TrickBot is a Russian-linked organized cybercrime group and malware ecosystem best known for the TrickBot banking trojan, which emerged in 2016 and evolved into a modular intrusion platform used for banking fraud, credential theft, enterprise compromise, and ransomware enablement. The group is widely associated with the industry cluster name Wizard Spider and has been linked to the development or operation of related tooling including Anchor, BazarLoader/BazarBackdoor, and Diavol. Over time, TrickBot shifted from targeting retail banking customers to targeting corporate networks, blending commodity malware distribution with hands-on-keyboard post-compromise activity more typical of mature intrusion crews. TrickBot initially focused on stealing online banking credentials and used webinjects against financial institutions, including banks in Australia, New Zealand, the United Kingdom, Germany, and Canada. It later expanded into a broader malware-as-a-service and access-broker model, adding modules for browser credential theft, mail and web-history collection, Active Directory and domain-controller reconnaissance, SMB propagation, RDP brute forcing, Outlook and POS-related theft, and proxy/backconnect capability. Reporting also describes renewed development of its banking functionality through updated webinject modules influenced by Zeus-style techniques and sharing code similarities with IcedID components. The group is strongly associated with enterprise intrusions that use phishing, malicious Office documents and macros, second-stage delivery via other botnets such as Emotet, and lateral movement inside victim environments. Once established, operators have used Cobalt Strike, PowerShell Empire, Metasploit, BloodHound, ADFind, PowerView, Mimikatz, LaZagne, and similar tooling for reconnaissance, credential theft, privilege escalation, persistence, and lateral movement. Documented behaviors include LSASS dumping, theft of browser and Windows credential stores, collection of Kerberos material, overpass-the-hash, SMB and WMI-based movement, domain trust enumeration, and compromise of domain controllers including NTDS extraction. TrickBot malware and associated loaders also employ defense evasion measures such as runtime string and API decryption, dynamic API resolution, process injection, crypters, and UAC bypass techniques including abuse of legitimate Windows binaries. TrickBot infections have frequently served as a precursor to ransomware deployment. The ecosystem has been repeatedly linked to Ryuk and Conti operations, and U.S. government reporting formally linked Diavol to the TrickBot Group. Anchor, a TrickBot-derived framework, has been described as a stealthier post-exploitation and persistence platform for higher-value enterprise victims, supporting long-term access, cleanup, and targeted data extraction. TrickBot-associated operations have also been tied to data exfiltration and extortion-oriented intrusions, further blurring the line between banking malware, access brokerage, and ransomware operations. Victimology is global. High-confidence reporting shows targeting of financial institutions and broad enterprise sectors worldwide, with notable impact on healthcare, government, and other large organizations. The group has infected victims across many countries and has been observed supporting follow-on ransomware attacks against hospitals, municipalities, emergency services, and commercial enterprises. Known aliases and associated names include TrickBot Group, TrickBot operators, and Wizard Spider. Related subprojects or malware families commonly tied to the ecosystem include Anchor, BazarLoader/BazarBackdoor, and Diavol.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
392 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercrime group behind the TrickBot malware, providing Conti with remote access and initial access at scale before being effectively absorbed into Conti's operation.
Mentioned only as a group Bentley was affiliated with; not a primary subject of the content.
Crimeware operators using the TrickBot malware framework, with the mexec module acting as a loader/downloader to deliver tertiary malware, enable pivoting inside compromised enterprise networks, and evade detection.
Cybercriminal syndicate conducting large-scale ransomware campaigns across essential services including healthcare and banking; associated with Ryuk, Conti, and multiple offshoot ransomware operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.