TrickBot Malware Adopts DNS Tunneling for Command-and-Control Communication

TrickBot Malware Adopts DNS Tunneling for Command-and-Control Communication

First seen 22 Jul 2026, 15:26 UTC Infosecurity-Magazinewww.fortinet.com 84% similarity 69.5

Article Content

Browse articles
ThreatCluster

A new variant of TrickBot has been identified using DNS tunneling instead of HTTP for command-and-control (C2) communication. This shift allows the malware to conceal its traffic within malformed DNS queries, making detection more challenging. FortiGuard Labs reported that this variant maintains its modular architecture, enabling it to download and execute additional malicious modules. The malware persists on infected systems by leveraging the Windows Task Scheduler, creating tasks that run every few minutes. This adaptation highlights the ongoing evolution of TrickBot, which previously faced significant disruption from a 2020 takedown effort. The malware's ability to encrypt commands and disguise its traffic poses a high risk to Windows users. The research indicates that the malware can transfer data at a rate of approximately 30.7 KB per second. Organizations are advised to enhance their DNS security measures to mitigate the risks associated with this variant.

Key Points: • TrickBot has transitioned from HTTP to DNS tunneling for C2 communication. • The malware maintains persistence using the Windows Task Scheduler, creating tasks every few minutes. • This variant can transfer data at a rate of approximately 30.7 KB per second, increasing its stealth.

ThreatCluster AI

Timeline

2020-10-01
TrickBot botnet takedown
Microsoft coordinated a takedown of the TrickBot botnet, disrupting over one million infections.
Infosecurity-Magazine
2026-07-22
New TrickBot variant identified
FortiGuard Labs reported a TrickBot variant using DNS tunneling for C2 communication, enhancing its evasion techniques.
Fortinet

Community

Browse all →