ATT&CKReferencesEclypsium Trickboot December 2020

Eclypsium Trickboot December 2020

Eclypsium, Advanced Intelligence. (2020, December 1). TRICKBOT NOW OFFERS ‘TRICKBOOT’: PERSIST, BRICK, PROFIT. Retrieved March 15, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareTrickBot

TrickBot gathers the OS version, machine name, CPU type, amount of RAM available, and UEFI/BIOS firmware information from the victim’s machine.

T1495
Firmware Corruption
MalwareTrickBot

TrickBot module "Trickboot" can write or erase the UEFI/BIOS firmware of a compromised device.

T1542.003
Bootkit
MalwareTrickBot

TrickBot can implant malicious code into a compromised device's firmware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.