TrickBot

S0266

Malware.View on attack.mitre.org

About this malware

TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.

Techniques used55

Procedure examples55

TechniqueProcedure example
T1005
Data from Local System

TrickBot collects local files and information from the victim’s local machine.

T1007
System Service Discovery

TrickBot collects a list of install programs and services on the system’s machine.

T1008
Fallback Channels

TrickBot can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers.

T1016
System Network Configuration Discovery

TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine.

T1018
Remote System Discovery

TrickBot can enumerate computers and network devices.

T1021.005
VNC

TrickBot has used a VNC module to monitor the victim and collect information to pivot to valuable systems on the network

T1027
Obfuscated Files or Information

TrickBot uses non-descriptive names to hide functionality.

T1027.002
Software Packing

TrickBot leverages a custom packer to obfuscate its functionality.

T1027.013
Encrypted/Encoded File

TrickBot uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files.

T1033
System Owner/User Discovery

TrickBot can identify the user and groups the user belongs to on a compromised host.

T1036
Masquerading

The TrickBot downloader has used an icon to appear as a Microsoft Word document.

T1041
Exfiltration Over C2 Channel

TrickBot can send information about the compromised host and upload data to a hardcoded C2 server.

T1053.005
Scheduled Task

TrickBot creates a scheduled task on the system that provides persistence.

T1055
Process Injection

TrickBot has used Nt* Native API functions to inject code into legitimate processes such as wermgr.exe.

T1055.012
Process Hollowing

TrickBot injects into the svchost.exe process.

View all 55 procedure examples

Groups that use it2

Campaigns0

None recorded.

References4

  1. CrowdStrike Wizard Spider October 2020 Open source
    Podlosky, A., Hanel, A. et al. (2020, October 16). WIZARD SPIDER Update: Resilient, Reactive and Resolute. Retrieved June 15, 2021.
  2. Fidelis TrickBot Oct 2016 Open source
    Reaves, J. (2016, October 15). TrickBot: We Missed you, Dyre. Retrieved August 2, 2018.
  3. IBM TrickBot Nov 2016 Open source
    Keshet, L. (2016, November 09). Tricks of the Trade: A Deeper Look Into TrickBot’s Machinations. Retrieved August 2, 2018.
  4. S2 Grupo TrickBot June 2017 Open source
    Salinas, M., Holguin, J. (2017, June). Evolution of Trickbot. Retrieved July 31, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.