Last seven days
- First activity
- Jul 27, 2026
- Last activity
- Jul 27, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
TrickBot is a modular Windows malware family that emerged as a banking trojan and evolved into a broad criminal malware platform used for credential theft, post-compromise control, lateral movement, and delivery of additional payloads including ransomware.
Profile source: Mallory opens in a new tabTrickBot
TrickBot is a modular Windows malware family that emerged as a banking trojan and evolved into a broad criminal malware platform used for credential theft, post-compromise control, lateral movement, and delivery of additional payloads including ransomware. It has long been associated with the TrickBot cybercrime ecosystem and with actors linked to Wizard Spider and later Conti-related operations. The malware has also been connected in public reporting to Ryuk-linked intrusion activity and to broader Russian cybercrime support networks targeted by sanctions.
TrickBot is notable for its extensible architecture and its ability to download and execute additional modules after initial compromise. Reported capabilities include theft of Outlook and browser data, execution of Windows commands and PowerShell, DLL execution through signed Windows utilities, direct execution of downloaded code, and process injection techniques including process hollowing and process doppelgänging. It has also been observed modifying the Windows Registry and using encoded PowerShell for persistence and lateral movement.
On Windows systems, TrickBot has demonstrated multiple persistence and defense-evasion mechanisms. Observed variants create recurring scheduled tasks to relaunch the malware, store task metadata in NTFS Alternate Data Streams, encrypt internal strings, and resolve APIs dynamically at runtime using hash-based lookups to hinder static analysis. Separate samples have used API hammering and delayed execution to overwhelm or evade sandbox instrumentation before injecting into legitimate Windows processes.
A more covert variant replaced earlier HTTP-based command-and-control with DNS tunneling. In that design, outbound command data is encrypted, encoded into malformed DNS queries, and inbound tasking or module data is reconstructed from values embedded in DNS responses. This transport allows TrickBot traffic to blend into routine DNS activity while preserving enough throughput for sustained command exchange and module delivery.
TrickBot has been distributed by other malware, notably Emotet, which has served as a downloader for TrickBot in phishing-driven infection chains. Across its evolution, TrickBot has remained one of the most significant modular crimeware platforms in the Windows ecosystem, bridging banking trojan functionality with enterprise intrusion, credential theft, stealthy persistence, and ransomware enablement.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Ce dernier est recherché par la police allemande et considéré comme impliqué dans le botnet TrickBot et Wizard Spider.
The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT.
WithSecure found connections between GREYVIBE’s tooling and both the TrickBot gang and UAC-0098, a group previously linked to Russian cybercriminal networks.
The most notorious among these are campaigns involving banking Trojans such as Dridex and TrickBot, ransomware such as Clop/Cryptomix and MINEBRIDGE...
...sanctions against the Russian hackers allegedly connected to a single network behind the Conti and Ryuk ransomware variants, as well as the infamous Trickbot banking trojan...
Threat actors use BazarLoader and Trickbot to deploy the Ryuk or Conti ransomware, while IcedID has been used in the past to deploy the now-defunct Maze and Egregor ransomware infections.
Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Trickbot, a modular malware platform
Selon MICROSOFT, les opérateurs de PISTACHE TEMPEST auraient également utilisé le code malveillant TrickBot et le MaaS GoziAT [14].
The relationship between Russian Intelligence organizations and various Russian cybercriminal groups, such as a partnership between RomCom and Trickbot, essentially functions as a modern-day privateer model.
In November 2021, Cybereason revealed that the operators of the TrickBot trojan were teaming up with TA551 to distribute Conti Ransomware.
"...the U.S. Federal Bureau of Investigation (FBI) issued an alert warning of attacks involving WIZARD SPIDER’s TrickBot leading to ransomware infections..."
"TA800... is an affiliate distributor of the The Trick, also known as Trickbot, and BazaLoader."
Distribution of Qbot affiliate “partner01” as the primary payload delivered by Emotet instead of The Trick.
"...shares code and forensic markers with other malware from the Trickbot family..."
Conti ransomware ... is a ransomware operation ... known for other notorious malware infections, such as TrickBot. The ransomware gang usually gains access to a network through BazarLoader or TrickBot malware infections installed via phishing attacks...
“Members of the group are alleged to have connections with… the Trickbot banking Trojan.”
Malware like Vatet loader, PyXie, Trickbot, and RansomExx, as well as some post-intrusion tools like Cobalt Strike, are typically part of this threat group’s arsenal.
"AdFind Command Activity" ... "The AdFind tool has been observed in Trickbot, Ryuk, Maze, and FIN6 campaigns."
Exploited software
MITRE ATT&CK
Reporting
Researchers detailed MedusaHVNC, a malware-as-a-service remote access trojan that gives attackers covert control of infected Windows systems by creating an invisible desktop and launching legitimate browsers outside the victim’s view. The malware lets operators abuse the victim’s existing browser profiles, cookies, and live authenticated sessions, making malicious activity appear to come from the user’s own device. Analysts said the payload supports typical hidden VNC functions including screen capture, synthetic keyboard and mouse input, window interaction, and clipboard access, with references to Chrome, Edge, and Firefox. Analysis of a recent sample found a five-stage infection chain starting with wscript.exe running an obfuscated JScript launcher, followed by files dropped into the TEMP directory, persistence via a Startup-folder batch file, and AutoIt-based components that inject a loader into charmap.exe before unpacking the final unsigned 64-bit payload. The malware contains the MedusaHVNC family string and communicates over a custom TCP protocol with a hard-coded command-and-control server at 51.89.204.28:4444. Researchers said defenders should focus on outbound traffic monitoring, blocking known infrastructure and file hashes, and watching for unexpected data exfiltration because stolen information must still leave the network.
Researchers identified a TrickBot variant for Microsoft Windows that replaces its usual HTTP command-and-control channel with a custom DNS tunneling mechanism, allowing the malware to hide outbound tasking in malformed DNS queries and reconstruct inbound data from IPv4 addresses returned in DNS responses. Fortinet said the malware sends XOR-encrypted, hex-encoded command data in chunks designed to resemble legitimate domain labels, with traffic observed via 8.8.8.8 and a command-and-control domain of westurn.in. The transport redesign preserves TrickBot’s modular architecture while making communications harder to detect and block. The malware maintains persistence through Windows Task Scheduler, with tasks configured to run every five minutes, and stores task metadata in NTFS Alternate Data Streams to reduce visibility. Fortinet reported the variant also uses encrypted strings and hash-based runtime API resolution to complicate analysis, while retaining capabilities for module download, rundll32-based execution, PowerShell execution, direct machine-code execution, process hollowing, and process doppelgänging. Researchers measured the DNS tunnel at roughly 30.7 KB/s, indicating the channel is practical for sustained covert command-and-control operations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.