TrickBot was updated to abuse Windows User Account Control on multiple versions of Windows, letting the malware launch with elevated privileges without showing a visible prompt. Researchers reported that the trojan used the fodhelper.exe auto-elevation technique on Windows 10 and CMSTPLUA on Windows 7, then quickly shifted to a newer Windows 10 bypass that abused wsreset.exe through registry changes under HKCU\Software\Classes. The changes allowed TrickBot to run more quietly, evade user suspicion, and weaken host defenses while maintaining administrative access.
The malware’s expanded privilege-escalation capability supported a broader credential-theft and post-compromise toolkit already seen in earlier TrickBot campaigns. Fortinet’s analysis of the pwgrab module showed TrickBot stealing saved passwords, browser data, autofill information, and credentials from applications including Outlook, FileZilla, and WinSCP, while persisting through scheduled tasks and exfiltrating data over HTTP. Reporting also noted TrickBot’s ability to spread laterally, target Active Directory data on domain controllers, and provide access that could later be used to deploy Ryuk ransomware.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
The January 2020 article notes that BleepingComputer reported in September 2019 that the GootKit banking trojan added the Windows 10 Fodhelper UAC bypass. GootKit used it to run a command that whitelisted the malware's path in Windows Defender.
BleepingComputer's January 2020 reporting says TrickBot had previously targeted Windows Defender by attempting to disable various scan options in July 2019. This marked an earlier effort by the malware to weaken Windows 10 security protections.
FortiGuard Labs collected a TrickBot sample on October 19, 2018 that arrived via a malicious Excel document named "Sep_report.xls." The malware downloaded TrickBot, installed itself under %AppData%\VsCard, persisted with a scheduled task named "Msnetcs," and requested the new pwgrab module from C2.
Fortinet's analysis states the TrickBot pwgrab32 credential-stealing module examined in the report was generated on October 16, 2018. The module was built to steal browser, email, and file-transfer credentials from infected systems.
ReaQta discovered that TrickBot changed its Windows 10 privilege-escalation method to abuse wsreset.exe instead of fodhelper.exe. By writing a command under the AppX registry path, TrickBot could execute itself with elevated privileges without displaying a UAC prompt.
SentinelLabs researcher Vitali Kremez discovered a TrickBot sample that used the trusted Windows binary fodhelper.exe to bypass UAC on Windows 10 without showing a prompt. The malware selected CMSTPLUA on Windows 7 and Fodhelper on Windows 10 to launch itself with elevated privileges more stealthily.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 29 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcefortinet.com
Open sourceactivecyber.us
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.