Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The dropper version of mexec is very similar to the downloader except that the payload is carried onboard... Function obfuscation using a table of offsets... The above code is the start of the process of building out the function address table; it jumps over a table of offsets to kick off the process.
Loader used by TrickBot has had continued development related to obfuscation for anti-analysis.
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader component within the TrickBot framework that has undergone continued development focused on anti-analysis and obfuscation. The article describes function-table reconstruction, decoding of embedded objects, and decompression of embedded 32-bit and 64-bit TrickBot payloads.
TrickLoader is described as a similar TrickBot loader whose deobfuscation and functionality overlap with the mexec dropper, though the article notes mexec is not used to deliver TrickBot itself.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.