TrickBot is a Russia-based cybercriminal syndicate and malware ecosystem best known for operating the TrickBot banking trojan and for its central role in large-scale ransomware intrusion activity. Over time, TrickBot evolved from a modular banking malware operation into a broader criminal enterprise that provided initial access, post-compromise tooling, credential theft, reconnaissance, lateral movement, and malware delivery capabilities for follow-on extortion campaigns. The group is widely associated with the deployment and enablement of Ryuk and later Conti ransomware, and has also been linked to BazarLoader, SystemBC, IcedID, Diavol, and related criminal tooling. The actor is commonly referred to as TrickBot and is also tracked by some vendors and governments as Wizard Spider. TrickBot has targeted a wide range of sectors internationally, including financial institutions, enterprises, schools, government entities, and healthcare organizations. It was notably implicated in ransomware activity affecting hospitals and healthcare providers, including during the COVID-19 period. Reporting has also linked TrickBot-associated activity to systematic targeting of Ukraine and to operations whose targeting aligned at times with Russian state interests. The group’s tradecraft includes phishing-based initial access, malware distribution partnerships, modular payload delivery, credential theft, Active Directory reconnaissance, domain trust discovery, network configuration discovery, and enterprise-wide propagation. Documented behaviors include use of native Windows utilities and administrative discovery commands consistent with ATT&CK techniques such as System Network Configuration Discovery and Domain Trust Discovery. TrickBot operators also developed mobile malware to bypass banking two-factor authentication, demonstrating capability beyond Windows intrusions. TrickBot functioned not only as a malware family but as an organized criminal network with leadership, administrators, developers, and affiliates. Public law-enforcement actions and sanctions have identified Russian national Vitaly Nikolaevich Kovalev, also known as Stern, as a senior figure and founder or leader of the TrickBot group. Multiple members have been sanctioned or placed on wanted lists by Western governments. The syndicate is closely intertwined with the Conti operation; Conti is widely assessed to have been developed and operated by members of the TrickBot gang, with substantial overlap in personnel, infrastructure, and operational management. Following pressure from takedowns, sanctions, leaks, and arrests, the broader network fragmented and rebranded across successor ransomware and malware operations rather than disappearing outright. TrickBot has also maintained relationships with other criminal service providers and distribution actors. It has been linked to partnerships with spam and phishing operators such as TA551, and to broader access-and-delivery ecosystems that enabled ransomware deployment at scale. Some reporting and government assessments further indicate that key TrickBot members likely maintained links to Russian intelligence or benefited from selective protection within the Russian cybercriminal environment, although the precise nature of those relationships is not fully public. Overall, TrickBot is best understood as both a malware platform and a long-running Russian cybercrime organization that helped shape the modern ransomware ecosystem through its integration of banking malware, access brokerage, loader operations, and enterprise ransomware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercriminal syndicate conducting large-scale ransomware campaigns across essential services including healthcare and banking; associated with Ryuk, Conti, and multiple offshoot ransomware operations.
Cybercriminal gang associated with the TrickBot malware ecosystem and linked in the article to Conti-related criminal operations.
A malware syndicate closely tied to Conti; associated Russian nationals were sanctioned and charged for attacks against more than 900 victims worldwide.
Cybercriminal group referenced here because GREYVIBE tooling showed connections to it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.