Rapid Response: TrickBoot | Huntress
ID: d04a1382-560d-58f3-a134-8fce6bc5775e
STIX ID: report--d04a1382-560d-58f3-a134-8fce6bc5775e
Feed Name: Huntress Blog
**Executive Summary:** Huntress reports that the TrickBot malware has acquired a new module named TrickBoot which targets firmware/UEFI to discover and exploit firmware write/read capabilities, enabling persistent bootkit implants that survive OS wipes and can potentially brick devices or support ransomware; the report provides indicators (e.g., randomly named scheduled tasks like "AdvancedLocTechnic", the RWEverything driver rwdrv.sys, module names such as injectDll32/injectDll64), an attack chain (Emotet dropper -> scheduled tasks -> module download -> TrickBoot firmware operations), and recommended mitigations including email security, least privilege, firmware/UEFI patching, and detection for misuse of legitimate drivers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
