Skip to main content
Mallory
4 malware families

Trickbot

Also known asTrickBot

TrickBot is a Russia-based cybercrime gang and malware operation active since at least 2016. It is also referred to as Wizard Spider in the provided content. The group has been linked to a broader criminal network behind TrickBot, Conti, and Ryuk, and reporting in the content also associates it with Diavol and Karakurt. Authorities in the United States and the United Kingdom sanctioned seven individuals allegedly behind TrickBot, and U.S. and U.K. assessments cited in the content state that current or key TrickBot members maintain links to Russian intelligence services. The content also notes targeting that aligned with Russian state objectives, including systematic attacks on Ukraine and targeting of the International Olympic Committee. Operationally, TrickBot is described as a modular banking trojan that evolved into a malware delivery platform and botnet used to spread ransomware. It has infected millions of computers and has been used to deploy Ryuk and Conti ransomware; the content also states it partnered with ransomware groups to deploy Ryuk, Conti, Diavol, and Karakurt. TrickBot targeted hospitals and healthcare centers in the United States during the COVID-19 pandemic. The group has also worked with TA551 in phishing campaigns that deployed Conti ransomware, and BazarLoader and TrickBot infections are described as believed to be created by the same TrickBot hacking group. The malware family associated with TrickBot performs reconnaissance including system network configuration discovery and domain trust discovery using commands such as ipconfig /all, net config workstation, net view /all /domain, and nltest /domain_trusts. TrickBot also developed and used the TrickMo Android malware to bypass banking two-factor authentication by intercepting OTP, mTAN, and pushTAN codes, abusing Android accessibility services, forwarding and deleting SMS messages, resisting uninstallation, and persisting after reboot. The content further links TrickBot to other parts of the cybercrime ecosystem. WithSecure found connections between GREYVIBE tooling and the TrickBot gang, including suspected ties through an ISO builder also linked to UAC-0098. Treasury reporting cited in the content says Blender.io was used by ransomware gangs including TrickBot, and Treasury sanctions related to Operation Zero highlighted connections between the TrickBot cybercrime gang and that Russian exploit broker. Microsoft obtained an emergency court order in 2020 to disable TrickBot command-and-control IP addresses as part of a disruption effort against the botnet.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics29 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.001
Spearphishing Attachment
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
T1059.007
JavaScript
TA0003
Persistence
1 technique
T1547
Boot or Logon Autostart Execution
TA0004
Privilege Escalation
1 technique
T1547
Boot or Logon Autostart Execution
TA0005
Stealth
4 techniques
T1027
Obfuscated Files or Information
T1070
Indicator Removal
T1497
Virtualization/Sandbox Evasion
T1564
Hide Artifacts
TA0006
Credential Access
3 techniques
T1003
OS Credential Dumping
T1056
Input Capture
T1056.004
Credential API Hooking
T1111
Multi-Factor Authentication Interception
TA0007
Discovery
2 techniques
T1082
System Information Discovery
T1497
Virtualization/Sandbox Evasion
TA0008
Lateral Movement
1 technique
T1570
Lateral Tool Transfer
TA0009
Collection
4 techniques
T1005
Data from Local System
T1056
Input Capture
T1056.004
Credential API Hooking
T1185
Browser Session Hijacking
T1213
Data from Information Repositories
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1105×2
Ingress Tool Transfer
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
TA0040
Impact
3 techniques
T1486×4
Data Encrypted for Impact
T1490
Inhibit System Recovery
T1657
Financial Theft
IOCS

Observables

8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping24

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal4

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables8

Domains, IPs, and hashes tied to this actor, refreshed continuously.