TrickBot Emerges with a Few New Tricks
ID: 4d0df7e4-34c8-5c33-99fa-6dda77a1ad15
STIX ID: report--4d0df7e4-34c8-5c33-99fa-6dda77a1ad15
Feed Name: Zscaler Security Research Blog
This Zscaler ThreatLabZ report analyzes the TrickBot banking trojan (first seen 2016), detailing its common infection vectors (LNK/script/Office document downloaders), modular architecture and modules (credential stealing, lateral movement, VNC, RDP brute-force), C2 communication patterns (numeric IPs, SSL/TLS, specific request paths), operational relationships with other malware (Emotet, Ryuk, AnchorBot) and recent capability additions (rdpScanDll, Android MFA bypass), and recommends defensive actions such as SSL inspection and blocking known downloaders and C2 activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
