logo

TrickBot Emerges with a Few New Tricks

ID: 4d0df7e4-34c8-5c33-99fa-6dda77a1ad15

STIX ID: report--4d0df7e4-34c8-5c33-99fa-6dda77a1ad15

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-09-18

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ report analyzes the TrickBot banking trojan (first seen 2016), detailing its common infection vectors (LNK/script/Office document downloaders), modular architecture and modules (credential stealing, lateral movement, VNC, RDP brute-force), C2 communication patterns (numeric IPs, SSL/TLS, specific request paths), operational relationships with other malware (Emotet, Ryuk, AnchorBot) and recent capability additions (rdpScanDll, Android MFA bypass), and recommends defensive actions such as SSL inspection and blocking known downloaders and C2 activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.