TrickBot: Ono! New Tricks!
ID: 805f889a-82ac-5dda-92c5-a4f867c3342c
STIX ID: report--805f889a-82ac-5dda-92c5-a4f867c3342c
Feed Name: Binary Defense Blog
Threat Score
The report analyzes a TrickBot 'onoXX' campaign that uses hashbusting .php loaders, shifts toward fileless module loading on Windows 10, and, instead of typical ransomware follow-up, drops an XMR cryptominer via self-extracting RAR payloads. The authors provide runtime behavior, persistence mechanisms, script and binary filenames, MD5/SHA-like hashes, extracted miner configuration, and actionable IOCs to aid detection and incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
