CISA and the FBI have observed continued sophisticated spearphishing campaigns in North America delivering TrickBot, a trojan first identified in 2016. The lure is a fake traffic infringement notice — an email claiming you have an unpaid citation, with a link to "view the violation."
Why This Lure Works
It creates urgency and uncertainty at once. Most people cannot immediately recall whether they were photographed running a light three weeks ago, and the instinct is to check. That moment of doubt is the entire attack.
How to Recognise It
- Real citations do not arrive by email from an agency you never gave an email address to. They arrive by post.
- Hover the link before clicking and read the actual domain. Government sites end in
.gov. - Look for a demand to act within 24 or 48 hours. Urgency is the standard pressure tactic.
- Be suspicious of any attachment, especially one asking you to "enable content" or "enable macros."
What TrickBot Does Once It Is In
It steals credentials — banking, email, saved browser passwords — and it is frequently used to open the door for ransomware later. The infection is rarely the end of the story; it is the beginning of one.
If You Already Clicked
- Disconnect the computer from the network.
- Change your passwords from a different device, starting with email and banking.
- Turn on multi-factor authentication on those accounts.
- Have the machine properly examined. A quick antivirus scan is not sufficient for this family of malware.
- Watch your bank statements closely for the next several weeks.
MediaVision Technical Analysis
We remove this kind of infection regularly, and the pattern is consistent: the malware is the easy part, the credential exposure is the expensive part. If a work machine is involved, assume every password stored in that browser is compromised and rotate them all.
Unsure whether an email is genuine? Forward it to us before you click. That costs nothing.