Skip to content

TrickBot

TrickBot is a Windows banking trojan and modular malware platform associated with the Wizard Spider cybercrime group.

Profile source: Mallory opens in a new tab

TrickBot

Family profile

TrickBot is a Windows banking trojan and modular malware platform associated with the Wizard Spider cybercrime group. Initially used for banking fraud and credential theft, it developed into a malware loader and post-compromise framework used to deliver additional payloads, including Cobalt Strike and ransomware. TrickBot has been linked to ransomware operations involving Ryuk and Conti and was commonly delivered through malicious email campaigns, including Excel documents containing macros. It can use PowerShell to retrieve further payloads, open documents, and transfer collected data to command-and-control infrastructure. TrickBot has also incorporated the Heaven’s Gate technique to evade some security monitoring by transitioning from 32-bit WOW64 execution to native 64-bit code on affected Windows systems. The malware has been distributed through access supplied by Emotet and used in financially motivated intrusions against organizations across multiple sectors.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Post Exploitation

Reported operators

Threat actors

29 named in public reporting
WIZARD SPIDER

アメリカ合衆国とイギリスが共同で Trickbot と呼ばれるマルウェアを操るサイバー犯罪グループ(別名: Wizard Spider )に所属する 7 名に対し制裁措置をとりました。 Trickbot は Ryuk や Conti など複数のランサムウェアの展開に使用されていたことが分かっています。

Conti

Qbot and TrickBot, in particular, were Emotet’s main customers and used their access to deploy ransomware (e.g. Ryuk, Conti, ProLock, Egregor, DoppelPaymer, and others).

APT29

"1359593325": "TrickBot/SmokeLoader/Nobelium/APT29 - Stats uniques -> ips/hostnames: 256 publickeys: 183"

Mealybug

However, also in 2017, it was observed delivering the Trojan.Trickybot and Ransom.UmbreCrypt ransomware.

Lazarus

TrickBot was developed in 2016 as a banking malware. However, since then it has developed into something essentially different — a flexible, universal, module-based crimeware solution.

TA505

Trickbot was first spotted in 2016 as a banking trojan that was created as a successor to Dyre and designed to steal banking credentials. Over the years, Trickbot’s operators were able to build a massive botnet, and the malware evolved into a modular malware available for malware-as-a-service.

TA800

In 2020, we observed the shift from TA800 distributing the Trick, with intermittent shifts to Buer Loader, and a consistent distribution of Bazaloader since April 2020.

Trickbot

Of these, the Trickbot group seemed to be their best and longest-running customer based on the numerous observations of Trickbot being dropped by Emotet.

UNC1778

Trickbot is a popular and modular Trojan initially used in targeting the banking industry, that has meanwhile been used to compromise companies from other industries as well. It delivers several types of payloads.

PyXie

In a number of incidents we investigated, the actors established an initial foothold into the victim's network through common banking trojans such as IcedID or Trickbot.

fin12

TrickBot, meanwhile, debuted in late 2016 as a banking Trojan, before undergoing numerous modifications. As with many other prior banking Trojans, TrickBot's developers continued to refine the code and expand its capabilities, transforming it into information-stealing malware sporting modular capabilities.

TA551

Trickbot is a popular and modular Trojan initially used in targeting the banking industry, that has meanwhile been used to compromise companies from other industries as well. It delivers several types of payloads.

Gold Dupont

In a number of incidents we investigated, the actors established an initial foothold into the victim's network through common banking trojans such as IcedID or Trickbot.

QQAAZZ

The US Department of Justice has arraigned in court today a Latvian woman who was part of the Trickbot malware crew, where she served as a programmer and wrote code for controlling the malware and deploying ransomware on infected computers.

APT28

Collaborative research between Advanced Intelligence (AdvIntel) and Eclypsium has discovered that the TrickBot malware now has functionality designed to inspect the UEFI/BIOS firmware of targeted systems. This new functionality, which we have dubbed “TrickBoot,” makes use of readily available tools to check devices for well-known vulnerabilities that can allow attackers to read, write, or erase the UEFI/BIOS firmware of a device.

Overdose

Collaborative research between Advanced Intelligence (AdvIntel) and Eclypsium has discovered that the TrickBot malware now has functionality designed to inspect the UEFI/BIOS firmware of targeted systems. This new functionality, which we have dubbed “TrickBoot,” makes use of readily available tools to check devices for well-known vulnerabilities that can allow attackers to read, write, or erase the UEFI/BIOS firmware of a device.

Necurs

In cases where the geolocation matches a set list... this request led to the download of Trickbot as we used a UK based exit point.

FIN7

Overlaps were also found with TrickBot, Ryuk/Conti, FIN7, and TrueBot (also known as Silence.Downloader) malware operations

UNC2686

The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT.

GREYVIBE

WithSecure found connections between GREYVIBE’s tooling and both the TrickBot gang and UAC-0098, a group previously linked to Russian cybercriminal networks.

INDRIK SPIDER

...sanctions against the Russian hackers allegedly connected to a single network behind the Conti and Ryuk ransomware variants, as well as the infamous Trickbot banking trojan...

Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Trickbot, a modular malware platform

PISTACHE TEMPEST

Selon MICROSOFT, les opérateurs de PISTACHE TEMPEST auraient également utilisé le code malveillant TrickBot et le MaaS GoziAT [14].

