The Trickbot malware has been upgraded with a network reconnaissance module designed to survey local networks after infecting a victim’s computer. The new module uses the open-source masscan tool, a mass port scanner with its own TCP/IP stack and capable of scanning large swaths of the Internet in a matter of minutes. The module is a Windows DLL file, with a 32-bit or 64-bit architecture depending on the system the malware has infected. Trickbot gang has previously released a standalone reconnaissance tool known as LightBot in the form of a PowerShell script.
Source: https://www.bleepingcomputer.com/news/security/trickbot-malware-now-maps-victims-networks-using-masscan/