Researchers tied multiple malware components to TrickBot-associated operations, including a custom loader that fetched encoded payloads from GitHub files disguised as images and launched a 64-bit Cobalt Strike beacon directly in memory. The loader manually resolved APIs from ntdll.dll and kernel32.dll, loaded wininet.dll, and used HTTPS command-and-control on port 443, with beacon configuration pointing to rainbowmango.info subdomains and gpupdate.exe configured as a spawn-to process. Separate analysis of TrickLoader, the TrickBot framework’s loader component, showed years of increasing obfuscation, including hidden resource names, custom Base64 schemes, compressed payloads, function-table reconstruction, and anti-analysis techniques such as UAC bypass and Heaven’s Gate.
Additional reporting linked a newer Krypton/Xenon crypter and related data-exfiltration malware to the same ecosystem through a distinctive string-encoding pattern ending in mOrxx that had previously appeared in TrickBot tooling. Unpacked samples contained references to Mimikatz, a proof-of-concept for CVE-2020-0787, and downloads from raw.githubusercontent.com, while the exfiltration malware used WinINet APIs to upload stolen data to hard-coded uploadFile.php endpoints and also enumerated processes and collected desktop and window information. Investigators identified infrastructure including temp.positiveseca.com, se1.buttonrich.com, figures.pablotech.info, and files.pablotech.info, reinforcing links between TrickBot loaders, post-exploitation tooling, and data-theft activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
In 2018, TrickLoader added a user account control bypass, Heaven’s Gate techniques, function obfuscation, and further hid its configuration data.
In 2017, TrickLoader started obfuscating its resource section name and using a custom Base64 scheme for strings as part of its anti-analysis evolution.
SentinelLabs analyzed TrickLoader and recovered a 32-bit TrickBot binary plus embedded configuration after decompression and deobfuscation. The extracted config included version 1000480, gtag tot598, autorun modules, and multiple command-and-control servers on ports 443 and 449.
The same Krypton/Xenon research identified recent data exfiltrator malware samples apparently named "file_sender" based on an unstripped PDB path. The samples used WinINet APIs and hard-coded domains or IPs with uploadFile.php endpoints to send stolen data.
Walmart Global Tech examined a newer Krypton crypter variant, also called Xenon, and linked it to recent data exfiltrator samples through the same distinctive string encoding ending in "mOrxx." The analysis showed the crypter protecting payloads including Mimikatz, a CVE-2020-0787 proof of concept, and GitHub-downloaded content.
During analysis of the TrickBot-linked loader, researchers found that one GitHub account previously used to host the payload had been deleted, which they assessed may indicate actor cleanup after campaign use.
Walmart Global Tech analyzed a new loader tied to an actor involved in TrickBot Cobalt Strike and ransomware operations. The loader fetched encoded payloads from GitHub-hosted files masquerading as images and ultimately launched a 64-bit Cobalt Strike beacon in memory.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 92 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
4 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourceblog.reversinglabs.com
Open sourcemedium.com
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.