logo

TrickBot Disguises Scheduled Task as Wireshark Update to Maintain Windows Persistence

ID: 73cf8855-96dd-5e51-8dc7-244eb8c45efe

STIX ID: report--73cf8855-96dd-5e51-8dc7-244eb8c45efe

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Varshini

...
...

**Executive Summary:** FortiGuard researchers analyzed a TrickBot variant that hides C2 traffic inside malformed DNS requests to westurn.in, establishes persistence by creating Windows Scheduled Tasks disguised as "Wireshark autoupdate #<random_number>", and employs string encryption, API-hash resolution, and other anti-analysis techniques; the report includes technical TTPs and IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.