Trickbot recovered from a major 2020 disruption campaign and continued operating as a modular malware platform tied to credential theft, lateral movement, brute forcing, proxying, and ransomware delivery. Microsoft said its court-backed operation with hosting providers, ISPs, and industry partners disabled 120 of 128 identified Trickbot servers, including most core infrastructure, while the remaining systems included compromised IoT devices used for command-and-control. Despite that action, operators rapidly worked to restore infrastructure, and later reporting described Trickbot activity in 149 countries, with more than 140,000 observed victims and 223 campaigns over six months.
Researchers said the botnet evolved well beyond its banking Trojan origins into a flexible post-compromise framework linked to Ryuk, Conti, BazarBackdoor, and Anchor, with modules for Active Directory theft, browser interception, spam propagation, network scanning, RDP and OWA brute forcing, SQL discovery, and worm-like spread using EternalBlue and EternalRomance. In late 2021, Trickbot also began distributing Emotet again, helping drive the malware’s return after its takedown; observed infection chains used password-protected ZIP archives and malicious Excel files that launched PowerShell to download payloads into C:\ProgramData, underscoring the botnet’s continued role as a high-risk loader for follow-on malware and ransomware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
Check Point Research reported that Trickbot began dropping Emotet samples again in November 2021, marking Emotet's return roughly 10 months after its takedown.
An FBI advisory released on September 22, 2021 described Trickbot as one of the means used to deliver Conti ransomware to victims and said Conti had affected around 400 organizations worldwide.
The Trickbot campaign identified as "zem1" was observed from September 13 to September 15 and used 64 IP addresses.
An ITG23 developer associated with the Trickbot malware ecosystem was arrested in February 2021. The article presents the arrest as a setback the group later recovered from as it continued operations.
Emotet was taken down in January 2021 through a joint operation involving law enforcement agencies and judicial authorities worldwide.
As of October 18, Microsoft and partners said they had disabled 120 of 128 Trickbot infrastructure servers worldwide, including 62 of 69 original core servers and nearly all replacement servers.
Microsoft announced a disruption operation against Trickbot in October 2020, using court orders and coordination with partners, hosting providers, and ISPs to disable the botnet's infrastructure.
In 2020, Trickbot and Emotet were used to deliver Ryuk ransomware, linking both botnets to major ransomware operations.
The Lazarus Group was reportedly observed in December 2019 using the Trickbot Anchor Project framework, a backdoor module deployed to selected high-profile victims.
A database containing 250 million email addresses used by Trickbot operators in campaigns was discovered in July 2019.
Trickbot was first discovered in October 2016 and was described as a successor to the Dyre banking Trojan, initially focused on stealing online banking data.
Dyre, the banking Trojan that Trickbot later succeeded, was active from 2014 to 2016 and used man-in-the-browser attacks to steal banking credentials.
Check Point Research said 129 of 223 different Trickbot campaigns observed in the prior six months ceased activity in July.
The Trickbot campaign identified as "zev4" was first seen on July 26 and used 79 IP addresses, remaining active at the time of reporting.
5 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourcesecurityintelligence.com
Open sourcesecurelist.com
Open sourceblogs.microsoft.com
Open sourcenetscout.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.