Researchers and government agencies reported that TrickBot continued to evolve from a banking trojan into a modular crimeware platform used for credential theft, lateral movement, data exfiltration, and delivery of follow-on malware including Ryuk and Conti ransomware. Observed delivery chains included spearphishing lures themed as COVID-19 alerts, invoices, and traffic violations, with victims receiving encrypted Word macro documents or downloading malicious JavaScript from compromised websites. In one campaign, password-protected .docm files used an AutoOpen macro to extract hidden VBScript, write a .VBE file to C:\ProgramData, rebuild a TrickBot DLL, decode it with certutil, and execute it through regsvr32.exe, helping the malware evade static and behavioral detection.
TrickBot operators also updated internal tooling and infrastructure to improve stealth and spread. Palo Alto Networks documented the replacement of the older mworm propagation module with nworm, which fetched an encrypted payload over HTTP and executed it in memory on vulnerable Active Directory domain controllers, reducing forensic artifacts and avoiding persistence after reboot. Other reporting tied TrickBot infrastructure to leaked configuration data and IP addresses associated with MikroTik routers, suggesting use of compromised network devices in command-and-control operations. Across the reporting, defenders were urged to hunt for campaign-specific gtag identifiers, Office encryption artifacts, characteristic byte-level document changes, suspicious SMB activity including exploitation of CVE-2017-0144, and phishing-driven execution chains that lead to TrickBot installation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
HP Wolf Security says a stealthy TrickBot malspam campaign began on 16 September 2020, using COVID-19 alert and invoice lures with encrypted DOCM attachments tagged with gtag "ono76."
Unit 42 lists propagation URLs including /ico/VidT6cErs for nworm and /images/cursor.png and /images/imgpaper.png for mshare and tab, all first seen on 2020-04-20.
In April 2020, Unit 42 observed TrickBot stop using the mworm module in lab infections and replace it with a new propagation module called nworm, which fetched encrypted or encoded payloads and executed them in memory on domain controllers.
Unit 42 says that since February 2020, propagation-related URLs used IP addresses rather than domains, with distinct path patterns for mshare, mworm, and tab payload retrieval.
Unit 42 reports that starting in September 2019, TrickBot propagation to vulnerable Active Directory domain controllers used the mworm, mshare, and tab modules.
HP Wolf Security says that since June 2019, TrickBot has also been used to distribute post-exploitation tools and Ryuk ransomware, especially against large enterprises.
HP Wolf Security states TrickBot was first seen in 2014, while later CISA and Splunk references describe it as first identified or active since 2016 as a banking Trojan and crimeware platform.
CISA and the FBI issued a Joint Cybersecurity Advisory stating that TrickBot continued targeting victims in North America through spearphishing campaigns using traffic-infringement lures and malicious JavaScript downloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
splunk.com
Open sourceus-cert.cisa.gov
Open sourcethreatresearch.ext.hp.com
Open sourceen.wikipedia.org
Open sourceunit42.paloaltonetworks.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.