Trickbot Strikes Via New Spam Wave
Publish Date: 21 November 2018
![](https://documents.trendmicro.com/images/Spam01-11242018.jpg)
We have observed a new spam wave delivering Trickbot. This campaign uses spam mail with malicious attachments disguised as a Microsoft Excel file. The message contains fake payment notification, claiming to be from well-known banks or financial entities. When the .XLS attachment is opened, it asks users to enable macros. This then executes a PowerShell command to access a malicious link that downloads the Trickbot malware.
![](https://documents.trendmicro.com/images/Spam02-11242018.jpg)
Trend Micro detects the malicious attachment as Trojan.X97M.POWLOAD.NSFGAIBR. Trend Micro email products easily prevents spam messages from reaching your inbox. While products with anti-spam help, users are still advised to ignore email that are fro unknown sources.
Spam gesperrt am/um:: 21 November 2018 GMT-8
TMASE
- TMASE Engine::8.0
- Patrón TMASE: 4238