Trojan is modular in nature, meaning it can easily be customized with one or more of an array of custom components designed to carry out a range of malicious activities on infected computers. Trickbot is spread through spam and phishing email campaigns which usually bear a Microsoft Word attachment containing malicious macros. To date, it has mainly been used for two main purposes: stealing credentials from infected computers and acting as a distribution channel for other malware. Symantec believes that Trickbots operators earn most of their revenue from selling stolen credentials on the cyber underground.”]

