Skip to content

TrickBot

TrickBot is a modular Windows malware family that emerged as a banking trojan and evolved into a broad criminal malware platform used for credential theft, post-compromise control, lateral movement, and delivery of additional payloads including ransomware.

Profile source: Mallory opens in a new tab

TrickBot

Family profile

TrickBot is a modular Windows malware family that emerged as a banking trojan and evolved into a broad criminal malware platform used for credential theft, post-compromise control, lateral movement, and delivery of additional payloads including ransomware. It has long been associated with the TrickBot cybercrime ecosystem and with actors linked to Wizard Spider and later Conti-related operations. The malware has also been connected in public reporting to Ryuk-linked intrusion activity and to broader Russian cybercrime support networks targeted by sanctions.

TrickBot is notable for its extensible architecture and its ability to download and execute additional modules after initial compromise. Reported capabilities include theft of Outlook and browser data, execution of Windows commands and PowerShell, DLL execution through signed Windows utilities, direct execution of downloaded code, and process injection techniques including process hollowing and process doppelgänging. It has also been observed modifying the Windows Registry and using encoded PowerShell for persistence and lateral movement.

On Windows systems, TrickBot has demonstrated multiple persistence and defense-evasion mechanisms. Observed variants create recurring scheduled tasks to relaunch the malware, store task metadata in NTFS Alternate Data Streams, encrypt internal strings, and resolve APIs dynamically at runtime using hash-based lookups to hinder static analysis. Separate samples have used API hammering and delayed execution to overwhelm or evade sandbox instrumentation before injecting into legitimate Windows processes.

A more covert variant replaced earlier HTTP-based command-and-control with DNS tunneling. In that design, outbound command data is encrypted, encoded into malformed DNS queries, and inbound tasking or module data is reconstructed from values embedded in DNS responses. This transport allows TrickBot traffic to blend into routine DNS activity while preserving enough throughput for sustained command exchange and module delivery.

TrickBot has been distributed by other malware, notably Emotet, which has served as a downloader for TrickBot in phishing-driven infection chains. Across its evolution, TrickBot has remained one of the most significant modular crimeware platforms in the Windows ecosystem, bridging banking trojan functionality with enterprise intrusion, credential theft, stealthy persistence, and ransomware enablement.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 27, 2026
Last activity
Jul 27, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • CO1

Leading providers

  • UNE EPM TELECOMUNICACIONES S.A.1

Samples

Recent associated samples

Reported operators

Threat actors

18 named in public reporting
WIZARD SPIDER

Ce dernier est recherché par la police allemande et considéré comme impliqué dans le botnet TrickBot et Wizard Spider.

UNC2686

The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT.

GREYVIBE

WithSecure found connections between GREYVIBE’s tooling and both the TrickBot gang and UAC-0098, a group previously linked to Russian cybercriminal networks.

TA505

The most notorious among these are campaigns involving banking Trojans such as Dridex and TrickBot, ransomware such as Clop/Cryptomix and MINEBRIDGE...

Indrik Spider

...sanctions against the Russian hackers allegedly connected to a single network behind the Conti and Ryuk ransomware variants, as well as the infamous Trickbot banking trojan...

Trickbot

Threat actors use BazarLoader and Trickbot to deploy the Ryuk or Conti ransomware, while IcedID has been used in the past to deploy the now-defunct Maze and Egregor ransomware infections.

Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Trickbot, a modular malware platform

PISTACHE TEMPEST

Selon MICROSOFT, les opérateurs de PISTACHE TEMPEST auraient également utilisé le code malveillant TrickBot et le MaaS GoziAT [14].

RomCom

The relationship between Russian Intelligence organizations and various Russian cybercriminal groups, such as a partnership between RomCom and Trickbot, essentially functions as a modern-day privateer model.

TA551

In November 2021, Cybereason revealed that the operators of the TrickBot trojan were teaming up with TA551 to distribute Conti Ransomware.

Lunar Spider

"...the U.S. Federal Bureau of Investigation (FBI) issued an alert warning of attacks involving WIZARD SPIDER’s TrickBot leading to ransomware infections..."

