logo

Inside a TrickBot Variant Using DNS Tunneling for C2

ID: 4c8a36dc-fa8b-58a1-a260-e59a59142b1b

STIX ID: report--4c8a36dc-fa8b-58a1-a260-e59a59142b1b

Feed Name: Fortinet Blog

Threat Score
78/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

...
...

This report analyzes a TrickBot malware variant that uses DNS tunneling instead of HTTP for C2, describing its runtime string/API obfuscation, persistence through Windows Task Scheduler and NTFS Alternate Data Streams, packet encoding/fragmentation and IP-based data transport, supported remote commands (including module download and process injection), performance characteristics, and mitigation/IOC details such as the C2 domain (westurn.in), multiple sample SHA-256 hashes, and Fortinet detection signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.