Banking Botnet Profit Share

Instead of ripping each other's malware out of victim systems, the groups behind Trickbot and IcedID are playing nice with each other, says the risk intelligence firm, FlashpointIn what could be the beginning of a significant new trend, the operators of two separate banking botnets appear to have begun collaborating with each other in targeting systems and stealing money from victims.

Flashpoint says it has evidence suggesting the operators of the Trickbot and IcedID botnets have gotten into some kind of a profit-sharing arrangement in which they are using each other's malware and infrastructure to cash out victim bank accounts.

Such partnerships are extremely rare in the cyber-crime world where rival groups are more likely to rip each other's malware out of victim systems than collaborate on a malicious campaign. For enterprises, the trend could spell new trouble.

"This collaboration indicates that sophisticated botnet malware operators will … team up to defeat anti-fraud measures in place when [a] reasonable profit-sharing agreement can be reached amongst various groups," says Vitali Kremez, director of research at Flashpoint.

According to the vendor, some malware samples that it has recently analyzed suggest that computers infected with IcedID are also downloading the Trickbot banking Trojan.

IcedID is a banking malware sample that first popped up in the wild last April and is being massively distributed via spam email. Its victims have included financial services companies, retailers, and technology firms.

Up to now, IcedID has typically been installed on systems via a downloader called Emotet. But Flashpoint says that it now appears IcedID is being sent directly as spam. When the malware is installed on a system, it then acts as a downloader for Trickbot, which in turn installs other malware modules on the compromised system.

"IcedID is a primarily banking malware with downloader capabilities to install additional malware," Kremez says.

One of its key features is its ability to maintain persistence on infected machines. TrickBot is more of a multi-modular banking malware that has targeted victims in a slew of industries. The group behind it has used infected systems for a range of different malicious activities including bank account hijacking and for cryptocurrency mining.

"It is considered to be the successor to the Dyre banking malware and contains various credential-stealing, cryptocurrency mining as well as network propagation [features], amongst others," Kremez notes.

Flashpoint says the collaboration between the IcedD and Trickbot groups has given the pair significant new capabilities. The two groups are using their respective malware tools to steal credentials for breaking into bank accounts belonging to the owners of infected systems and stealing money from them.

Members from the two groups monitor infected systems for activities that are of specific interest. For instance, when the owner of a system that is infected with Trickbot and IcedID malware tries to log into a bank account of interest, the botmaster grabs the login credentials and other details and passes it on to affiliates.

The affiliates then use the login credentials and other information required to access the victim's account and transfer money out of it to rogue accounts previously opened by money mules. The mules often open the fraudulent bank accounts in the same financial institution and same geographic location as the victim's own account.

"The group botmasters collaborate on cashing out compromised bank accounts and share profits from their infections," Kremez says.

IcedID appears to be more focused on banking account-stealing operation, while TrickBot group also deploys additional modules to maximize profits from the compromised machines. Each compromised machine bears indicators of who exactly delivered the infection so it is easier to share the spoils.

Based on how the collaboration between IcedID and Trickbot has been working so far and the shared infrastructure they have built, it is quite likely that the operators of the two groups will continue to partner, Flashpoint said.

Expect to see more malware developers and fraud masters try and foster such collaborative partnerships if doing so can help them bypass the latest anti-fraud measures.

Dark Reading

You Might Also Read: 

Botnets Are Here To Stay:

Interpol Located & Shut Down 9,000 Command Servers
 

 

« Ukraine Detects A Cyber Attack On A NATO Member
Russia Is Building A Separate Military Cloud »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Biscom

Biscom

Biscom offers solutions for secure file transfer, synchronization, file translation, and mobile devices, designed to deliver mission-critical reliability, streamline workflows and reduce costs.

Zanasi & Partners

Zanasi & Partners

Zanasi & Partners is a security research and advisory company active in the EU and MENA areas. Services focus on technology solutions.

CARICERT

CARICERT

CARICERT is the National Cyber Emergency Response Team of Curacao in the Caribbean.

Findings

Findings

Findings (formerly IDRRA) is a scalable AI powered assessment platform that streamlines security compliance across sectors, jurisdictions and regulatory frameworks.

PeckShield

PeckShield

PeckShield is a blockchain security company which aims to elevate the security, privacy, and usability of entire blockchain ecosystem by offering top-notch, industry-leading services and products.

M12

M12

M12 (formerly Microsoft Ventures) is the corporate venture capital subsidiary of Microsoft.

ControlMap

ControlMap

ControlMap is a software as a service platform with a mission to simplify and eliminate stress from everyday operations of modern IT compliance teams.

Avancer Corporation

Avancer Corporation

Avancer Corporation is a multi-system integrator focusing on Identity and Access Management (IAM) Technology. Founded in 2004.

MindWise

MindWise

MindWise is a comprehensive global threat monitoring solution with implementations for fraud prevention and enterprise threat intelligence.

QAlified

QAlified

QAlified offer independent testing and quality assurance services for software projects including security testing.

Infinipoint

Infinipoint

Infinipoint pioneers the first Device-Identity-as-a-Service (DIaaS) solution, addressing Zero Trust device access and enabling enterprises of all sizes to automate cyber hygiene.

Airiam

Airiam

Airiam provides cybersecurity, managed IT, consulting, incident response, and digital transformation services so you can focus on what matters most.

Vancord

Vancord

Vancord is an information and security technology company that works in collaboration with clients to support their infrastructure and data security needs for today and tomorrow.

SHI International

SHI International

SHI International deliver against your IT and business needs, helping you build strategies and solutions that will drive innovation, collaboration and security.

The Purple Guys

The Purple Guys

The Purple Guys offer Trouble-Free IT Support to businesses across the Central and Southern US. Safe and Secure, Rapid Response, Friendly Support that’s our Purple Promise.

Leostream

Leostream

Leostream's Remote Desktop Access Platform enables seamless work-from-anywhere flexibility while maintaining security and constant visibility of users.