New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs
Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs.
Modular banking trojan used for credential theft and as a precursor to Ryuk/Conti ransomware deployment.
Also known as: trickbot, trick bot, trickster
Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs.
This TrickBot variant, detailed in research by Fortinet's FortiGuard Labs, utilizes a modular architecture but features a redesigned transport layer.
New TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP pattern
FortiGuard Labs analyzes a TrickBot variant that uses DNS tunneling for C2 communication, modular execution, and employs persistence and obfuscation techniques