TrickBot, also known as the TrickBot Group or TrickBot operators, is a financially motivated cybercrime organization associated with the development and operation of the TrickBot malware platform. Its operators are also tracked under the industry designation Wizard Spider, which encompasses closely connected TrickBot and Conti ransomware operations. The organization developed a network of malware developers, infrastructure operators, and intrusion specialists that compromised millions of computers worldwide. First observed in 2016, TrickBot began as banking malware and a successor to Dyre before evolving into a modular malware-as-a-service and initial-access platform. Early banking targets included Australia, followed by New Zealand, the United Kingdom, Germany, and Canada. Its subsequent operations affected enterprises globally. Initial access commonly involved phishing messages, malicious Office macros, and delivery through Emotet. Its modules supported browser and banking credential theft, Active Directory discovery, network scanning, SMB propagation, RDP brute forcing, and data exfiltration. Operators also used Windows UAC bypasses, remote-control modules, multiple persistence mechanisms, and security-tool impairment. TrickBot enabled hands-on-keyboard intrusions using Cobalt Strike, PowerShell Empire, Metasploit, Mimikatz, LaZagne, ADFind, and BloodHound. Operators maintained access to compromised networks, collected valuable information, and transferred access to ransomware operators, notably those deploying Ryuk and Conti. Related development included the Bazar malware family and Anchor, a framework for targeted post-exploitation, persistent access, and data extraction from high-value enterprise environments. TrickBot survived a coordinated infrastructure disruption in October 2020 and helped restore Emotet distribution in November 2021. Its operators overlapped substantially with Conti, which absorbed developers and managers by late 2021. New TrickBot campaigns declined sharply around the beginning of 2022. The United States and United Kingdom sanctioned group members in 2023.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
22 malware families attributed to this actor across reporting.
17 additional families tracked in Mallory.
464 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The explicitly identified TrickBot group operated a banking-trojan and malware-loader ecosystem used for credential theft and ransomware staging. Its operators overlapped heavily with Conti. The article describes infrastructure disruptions, sanctions, and criminal investigations involving the group.
Cybercrime group behind the TrickBot malware, providing Conti with remote access and initial access at scale before being effectively absorbed into Conti's operation.
Mentioned only as a group Bentley was affiliated with; not a primary subject of the content.
Crimeware operators using the TrickBot malware framework, with the mexec module acting as a loader/downloader to deliver tertiary malware, enable pivoting inside compromised enterprise networks, and evade detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.