Skip to content
TrickBot Malware Adopts DNS Tunneling for Command-and-Control Communication

TrickBot Malware Adopts DNS Tunneling for Command-and-Control Communication

First seen 22 Jul 2026, 15:26 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 23, 2026 at 14:55 UTC
  • TrickBot has transitioned from HTTP to DNS tunneling for C2 communication.
  • The malware maintains persistence using the Windows Task Scheduler, creating tasks every few minutes.
  • This variant can transfer data at a rate of approximately 30.7 KB per second, increasing its stealth.

A new variant of TrickBot has been identified using DNS tunneling instead of HTTP for command-and-control (C2) communication. This shift allows the malware to conceal its traffic within malformed DNS queries, making detection more challenging. FortiGuard Labs reported that this variant maintains its modular architecture, enabling it to download and execute additional malicious modules. The malware persists on infected systems by leveraging the Windows Task Scheduler, creating tasks that run every few minutes. This adaptation highlights the ongoing evolution of TrickBot, which previously faced significant disruption from a 2020 takedown effort. The malware's ability to encrypt commands and disguise its traffic poses a high risk to Windows users. The research indicates that the malware can transfer data at a rate of approximately 30.7 KB per second. Organizations are advised to enhance their DNS security measures to mitigate the risks associated with this variant.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 50d ago How this analysis works

Timeline

2020-10-01
TrickBot botnet takedown
Microsoft coordinated a takedown of the TrickBot botnet, disrupting over one million infections.
Infosecurity-Magazine
2026-07-22
New TrickBot variant identified
FortiGuard Labs reported a TrickBot variant using DNS tunneling for C2 communication, enhancing its evasion techniques.
Fortinet

More articles in this cluster (3)

Following this threat?

Track Trickbot in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed