logo

Rapid Response: TrickBoot | Huntress

ID: d04a1382-560d-58f3-a134-8fce6bc5775e

STIX ID: report--d04a1382-560d-58f3-a134-8fce6bc5775e

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

**Executive Summary:** Huntress reports that the TrickBot malware has acquired a new module named TrickBoot which targets firmware/UEFI to discover and exploit firmware write/read capabilities, enabling persistent bootkit implants that survive OS wipes and can potentially brick devices or support ransomware; the report provides indicators (e.g., randomly named scheduled tasks like "AdvancedLocTechnic", the RWEverything driver rwdrv.sys, module names such as injectDll32/injectDll64), an attack chain (Emotet dropper -> scheduled tasks -> module download -> TrickBoot firmware operations), and recommended mitigations including email security, least privilege, firmware/UEFI patching, and detection for misuse of legitimate drivers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.