アメリカ合衆国とイギリスが共同で Trickbot と呼ばれるマルウェアを操るサイバー犯罪グループ(別名: Wizard Spider )に所属する 7 名に対し制裁措置をとりました。 Trickbot は Ryuk や Conti など複数のランサムウェアの展開に使用されていたことが分かっています。
TrickBot
TrickBot is a Windows banking trojan and modular malware platform associated with the Wizard Spider cybercrime group.
Profile source: Mallory opens in a new tabTrickBot
Family profile
TrickBot is a Windows banking trojan and modular malware platform associated with the Wizard Spider cybercrime group. Initially used for banking fraud and credential theft, it developed into a malware loader and post-compromise framework used to deliver additional payloads, including Cobalt Strike and ransomware. TrickBot has been linked to ransomware operations involving Ryuk and Conti and was commonly delivered through malicious email campaigns, including Excel documents containing macros. It can use PowerShell to retrieve further payloads, open documents, and transfer collected data to command-and-control infrastructure. TrickBot has also incorporated the Heaven’s Gate technique to evade some security monitoring by transitioning from 32-bit WOW64 execution to native 64-bit code on affected Windows systems. The malware has been distributed through access supplied by Emotet and used in financially motivated intrusions against organizations across multiple sectors.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Post Exploitation
Reported operators
Threat actors
29 named in public reportingQbot and TrickBot, in particular, were Emotet’s main customers and used their access to deploy ransomware (e.g. Ryuk, Conti, ProLock, Egregor, DoppelPaymer, and others).
"1359593325": "TrickBot/SmokeLoader/Nobelium/APT29 - Stats uniques -> ips/hostnames: 256 publickeys: 183"
However, also in 2017, it was observed delivering the Trojan.Trickybot and Ransom.UmbreCrypt ransomware.
TrickBot was developed in 2016 as a banking malware. However, since then it has developed into something essentially different — a flexible, universal, module-based crimeware solution.
Trickbot was first spotted in 2016 as a banking trojan that was created as a successor to Dyre and designed to steal banking credentials. Over the years, Trickbot’s operators were able to build a massive botnet, and the malware evolved into a modular malware available for malware-as-a-service.
In 2020, we observed the shift from TA800 distributing the Trick, with intermittent shifts to Buer Loader, and a consistent distribution of Bazaloader since April 2020.
Of these, the Trickbot group seemed to be their best and longest-running customer based on the numerous observations of Trickbot being dropped by Emotet.
Trickbot is a popular and modular Trojan initially used in targeting the banking industry, that has meanwhile been used to compromise companies from other industries as well. It delivers several types of payloads.
In a number of incidents we investigated, the actors established an initial foothold into the victim's network through common banking trojans such as IcedID or Trickbot.
TrickBot, meanwhile, debuted in late 2016 as a banking Trojan, before undergoing numerous modifications. As with many other prior banking Trojans, TrickBot's developers continued to refine the code and expand its capabilities, transforming it into information-stealing malware sporting modular capabilities.
Trickbot is a popular and modular Trojan initially used in targeting the banking industry, that has meanwhile been used to compromise companies from other industries as well. It delivers several types of payloads.
In a number of incidents we investigated, the actors established an initial foothold into the victim's network through common banking trojans such as IcedID or Trickbot.
The US Department of Justice has arraigned in court today a Latvian woman who was part of the Trickbot malware crew, where she served as a programmer and wrote code for controlling the malware and deploying ransomware on infected computers.
Collaborative research between Advanced Intelligence (AdvIntel) and Eclypsium has discovered that the TrickBot malware now has functionality designed to inspect the UEFI/BIOS firmware of targeted systems. This new functionality, which we have dubbed “TrickBoot,” makes use of readily available tools to check devices for well-known vulnerabilities that can allow attackers to read, write, or erase the UEFI/BIOS firmware of a device.
Collaborative research between Advanced Intelligence (AdvIntel) and Eclypsium has discovered that the TrickBot malware now has functionality designed to inspect the UEFI/BIOS firmware of targeted systems. This new functionality, which we have dubbed “TrickBoot,” makes use of readily available tools to check devices for well-known vulnerabilities that can allow attackers to read, write, or erase the UEFI/BIOS firmware of a device.
In cases where the geolocation matches a set list... this request led to the download of Trickbot as we used a UK based exit point.
Overlaps were also found with TrickBot, Ryuk/Conti, FIN7, and TrueBot (also known as Silence.Downloader) malware operations
The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT.
WithSecure found connections between GREYVIBE’s tooling and both the TrickBot gang and UAC-0098, a group previously linked to Russian cybercriminal networks.
...sanctions against the Russian hackers allegedly connected to a single network behind the Conti and Ryuk ransomware variants, as well as the infamous Trickbot banking trojan...
Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Trickbot, a modular malware platform
Selon MICROSOFT, les opérateurs de PISTACHE TEMPEST auraient également utilisé le code malveillant TrickBot et le MaaS GoziAT [14].
The relationship between Russian Intelligence organizations and various Russian cybercriminal groups, such as a partnership between RomCom and Trickbot, essentially functions as a modern-day privateer model.
"...the U.S. Federal Bureau of Investigation (FBI) issued an alert warning of attacks involving WIZARD SPIDER’s TrickBot leading to ransomware infections..."
Distribution of Qbot affiliate “partner01” as the primary payload delivered by Emotet instead of The Trick.
"...shares code and forensic markers with other malware from the Trickbot family..."
“Members of the group are alleged to have connections with… the Trickbot banking Trojan.”
"AdFind Command Activity" ... "The AdFind tool has been observed in Trickbot, Ryuk, Maze, and FIN6 campaigns."
Exploited software
Vulnerabilities linked to TrickBot
7 CVEsMITRE ATT&CK
TrickBot in ATT&CK
125 distinct techniquesTechniques
125 techniquesReporting
Research mentioning TrickBot
GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Ransomware Group clop Hits: HONGHE-TECH.COM
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.