Trickbot Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
36
occurrences
First Seen
October 23, 2025
Last Seen
July 23, 2026

Related Threat Clusters

  • Operation Endgame Disrupts Evil Corp's SocGholish Malware Network

    On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…

    67 articles · Updated June 18, 2026
  • EU Sanctions Russia Over Ongoing Cyber Espionage Campaign

    The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…

    172 articles · Updated July 13, 2026
  • MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

    In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…

    16 articles · Updated July 22, 2026
  • EU Sanctions Vitaly Kovalev, Ransomware Leader of Trickbot Group

    On July 14, 2026, the European Union, in coordination with the U.S. and U.K., sanctioned Vitaly Nikolayevich Kovalev, known as 'Stern,' a key figure in the Trickbot ransomware syndicate. Kovalev is linked to over $300…

    4 articles · Updated July 15, 2026
  • FishMonger Expands SprySOCKS Malware to Windows with Kernel-Level Stealth

    ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS,…

    12 articles · Updated June 16, 2026
  • Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers

    A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…

    7 articles · Updated July 1, 2026
  • Old UEFI Shims Exploit Bypass of Secure Boot Security

    ESET researchers have discovered 11 outdated UEFI shim bootloaders, all version 0.9 or below, that can bypass UEFI Secure Boot protections on systems trusting Microsoft's 2011 certificate. These vulnerabilities allow…

    14 articles · Updated July 14, 2026
  • TrickBot Malware Adopts DNS Tunneling for Command-and-Control Communication

    A new variant of TrickBot has been identified using DNS tunneling instead of HTTP for command-and-control (C2) communication. This shift allows the malware to conceal its traffic within malformed DNS queries, making…

    3 articles · Updated July 22, 2026
  • Surge in Account Takeover Fraud Threatens Organizations

    Account takeover (ATO) fraud has surged dramatically, with a reported 354% increase in cases and $13 billion in losses in 2023. This type of cybercrime involves unauthorized access to legitimate user accounts through…

    2 articles · Updated April 29, 2026
  • Ukrainian National Pleads Guilty in Conti Ransomware Case

    Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian national, pleaded guilty to conspiracy to commit wire fraud related to the Conti ransomware operation. This group was responsible for over 1,000 attacks…

    17 articles · Updated June 12, 2026

Recent Intelligence Reports

  • 003 — attack.mitre.org · July 23, 2026
  • Inside A Trickbot Variant Using Dns Tunneling For C2 — www.fortinet.com · July 23, 2026
  • TrickBot variant uses DNS tunneling for command and control | brief — Scworld · July 22, 2026
  • TrickBot Ditches HTTP for DNS Tunneling in Latest Variant — Infosecurity-Magazine · July 22, 2026
  • EU Sanctions 'Stern,' Trickbot Ransomware Leader Tied to $300M — Blockchain.News · July 16, 2026
  • The EU sanctions "the most active ransomware operator in history" Stern, involved in over ... — Chaincatcher · July 15, 2026
  • “Stern” Ransomware Operator Sanctioned by EU — Chainalysis · July 14, 2026
  • EU imposes sanctions on 9 Russians and 4 companies over cyberattacks — Pravda.Ua · July 14, 2026

CVSS v3.1 Breakdown