Researchers from Dell Secureworks saw a new feature in TrickBot that allows it to tamper with the web sessions of users from Verizon, T-Mobile, and Sprint mobile carriers. TrickBot was born from the same threat actors behind Dyreza, the credential-stealing malware our own researcher Hasherazade dissected back in 2015. The sudden targeting of mobile phone PINs suggests that threat actors using TrickBot are showing interest in getting involved with certain fraud tactics like port-out fraud and SIM swap.”]