logo

TrickBot: Ono! New Tricks!

ID: 805f889a-82ac-5dda-92c5-a4f867c3342c

STIX ID: report--805f889a-82ac-5dda-92c5-a4f867c3342c

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

The report analyzes a TrickBot 'onoXX' campaign that uses hashbusting .php loaders, shifts toward fileless module loading on Windows 10, and, instead of typical ransomware follow-up, drops an XMR cryptominer via self-extracting RAR payloads. The authors provide runtime behavior, persistence mechanisms, script and binary filenames, MD5/SHA-like hashes, extracted miner configuration, and actionable IOCs to aid detection and incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.