies in firmware adjustments.

As a quick refresher, the "D" in RTX 5090D stands for "Dragon." It marks GPUs made by Nvidia to bypass the export restrictions imposed by the U.S. on China, which limit the sale of high-performance graphics processors. We first saw it appear in the RTX 4090D as a remedy for the fact that the base RTX 4090 exceeds the performance thresholds set by these regulations.

Read more