TrickBot, also referred to as The Trick, is a modular Windows banking trojan that evolved into a broader crimeware platform used for credential theft, post-compromise access, and malware delivery. First observed in 2016 and widely distributed from 2017 onward, it has been associated with large-scale financially motivated email campaigns and has frequently appeared as a second-stage payload delivered by other malware ecosystems including Emotet, Buer, and Ostap-based infection chains. It has also been distributed directly by prolific cybercrime actors such as TA505 and by affiliate-style distributors including TA800.
TrickBot is best known for banking-trojan functionality, but operational reporting shows it has also served as an initial-access malware family in intrusion chains that later led to ransomware deployment. In criminal operations, infections with TrickBot have been linked to access brokerage and follow-on deployment of tools and payloads used for data theft, lateral movement, and enterprise compromise. Reporting has associated TrickBot-enabled access with ransomware ecosystems including Conti and Ryuk-related activity, although there is no exclusive one-to-one mapping between TrickBot and any single ransomware operation.
Observed delivery methods include phishing emails carrying malicious Office documents with macros, HTML attachments, password-protected documents, compressed script attachments, and malicious links. Campaigns have used topical and localized social-engineering lures, including invoice and transaction themes, political themes, and coronavirus-related messaging. In some campaigns, enabling macros triggered downloaders such as Ostap, which then retrieved TrickBot. Emotet has also repeatedly delivered TrickBot as a follow-on payload, and TA505 historically used geo-targeted logic to selectively deliver TrickBot to victims in specific countries.
TrickBot primarily targets Windows systems. Its role in the threat landscape extends beyond online banking fraud: it has functioned as a flexible malware platform within multi-stage intrusion chains, enabling persistence, credential theft, and broader post-exploitation activity that can culminate in high-impact enterprise attacks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These criminal threat actors compromise victim organizations with first-stage malware like The Trick, Dridex, or Buer Loader and will then sell their access to ransomware operators to deploy data theft and encryption operations.
These criminal threat actors compromise victim organizations with first-stage malware like The Trick, Dridex, or Buer Loader and will then sell their access to ransomware operators to deploy data theft and encryption operations.
The Trick, also known as Trickbot, is another banking Trojan that TA505 first began distributing in June of 2017.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The Trick is mentioned as a historical payload previously distributed by Emotet.
A banking trojan used as a first-stage payload and initial access facilitator; access obtained through it is sold or used to enable follow-on ransomware deployment.
A modular banking trojan and malware loader, Trickbot is used for credential theft, lateral movement, and as a delivery mechanism for other malware, including ransomware.
The Trick is identified as a second-stage payload observed after Emotet infection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.