The Trickbot banking trojan continues to evolve, Trend Micro detected a new variant that includes a new module used for Remote App Credential-Grabbing. The new variant is being spread via spam emails that pose as tax-incentive notification purporting to be from the financial services company Deloitte. Trickbot relies on pwgrab module to capture the VNC credentials, including the target machines hostname, port and proxy settings. The module searches for files using the *. vnc. lnk affix.”]
Source: https://securityaffairs.co/wordpress/81264/malware/trickbot-malware-evolves.html

