Trojan
TrickBot
First seen: 2016-10 • Status: inactive
Currently Inactive
TrickBot was once the Swiss Army knife of malware - it could steal banking credentials, spread through networks, and open doors for ransomware. It was behind countless Ryuk and Conti ransomware attacks. After years of law enforcement action and the Russia-Ukraine conflict impacting the group, TrickBot finally shut down. But its people moved to other malware operations.
Overview
TrickBot was one of the most sophisticated modular banking trojans that evolved into a major initial access broker for ransomware operations. After multiple law enforcement takedowns and internal issues, the TrickBot operation wound down in 2024. Many of its developers and affiliates migrated to other operations.
Also Known As
Trickster, TrickLoader, TheTrick
How It Spreads
- • Malspam campaigns with Office documents
- • Emotet malware delivering TrickBot
- • Exploit kits
- • Network propagation using EternalBlue
- • Compromised websites
What It Does
- • Stole banking credentials via web injection
- • Provided access for Ryuk and Conti ransomware
- • Spread through networks using multiple modules
- • Harvested credentials from browsers and applications
- • Collected Active Directory information
- • Disabled Windows Defender and security tools
Is your business exposed?
Target Platforms
Windows 7, Windows 10, Windows 11
Detection Tips
- • Monitor for TrickBot persistence in scheduled tasks
- • Detect web injection behavior in browser processes
- • Alert on attempts to disable Windows Defender
- • Watch for lateral movement using EternalBlue
- • Monitor for gtag parameters in C2 communications
MITRE ATT&CK Techniques
T1185, T1055, T1003, T1562.001, T1210
If You're Infected
- 1.
Note: TrickBot is largely inactive but remnants may exist
- 2.
Isolate infected systems and check for ransomware indicators
- 3.
Patch EternalBlue vulnerability (MS17-010) across environment
- 4.
Remove TrickBot modules and persistence mechanisms
- 5.
Reset domain admin and service account credentials
- 6.
Hunt for successor malware (BazarLoader, Anchor)
Related Malware
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required