Contact Us

1 (800) 723-1166 |



Trickbot Goes After Cryptocurrency

Forcepoint Security Labs have encountered an ongoing Trickbot campaign that appears to target crypto-currencies. Trickbot is a banking Trojan that is traditionally known to target financial institutions. Recently, we have observed Trickbot targeting Paypal and expanding its list of target institutions to include those from Nordic countries.

Today’s campaign uses Canadian Imperial Bank of Commerce (CIBC) as a social engineering lure and targets Coinbase, a digital assets exchange site.

TrickBot spread by Necurs Botnet, Adds Nordic Countries to its Targets

At around 09:00 BST yesterday, Forcepoint Security Labs™ observed a significant malicious email campaign from the Necurs botnet. Necurs is a prevalent botnet that is known to spreading Locky ransomware, pump-and-dump stock scams, and more recently the Jaff ransomware. This time Necurs has been seen spreading the Trickbot banking Trojan, complete with an updated set of targets.