Fake Barclays Secured Message: New Message Received delivers Trickbot via CVE-2018-8174

We have had a break from Trickbot hitting the UK in last week or so, that generally means that the criminals are experimenting with new delivery systems.  The reappearance on Monday 25 June 2018  confirms this. I am not sure how successful this new system will be because it uses an exploit CVE-2018-8174 ( which only affected Internet Explorer) which was fixed in May 2018 windows updates, so I doubt there are enough vulnerable systems around that makes this worthwhile continuing with the campaign.  Instead of the usual word docs with either macros, embedded ole objects or using the Microsoft Continue reading →

The post Fake Barclays Secured Message: New Message Received delivers Trickbot via CVE-2018-8174 appeared first on My Online Security.