TrickBot is a modular Windows banking trojan first observed in 2016 that evolved into a credential-theft, network-compromise, and malware-delivery platform. It became a prominent component of ransomware infection chains, particularly those involving Ryuk and Conti, providing initial access and supporting post-exploitation activity before ransomware deployment.
TrickBot downloads additional modules from command-and-control infrastructure to perform banking fraud, credential theft, system discovery, and lateral movement. Its banking functionality includes fraudulent website redirection, web injection, and form grabbing. Other modules steal browser credentials, cookies, autofill data, browsing history, saved application passwords, and domain credentials. It collects host information, enumerates computers and network devices, and transmits stolen information over HTTP and HTTPS. Its propagation modules abuse SMB and LDAP, use harvested credentials, and exploit EternalBlue and EternalRomance to move through vulnerable Windows networks.
TrickBot is distributed through malicious email campaigns containing links or macro-enabled Microsoft Office attachments and has also been delivered as a secondary payload by Emotet. Campaigns have impersonated familiar accounting and financial brands and used COVID-19 themes. The malware establishes scheduled-task persistence, checks for sandbox environments, attempts to disable antivirus protection, injects code into legitimate processes using native Windows APIs, and disguises executable payloads with document icons. Its operators have used compromised MikroTik routers as command-and-control proxies to obscure infrastructure and redirect traffic through non-standard ports.
TrickBot has been used in Wizard Spider operations and historically distributed by Storm-0324. Its operation became closely integrated with Conti, including overlapping personnel and Conti's acquisition of the TrickBot operation. Microsoft and partners disrupted TrickBot infrastructure in October 2020, and infrastructure associated with the family was also targeted during Operation Endgame in May 2024.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
TrickBot spread through the EternalBlue SMB flaw, so patch Windows and disable SMBv1. | TrickBot is a modular trojan that appeared in 2016 as a banking trojan and became a staging platform for ransomware, especially Ryuk and Conti.
TabDll – Uses the EternalRomance exploit (CVE-2017-0147) to spread via SMBv1.
Exploiting CVE-2018-14847 on devices with RouterOS versions older than 6.42. This vulnerability gives the attacker the ability to read arbitrary files like user.dat, which contains passwords.
In Microsoft’s December 14, 2021, Patch Tuesday vulnerability release, security patches were released for a high severity zero-day vulnerability impacting the Windows AppX installer. The vulnerability is tracked as CVE-2021-43890 (CVSS: 7.1). Exploitation allows a threat actor to create a malicious file that appears to be a legitimate application. Exploitation in the wild has been observed in the delivery of multiple malware types including: Emotet, Trickbot, and BazarLoader. | Exploitation in the wild has been observed in the delivery of multiple malware types including: Emotet, Trickbot, and BazarLoader.
the seller offered two types of weaponized Microsoft Office documents (maldocs) to users: one that exploits a known vulnerability in Microsoft Office (CVE-2017-8570) and another that uses a malicious macro.
In August, Microsoft Threat Intelligence Center (MSTIC) identified a small number of attacks (less than 10) that attempted to exploit a remote code execution vulnerability in MSHTML using specially crafted Microsoft Office documents. These attacks used the vulnerability, tracked as CVE-2021-40444, as part of an initial access campaign that distributed custom Cobalt Strike Beacon loaders. | Additionally, some of the infrastructure that hosted the oleObjects utilized in the August 2021 attacks abusing CVE-2021-40444 were also involved in the delivery of BazaLoader and Trickbot payloads — activity that overlaps with a group Microsoft tracks as DEV-0193.
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
25 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TrickBot is a modular trojan that appeared in 2016 as a banking trojan and became a staging platform for ransomware, especially Ryuk and Conti.
TrickBot has used an email with an Excel sheet containing a malicious macro to deploy the malware
“Prior to this threat, Storm-0324 had the following range of payload distribution: ... Trickbot.”
Drawing inspiration from Dyre (or Dyreza), Trickbot consists of an ecosystem of plugin modules and helper components.
"1359593325": "TrickBot/SmokeLoader/Nobelium/APT29 - Stats uniques -> ips/hostnames: 256 publickeys: 183"
However, also in 2017, it was observed delivering the Trojan.Trickybot and Ransom.UmbreCrypt ransomware.
46 distinct techniques documented for this family, organized by ATT&CK tactic.
1,743 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Steals credentials, maps networks, and moves laterally to prepare ransomware deployment. The article describes operator overlap with Conti, exploitation-based propagation, and assistance in rebuilding Emotet after its takedown.
Mentioned as part of the historical WIZARD SPIDER/SystemBC lineage and a single possible JA3 fingerprint detection, not as a confirmed payload in this operation.
Malware managed by the Russian group experts linked to the Ryuk ransomware gang; no further capabilities are described in the content.
The content identifies TrickBot as malware managed by the Russian group tied to the Ryuk ransomware operation; no further capabilities are provided.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.