TA800

"TA800... is an affiliate distributor of the The Trick, also known as Trickbot, and BazaLoader."

TA542

Distribution of Qbot affiliate “partner01” as the primary payload delivered by Emotet instead of The Trick.

Ryuk

"...shares code and forensic markers with other malware from the Trickbot family..."

Conti

Conti ransomware ... is a ransomware operation ... known for other notorious malware infections, such as TrickBot. The ransomware gang usually gains access to a network through BazarLoader or TrickBot malware infections installed via phishing attacks...

Cardinal

“Members of the group are alleged to have connections with… the Trickbot banking Trojan.”

Gold Dupont

Malware like Vatet loader, PyXie, Trickbot, and RansomExx, as well as some post-intrusion tools like Cobalt Strike, are typically part of this threat group’s arsenal.

FIN6

"AdFind Command Activity" ... "The AdFind tool has been observed in Trickbot, Ryuk, Maze, and FIN6 campaigns."

Exploited software

Vulnerabilities linked to TrickBot

4 CVEs

MITRE ATT&CK

TrickBot in ATT&CK

118 distinct techniques

Techniques

118 techniques
T1059.001 PowerShell T1218.011 Rundll32 T1055.002 Portable Executable Injection T1059 Command and Scripting Interpreter T1564.003 Hidden Window T1053.005 Scheduled Task T1071.004 DNS T1055.005 Thread Local Storage T1105 Ingress Tool Transfer T1572 Protocol Tunneling T1055.013 Process Doppelgänging T1027 Obfuscated Files or Information T1055 Process Injection T1059.003 Windows Command Shell T1071 Application Layer Protocol T1564.004 NTFS File Attributes T1055.012 Process Hollowing T1027.007 Dynamic API Resolution T1132 Data Encoding T1486 Data Encrypted for Impact T1547.001 Registry Run Keys / Startup Folder T1082 System Information Discovery T1112 Modify Registry T1497 Virtualization/Sandbox Evasion T1106 Native API T1021.002 SMB/Windows Admin Shares T1555 Credentials from Password Stores T1543.003 Windows Service T1053.003 Cron T1547 Boot or Logon Autostart Execution T1083 File and Directory Discovery T1087 Account Discovery T1204.002 Malicious File T1016 System Network Configuration Discovery T1071.001 Web Protocols T1140 Deobfuscate/Decode Files or Information T1033 System Owner/User Discovery T1069 Permission Groups Discovery T1021 Remote Services T1078 Valid Accounts T1587.001 Malware T1090.003 Multi-hop Proxy T1005 Data from Local System T1057 Process Discovery T1041 Exfiltration Over C2 Channel T1562 Impair Defenses T1059.005 Visual Basic T1566 Phishing T1570 Lateral Tool Transfer T1560 Archive Collected Data T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link T1003 OS Credential Dumping T1027.013 Encrypted/Encoded File T1555.003 Credentials from Web Browsers T1056 Input Capture T1204 User Execution T1074 Data Staged T1219 Remote Access Tools T1059.004 Unix Shell T1021.001 Remote Desktop Protocol T1574.013 KernelCallbackTable T1497.001 System Checks T1558 Steal or Forge Kerberos Tickets T1210 Exploitation of Remote Services T1018 Remote System Discovery T1555.001 Keychain T1056.003 Web Portal Capture T1539 Steal Web Session Cookie T1185 Browser Session Hijacking T1003.001 LSASS Memory T1090.002 External Proxy T1046 Network Service Discovery T1059.007 JavaScript T1027.006 HTML Smuggling T1649 Steal or Forge Authentication Certificates T1056.004 Credential API Hooking T1564 Hide Artifacts T1482 Domain Trust Discovery T1189 Drive-by Compromise T1553.002 Code Signing T1548.002 Bypass User Account Control T1574.011 Services Registry Permissions Weakness T1562.001 Disable or Modify Tools T1068 Exploitation for Privilege Escalation T1568.002 Domain Generation Algorithms T1003.003 NTDS T1003.002 Security Account Manager T1053 Scheduled Task/Job T1027.002 Software Packing T1666 Modify Cloud Resource Hierarchy T1090 Proxy T1480.001 Environmental Keying T1573.001 Symmetric Cryptography T1657 Financial Theft T1036 Masquerading T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1590.005 IP Addresses T1552.001 Credentials In Files T1555.005 Password Managers T1218.005 Mshta T1559 Inter-Process Communication T1218.010 Regsvr32 T1497.003 Time Based Checks T1008 Fallback Channels T1007 System Service Discovery T1559.001 Component Object Model T1110.004 Credential Stuffing T1552.002 Credentials in Registry T1571 Non-Standard Port T1021.005 VNC T1087.001 Local Account T1542.003 Bootkit T1495 Firmware Corruption T1135 Network Share Discovery T1087.003 Email Account T1132.001 Standard Encoding T1203 Exploitation for Client Execution