RomCom

The relationship between Russian Intelligence organizations and various Russian cybercriminal groups, such as a partnership between RomCom and Trickbot, essentially functions as a modern-day privateer model.

Lunar Spider

"...the U.S. Federal Bureau of Investigation (FBI) issued an alert warning of attacks involving WIZARD SPIDER’s TrickBot leading to ransomware infections..."

TA542

Distribution of Qbot affiliate “partner01” as the primary payload delivered by Emotet instead of The Trick.

Ryuk

"...shares code and forensic markers with other malware from the Trickbot family..."

Cardinal

“Members of the group are alleged to have connections with… the Trickbot banking Trojan.”

FIN6

"AdFind Command Activity" ... "The AdFind tool has been observed in Trickbot, Ryuk, Maze, and FIN6 campaigns."

Exploited software

Vulnerabilities linked to TrickBot

7 CVEs

MITRE ATT&CK

TrickBot in ATT&CK

125 distinct techniques

Techniques

125 techniques
T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer T1204.002 Malicious File T1204 User Execution T1566 Phishing T1036 Masquerading T1021 Remote Services T1566.002 Spearphishing Link T1542 Pre-OS Boot T1003 OS Credential Dumping T1056.001 Keylogging T1497.001 System Checks T1071 Application Layer Protocol T1548.002 Bypass User Account Control T1018 Remote System Discovery T1059.001 PowerShell T1555 Credentials from Password Stores T1078.001 Default Accounts T1486 Data Encrypted for Impact T1056 Input Capture T1027 Obfuscated Files or Information T1057 Process Discovery T1132 Data Encoding T1059.005 Visual Basic T1041 Exfiltration Over C2 Channel T1053.005 Scheduled Task T1005 Data from Local System T1112 Modify Registry T1555.003 Credentials from Web Browsers T1562.001 Disable or Modify Tools T1082 System Information Discovery T1140 Deobfuscate/Decode Files or Information T1016 System Network Configuration Discovery T1587.001 Malware T1071.001 Web Protocols T1008 Fallback Channels T1055 Process Injection T1573 Encrypted Channel T1059 Command and Scripting Interpreter T1620 Reflective Code Loading T1539 Steal Web Session Cookie T1053 Scheduled Task/Job T1090 Proxy T1568 Dynamic Resolution T1210 Exploitation of Remote Services T1070 Indicator Removal T1570 Lateral Tool Transfer T1083 File and Directory Discovery T1543 Create or Modify System Process T1560 Archive Collected Data T1033 System Owner/User Discovery T1106 Native API T1046 Network Service Discovery T1055.012 Process Hollowing T1069 Permission Groups Discovery T1543.003 Windows Service T1562 Impair Defenses T1135 Network Share Discovery T1552.002 Credentials in Registry T1547.001 Registry Run Keys / Startup Folder T1078 Valid Accounts T1219 Remote Access Tools T1547 Boot or Logon Autostart Execution T1564.003 Hidden Window T1070.004 File Deletion T1021.001 Remote Desktop Protocol T1110 Brute Force T1190 Exploit Public-Facing Application T1027.013 Encrypted/Encoded File T1218.010 Regsvr32 T1218 System Binary Proxy Execution T1133 External Remote Services T1098.004 SSH Authorized Keys T1119 Automated Collection T1566.003 Spearphishing via Service T1558.003 Kerberoasting T1204.001 Malicious Link T1218.011 Rundll32 T1021.002 SMB/Windows Admin Shares T1059.007 JavaScript T1114 Email Collection T1047 Windows Management Instrumentation T1584.005 Botnet T1496 Resource Hijacking T1090.003 Multi-hop Proxy T1649 Steal or Forge Authentication Certificates T1185 Browser Session Hijacking T1059.003 Windows Command Shell T1068 Exploitation for Privilege Escalation T1213.002 Sharepoint T1056.003 Web Portal Capture T1657 Financial Theft T1584.008 Network Devices T1007 System Service Discovery T1553.002 Code Signing T1056.004 Credential API Hooking T1589 Gather Victim Identity Information T1218.005 Mshta T1571 Non-Standard Port T1482 Domain Trust Discovery T1027.002 Software Packing T1189 Drive-by Compromise T1552.001 Credentials In Files T1203 Exploitation for Client Execution T1573.001 Symmetric Cryptography T1565 Data Manipulation T1087.003 Email Account T1537 Transfer Data to Cloud Account T1207 Rogue Domain Controller T1558 Steal or Forge Kerberos Tickets T1187 Forced Authentication T1132.001 Standard Encoding T1497 Virtualization/Sandbox Evasion T1559 Inter-Process Communication T1087.001 Local Account T1528 Steal Application Access Token T1003.006 DCSync T1590 Gather Victim Network Information T1001 Data Obfuscation T1547.009 Shortcut Modification T1213 Data from Information Repositories T1569.002 Service Execution T1568.002 Domain Generation Algorithms T1197 BITS Jobs T1552 Unsecured Credentials

Reporting

Research mentioning TrickBot

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

Aug 12
Hookphish

Ransomware Group clop Hits: LARGAN.COM.TW

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.