Malware.View on attack.mitre.org
TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
TrickBot collects local files and information from the victim’s local machine. |
| T1007 System Service Discovery |
TrickBot collects a list of install programs and services on the system’s machine. |
| T1008 Fallback Channels |
TrickBot can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers. |
| T1016 System Network Configuration Discovery |
TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine. |
| T1018 Remote System Discovery |
TrickBot can enumerate computers and network devices. |
| T1021.005 VNC |
TrickBot has used a VNC module to monitor the victim and collect information to pivot to valuable systems on the network |
| T1027 Obfuscated Files or Information |
TrickBot uses non-descriptive names to hide functionality. |
| T1027.002 Software Packing |
TrickBot leverages a custom packer to obfuscate its functionality. |
| T1027.013 Encrypted/Encoded File |
TrickBot uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files. |
| T1033 System Owner/User Discovery |
TrickBot can identify the user and groups the user belongs to on a compromised host. |
| T1036 Masquerading |
The TrickBot downloader has used an icon to appear as a Microsoft Word document. |
| T1041 Exfiltration Over C2 Channel |
TrickBot can send information about the compromised host and upload data to a hardcoded C2 server. |
| T1053.005 Scheduled Task |
TrickBot creates a scheduled task on the system that provides persistence. |
| T1055 Process Injection |
TrickBot has used |
| T1055.012 Process Hollowing |
TrickBot injects into the svchost.exe process. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.