Reporting

Research mentioning TrickBot

Jul 27
Cyber Security News

Hackers Can Use MedusaHVNC to Control Your PC on a Desktop You Cannot See

Researchers detailed MedusaHVNC, a malware-as-a-service remote access trojan that gives attackers covert control of infected Windows systems by creating an invisible desktop and launching legitimate browsers outside the victim’s view. The malware lets operators abuse the victim’s existing browser profiles, cookies, and live authenticated sessions, making malicious activity appear to come from the user’s own device. Analysts said the payload supports typical hidden VNC functions including screen capture, synthetic keyboard and mouse input, window interaction, and clipboard access, with references to Chrome, Edge, and Firefox. Analysis of a recent sample found a five-stage infection chain starting with wscript.exe running an obfuscated JScript launcher, followed by files dropped into the TEMP directory, persistence via a Startup-folder batch file, and AutoIt-based components that inject a loader into charmap.exe before unpacking the final unsigned 64-bit payload. The malware contains the MedusaHVNC family string and communicates over a custom TCP protocol with a hard-coded command-and-control server at 51.89.204.28:4444. Researchers said defenders should focus on outbound traffic monitoring, blocking known infrastructure and file hashes, and watching for unexpected data exfiltration because stolen information must still leave the network.

Jul 27
Security Week

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection - SecurityWeek

Jul 27
Blackfog

MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions | BlackFog

Jul 23
Cyber Security News

TrickBot Turns Ordinary DNS Traffic Into a Hidden Channel for Malware Commands

Researchers identified a TrickBot variant for Microsoft Windows that replaces its usual HTTP command-and-control channel with a custom DNS tunneling mechanism, allowing the malware to hide outbound tasking in malformed DNS queries and reconstruct inbound data from IPv4 addresses returned in DNS responses. Fortinet said the malware sends XOR-encrypted, hex-encoded command data in chunks designed to resemble legitimate domain labels, with traffic observed via 8.8.8.8 and a command-and-control domain of westurn.in. The transport redesign preserves TrickBot’s modular architecture while making communications harder to detect and block. The malware maintains persistence through Windows Task Scheduler, with tasks configured to run every five minutes, and stores task metadata in NTFS Alternate Data Streams to reduce visibility. Fortinet reported the variant also uses encrypted strings and hash-based runtime API resolution to complicate analysis, while retaining capabilities for module download, rundll32-based execution, PowerShell execution, direct machine-code execution, process hollowing, and process doppelgänging. Researchers measured the DNS tunnel at roughly 30.7 KB/s, indicating the channel is practical for sustained covert command-and-control operations.

Jul 23
Hackread

New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs

Jul 23
Gurucul Threat Research

Inside a TrickBot Variant Using DNS Tunneling for C2 | Community Portal | Gurucul

Jul 22
Scworld

TrickBot variant uses DNS tunneling for command and control | brief | SC Media

Jul 22
Fortinet Threat Research

Inside a TrickBot Variant Using DNS Tunneling for C2 | FortiGuard Labs

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.