U.S. Cyber Command and Microsoft led parallel efforts to disrupt the TrickBot botnet, a major criminal infrastructure used to distribute ransomware and viewed as a potential threat to U.S. election security. Microsoft said it disabled 120 of 128 identified servers through court orders and coordination with hosting providers, ISPs, and international partners, while U.S. officials described a separate military operation intended to temporarily knock the botnet off balance and force its operators to spend time rebuilding rather than launching attacks. Earlier reporting had already shown TrickBot expanding beyond banking malware into large-scale email abuse through its TrickBooster module, which harvested credentials and contacts, sent spam from compromised accounts, and was tied to a database containing roughly 250 million harvested email addresses.
The disruption did not eliminate the threat. Incident responders documented a late-2020 intrusion in which TrickBot operators manually deployed malware, used Cobalt Strike for privilege escalation and lateral movement, dumped LSASS and NTDS.dit, and conducted extensive Active Directory reconnaissance consistent with a likely Ryuk ransomware attack path. By the end of 2021, reporting indicated that the Conti ransomware group had absorbed key TrickBot personnel and become the botnet’s primary user, with plans to shift initial access operations toward BazarBackdoor. The FBI also linked Diavol ransomware to the TrickBot group, underscoring how the operation persisted after takedowns and continued to serve as a core access and development hub for multiple ransomware campaigns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
The BleepingComputer report says Diavol switched in November from ransom notes named README_FOR_DECRYPT.txt to notes named Warning.txt.
The FBI said it first became aware of Diavol ransomware in October 2021, beginning the bureau's tracking of the operation and its indicators of compromise.
FortiGuard Labs released an analysis of Diavol ransomware in July 2021, documenting similarities with Conti that helped establish early technical links to TrickBot-associated tooling.
In early June 2021, FortiGuard Labs observed Diavol and Conti ransomware payloads deployed on the same network during a ransomware attack. The overlap later contributed to reporting on links between Diavol and TrickBot-associated operations.
AdvIntel reported that by the end of 2021, the Conti ransomware group had effectively acquired control of TrickBot, absorbing key developers and managers. The report said Conti became the sole end-user of TrickBot's botnet and planned to replace the aging malware with BazarBackdoor for initial access.
The DFIR Report analyzed a late-December 2020 intrusion attributed to Trickbot actors in which attackers manually executed Trickbot, used Cobalt Strike for privilege escalation and lateral movement, dumped LSASS and NTDS.dit, and conducted extensive Active Directory reconnaissance. The report assessed the likely intended end state was domain-wide Ryuk ransomware deployment.
As of October 18, Microsoft and partners said they had disabled 120 of 128 Trickbot infrastructure servers worldwide, including 62 of 69 original core servers and all but one of 59 replacement servers. Microsoft said the operators were scrambling to rebuild and shifting effort toward restoration rather than fresh attacks.
After Microsoft's coalition-led disruption effort on Monday, TrickBot operators replaced seized command-and-control servers and domains by the following day, with researchers describing the impact as temporary. Reporting also said TrickBot began moving command-and-control infrastructure to the EmerDNS decentralized DNS system during the recovery.
Security Affairs states that TrickBot has existed since October 2016, describing it as a Windows banking Trojan that later evolved with additional capabilities.
The FBI issued a Flash advisory formally linking the Diavol ransomware operation to the TrickBot Group, also known as Wizard Spider, and shared indicators of compromise and mitigations from prior attacks.
Microsoft announced a disruption operation against Trickbot using court orders and coordination with hosting providers, ISPs, and partners to disable infrastructure tied to ransomware delivery. The company said the action was intended to hinder attacks through the U.S. election period.
In recent weeks before the October 9, 2020 report, U.S. Cyber Command conducted an operation to temporarily disrupt the Trickbot botnet. Officials said the goal was to distract the Russian-speaking operators and reduce ransomware-related election risk rather than permanently dismantle the botnet.
After Deep Instinct notified DigiCert/Thawte about code-signing certificates abused by TrickBot and TrickBooster samples, the certificate authority revoked the offending certificates.
Deep Instinct reported an active TrickBot campaign using the new TrickBooster module to harvest email credentials and contacts, send malicious spam from compromised accounts, and delete evidence from mail folders. The investigation also recovered a database containing about 250 million harvested email addresses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
securityaffairs.co
Open sourcebleepingcomputer.com
Open sourcethedfirreport.com
Open sourceblogs.microsoft.com
Open sourceeset.com
Open sourcewashingtonpost.com
Open sourcedeepinstinct.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.