Threat Advisory

TrueBot Targeting Small and Medium Organizations for Data Encryption and Ransomware Attacks

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers discovered a new TrueBot malware variant. They discovered threat actor mostly targets small and medium-sized businesses, with a concentration on healthcare organisations, mostly in the US and a few in Canada. The primary goal of the TA is to get unauthorised access to user devices in order to search for cryptocurrency wallets and bank accounts. If a device is deemed uninteresting, they proceed to sell access to ransomware-as-a-service (RaaS) affiliates.[/subscribe_to_unlock_form]

Summary:

Researchers discovered a new TrueBot malware variant. They discovered threat actor mostly targets small and medium-sized businesses, with a concentration on healthcare organisations, mostly in the US and a few in Canada. The primary goal of the TA is to get unauthorised access to user devices in order to search for cryptocurrency wallets and bank accounts. If a device is deemed uninteresting, they proceed to sell access to ransomware-as-a-service (RaaS) affiliates.[emaillocker id="1283"]

Targets of the TrueBot malware have been seen in a wide range of industries, primarily in the US and Canada, including healthcare, professional services, religious institutions, advertising, education, and manufacturing. Data encryption appears to be the attackers' main goal. The organisation behind TrueBot has changed its strategy from high-profile attacks on financial institutions to stealing corporate accounts, banking accounts, and cryptocurrency wallets in order to advance their privileges. There are indications that Silence, another malware, is collaborating with RaaS operations and offering access to ransomware affiliates.

The team of researchers discovered the most recent actions connected to TrueBot, also known as Silence Downloader. The main goal of Silence Downloader is to obtain and run an executable file on a compromised system. The web address where the executable file is hosted is provided by the Command and Control (CnC) server upon receiving a manual command from the operator. This method ensures that the file cannot be obtained or analyzed within a sandbox environment.

Threat Profile:

References:

Eventus Security Threat Research & Development Team

[/emaillocker]
crossmenu