New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs
ID: 2ac0a3ce-ad8d-5cf3-b548-a49ddd27cf8d
STIX ID: report--2ac0a3ce-ad8d-5cf3-b548-a49ddd27cf8d
Feed Name: HackRead
Threat Score
Fortinet’s FortiGuard Labs identified a TrickBot variant that abuses DNS tunneling (using requests to westurn.in via 8.8.8.8) to receive commands and download modules, enabling remote code execution, PowerShell use, process injection, and persistent startup via disguised scheduled tasks and NTFS Alternate Data Streams; defenders should monitor unusually long DNS queries, unfamiliar subdomains, scheduled tasks, PowerShell activity, and process injection indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
