Trojan

TrickBot

First seen: 2016-10 • Status: inactive

Currently Inactive

TrickBot was once the Swiss Army knife of malware - it could steal banking credentials, spread through networks, and open doors for ransomware. It was behind countless Ryuk and Conti ransomware attacks. After years of law enforcement action and the Russia-Ukraine conflict impacting the group, TrickBot finally shut down. But its people moved to other malware operations.

Overview

TrickBot was one of the most sophisticated modular banking trojans that evolved into a major initial access broker for ransomware operations. After multiple law enforcement takedowns and internal issues, the TrickBot operation wound down in 2024. Many of its developers and affiliates migrated to other operations.

Also Known As

Trickster, TrickLoader, TheTrick

How It Spreads

  • Malspam campaigns with Office documents
  • Emotet malware delivering TrickBot
  • Exploit kits
  • Network propagation using EternalBlue
  • Compromised websites

What It Does

  • Stole banking credentials via web injection
  • Provided access for Ryuk and Conti ransomware
  • Spread through networks using multiple modules
  • Harvested credentials from browsers and applications
  • Collected Active Directory information
  • Disabled Windows Defender and security tools

Is your business exposed?

Target Platforms

Windows 7, Windows 10, Windows 11

Detection Tips

  • Monitor for TrickBot persistence in scheduled tasks
  • Detect web injection behavior in browser processes
  • Alert on attempts to disable Windows Defender
  • Watch for lateral movement using EternalBlue
  • Monitor for gtag parameters in C2 communications

MITRE ATT&CK Techniques

T1185, T1055, T1003, T1562.001, T1210

If You're Infected

  1. 1.

    Note: TrickBot is largely inactive but remnants may exist

  2. 2.

    Isolate infected systems and check for ransomware indicators

  3. 3.

    Patch EternalBlue vulnerability (MS17-010) across environment

  4. 4.

    Remove TrickBot modules and persistence mechanisms

  5. 5.

    Reset domain admin and service account credentials

  6. 6.

    Hunt for successor malware (BazarLoader, Anchor)

Related Malware

Emotet, Bazarloader, Ryuk, Conti

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required