Infosecurity-Magazine
TrickBot Malware Adopts DNS Tunneling for Command-and-Control Communication
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A new variant of TrickBot has been identified using DNS tunneling instead of HTTP for command-and-control (C2) communication. This shift allows the malware to conceal its traffic within malformed DNS queries, making detection more challenging. FortiGuard Labs reported that this variant maintains its modular architecture, enabling it to download and execute additional malicious modules. The malware persists on infected systems by leveraging the Windows Task Scheduler, creating tasks that run every few minutes. This adaptation highlights the ongoing evolution of TrickBot, which previously faced significant disruption from a 2020 takedown effort. The malware's ability to encrypt commands and disguise its traffic poses a high risk to Windows users. The research indicates that the malware can transfer data at a rate of approximately 30.7 KB per second. Organizations are advised to enhance their DNS security measures to mitigate the risks associated with this variant.
Key Points: • TrickBot has transitioned from HTTP to DNS tunneling for C2 communication. • The malware maintains persistence using the Windows Task Scheduler, creating tasks every few minutes. • This variant can transfer data at a rate of approximately 30.7 KB per second, increasing its stealth.