Woburn, MA – October 19, 2021 – Today Kaspersky researchers released an in-depth analysis of 61 existing modules of the infamous Trickbot banking Trojan, detailing the various ways the malware has been updated. Discovered in 2016, Trickbot’s main functionality was online banking data theft. Over its five years of activity, the Trickbot Trojan has changed as attackers came up with a more advanced toolset.

Trickbot is a descendant of the Dyre banking Trojan, which originated as a Trojan that stole banking data and account credentials. Today Trickbot has evolved and became a multi-modular malware ranging its activity from data theft to other malware distribution (such as Ryuk ransomware).

Kaspersky researchers have analyzed a total of 61 modules of Trickbot and discovered that the Trojan has acquired dozens of auxiliary modules that steal credentials and sensitive information. The malware spreads over local networks using stolen credentials and vulnerabilities, provides remote access and proxy network traffic, performs brute-force attacks and downloads other malware.

Trickbot targets companies and individual users around the world. According to Kaspersky, Trickbot’s activity is not geographically limited and most of the affected users were located in the USA (13.21%), Australia (10.25%) and China (9.77%), followed by Mexico (6.61%) and France (6.30%).

“Cybercriminals always update and refresh their toolsets,” said Oleg Kupreev, security expert at Kaspersky. “Right now, Trickbot has developed and became one of the most powerful and dangerous samples of its malware type. As cybercriminals evolve, so should protection techniques. Most of the attacks can be prevented, that is why it is important to have an up-to-date security solution.”

Kaspersky security solutions successfully detect and block all known versions of the Trickbot banking Trojan.

Learn more about Trickbot on Securelist.

To stay safe from financial threats like Trickbot, Kaspersky experts recommend that you:

·       Do not follow links in spam messages nor open documents attached to them.

·       Use online banking with multifactor authentication solutions.

·       Make sure all of your software is updated – including your operating system and all software applications (attackers exploit loopholes in widely used programs to gain entry).

·       Use a trusted security solution that can help you check the security of the URL you’re visiting and open any site in a protected container to prevent theft of sensitive data (like financial information).


About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection and a number of specialized security solutions and services to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky technologies and we help 240,000 corporate clients protect what matters most to them. Learn more at usa.kaspersky.com.

Media Contact

Sawyer Van Horn


(781) 503-1866



Trickbot banking Trojan evolves with 61 sophisticated techniques

Kaspersky Logo