TrickBot emerged as a banking trojan linked to post-Dyre criminal activity and was initially distributed through spam campaigns that installed intermediary loaders before fetching the malware from command-and-control infrastructure. Over time, operators expanded delivery methods to include malicious links, macro-enabled Word documents, ZIP archives with shortcut files, and phishing chains involving loaders such as Smoke Loader and Godzilla Loader. Researchers documented TrickBot copying itself into %AppData%\Roaming, using download-and-execute tasking, stealing browser passwords, form data, banking information, and system details, and in at least one case deploying an XMRig Monero miner alongside its core modules.
Network and intrusion analysis showed TrickBot using distinctive HTTPS/TLS command-and-control traffic on ports 443, 447, and 449, HTTP exfiltration on port 8082, and disguised payload retrieval through .png URLs that actually served Windows executables. The malware was also observed moving laterally in Active Directory environments via an EternalBlue-based SMB exploit and frequently serving as an initial access platform for Cobalt Strike and ransomware including Ryuk and Conti. By 2021 and early 2022, researchers reported a shift in the ecosystem as TrickBot was used to deliver Emotet and Qbot, while fresh TrickBot campaigns declined, suggesting operators were monetizing remaining infections and transitioning toward newer malware platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
The Hacker News reports that no new TrickBot activity had been recorded since the start of 2022, indicating campaigns had largely stalled. Researchers assessed that the malware was likely being phased out in favor of other platforms, even as some C2 infrastructure remained active.
The last set of attacks involving TrickBot was registered on December 28, 2021, according to the report cited by The Hacker News. The article uses this as the last dated campaign activity before the subsequent lull.
Intel 471 observed TrickBot delivering Qbot to compromised systems shortly after Emotet returned in November 2021. The report said this suggested a behind-the-scenes shake-up or migration toward other malware platforms.
The Hacker News reports that attacks first observed in November 2021 used TrickBot to download and execute Emotet binaries, reversing the earlier relationship where Emotet often dropped TrickBot. Intel 471 cited this as evidence of a major operational shift.
The TA551-related TrickBot download pattern changed from "/bdfh/" to "/bmdff/" around mid-August 2021, according to the malware analysis. This reflects an operational change in the delivery infrastructure.
The Hacker News says TA551 began delivering TrickBot in phishing campaigns starting in June 2021 using encrypted ZIP attachments containing macro-enabled documents. Those documents dropped HTA files, downloaded TrickBot DLLs, and executed them via regsvr32.exe.
A Malware-Traffic-Analysis examination of a TrickBot infection chain on 2018-02-01 found behavior similar to prior TrickBot activity but with an added Monero cryptocurrency mining component identified as XMRig. The infection chain ran from email to malicious link to Word document to macro execution to Smoke Loader to TrickBot.
Unit 42 states that TrickBot had been infecting victims since 2016. This marks the start of the malware family's observed activity in the source material.
The NETSCOUT ASERT report says TrickBot emerged after the November 2015 takedown of Dyreza/Dyre infrastructure, which had previously been tied to arrests by Russian authorities. The report presents this as the backdrop for early TrickBot activity.
The ASERT report says early TrickBot activity involved limited initial targeting, including a small number of Australian banks. It presents this as a characteristic of the malware's early operations.
ASERT describes an early spam campaign using the subject "You have received a new fax" and a malicious attachment, fax198-203-9153.scr, which installed Godzilla Loader. Godzilla Loader then downloaded TrickBot from 185.14.29[.]13/api.php.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
arbornetworks.com
Open sourcemalware-traffic-analysis.net
Open sourcethehackernews.com
Open sourcethehackernews.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.