惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

A
About on SuperTechFans
G
Google Developers Blog
L
LangChain Blog
aimingoo的专栏
aimingoo的专栏
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
云风的 BLOG
云风的 BLOG
小众软件
小众软件
月光博客
月光博客
Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理
P
Proofpoint News Feed
博客园 - 聂微东
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
The Cloudflare Blog
博客园_首页
美团技术团队
大猫的无限游戏
大猫的无限游戏
B
Blog
IT之家
IT之家
Jina AI
Jina AI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
C
Check Point Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Something strange is going on with Trickbot
Intel 471 · 2022-02-25 · via Intel 471 Blog

It’s been a turbulent 18 months for Trickbot.

The notorious modular malware has been in the spotlight, largely due to actions taken by both private companies and the U.S. government to thwart the attacks. Even as U.S. Cyber Command and Microsoft seized servers and the U.S. Department of Justice arrested several people alleged to be involved with the group that runs the malware, Trickbot stayed active throughout 2021 with various infection campaigns.

These sporadic periods of activity have not continued into 2022. From December 28, 2021 until February 17, 2022, Intel 471 researchers have not seen new Trickbot campaigns. While there have been lulls from time-to-time, this long of a break can be considered unusual. Our team assesses with high confidence that this break is partially due to a big shift from Trickbot’s operators, including working with the operators of Emotet.

Trickbot’s recent behavior

Examination of individual malware campaigns, tracked by identifiers known as “gtags,” further show there has been a lull in activity since mid-December 2021. These gtags are often listed as a three-letter term followed by a three-number sub-tag that further delineates individual campaigns. Intel 471 researchers tracking “lipXXX” campaigns show that the latest builds, categorized as “lip166,” came on December 28, 2021. That was one of three malware campaigns that were active during the month. As a contrast, eight different “lipXXX” builds were discovered in November 2021.

We found a similar pattern in campaigns with a “topXXX” gtag. The last known build came from the “top166” gtag on December 28, 2021, which was one of three “topXXX” builds in December. Yet eight separate “topXXX” builds were discovered the prior month.

In addition to the unusual disappearance of new builds (gtags), we have also observed that the onboard malware configuration files (mcconf), which contain a list of controller addresses the bot can connect to, have gone untouched for long periods of time. The most recent mcconf version numbers are 100021 (Dec 9) and 2000036 (Oct 25). These were once updated frequently, but are receiving fewer and fewer updates. It should be mentioned that Trickbot can receive controller address list updates on-the-fly, so the lack of updates could mean that there isn’t anyone cleaning up Trickbot controllers nor is there any pressure to update the on-board controller list.

The scarcity of campaigns only tells part of the story. While the campaigns themselves have been quiet, command and control infrastructure tied to Trickbot continues to operate normally, serving additional plugins, web injects and additional configurations to bots in the botnet. This activity shows that while there haven’t been any new campaigns, there is evidence of some effort to maintain Trickbot’s command and control infrastructure, even if that effort is essentially an automated one.

Looking at this holistically, this is unusual behavior, but it’s part of a trend that Intel 471 and other researchers have been observing for several months. The amount of Trickbot campaigns observed by researchers has continuously decreased over time. However, the amount of ransomware deployments of ransomware families linked with Trickbot, such as Conti, has continued. What can we deduce from this behavior?

Trickbot’s new teammates

Our team assesses with high confidence that Trickbot operators are working closely with the operators of Emotet. There is clear evidence of this relationship, for example, the resurrection of Emotet began with Trickbot. On November 14, 2021, we observed Trickbot pushing a command to its bots to download and execute Emotet samples. This marked the beginning of the return of Emotet.

Even before this event, Trickbot and Emotet operators had a relationship. Emotet was often used to drop Trickbot samples until the Emotet takedown. These Trickbot samples often had the gtag “morXXX.” The relationship worked both ways: Intel 471 has observed commands from Trickbot controllers to download and execute Emotet, long before the Emotet’s 2021 return.


Intel 471 cannot confirm, but it’s likely that the Trickbot operators have phased Trickbot malware out of their operations in favor of other platforms, such as Emotet. Trickbot, after all, is relatively old malware that hasn’t been updated in a major way. Detection rates are high and the network traffic from bot communication is easily recognized.

Another crucial piece of the puzzle is the Bazar malware family, which has development ties to the Trickbot group. Multiple threat actors leverage this stealthy backdoor to gain an initial foothold into high-value targets and execute follow-up payloads, such as Cobalt Strike and IcedID aka Bokbot. We have also seen Bazar controllers pushing commands to download and execute Trickbot (mid-2021) and Emotet (November 2021). These events connect Bazar to Trickbot operators, as well as to the revival of Emotet.

Bazar, Bokbot and Emotet likely aren’t the only tools leveraged by the threat actor group ditching Trickbot. Our monitoring registered instances of Trickbot pushing Qbot installs to bots of the Trickbot botnet shortly after the Emotet return from November 2021. This observation is yet another indicator that the Trickbot bots are being migrated to other malware platforms.

DateBot TransferPayload URLNotes
Feb 7, 2020Trickbot -> Emotethttp://66[.]85.173[.]43/59Emotic1.jpgonly morXXX bots received this command
Apr 1, 2020Trickbot -> Emotetnone, payload direct from C2only morXXX bots received this command
Sep 16, 2020Trickbot -> Emotethttp://104[.]193.252[.]221/FortiPlan1.gifonly morXXX bots received this command
Nov 14, 2021Trickbot -> Emotethttp://141[.]94.176[.]124/Loader_90563_1.dllFirst stage of Emotet’s resurrection campaign (bots with all gtags received the command)
Nov 24, 2021Bazar -> Bokbotnone, payload direct from C2Bokbot project ID BA205ACA
Nov 26, 2021Bazar -> Emotetnone, payload direct from C2
Dec 9, 2021Trickbot -> Qbothttp://46[.]30.41[.]173/stager2.dllQbot botnet ng_domain

Avoiding the spotlight

Despite the takedowns by U.S. Cyber Command in October 2020, Trickbot remained active into 2021. However, with the arrests of two alleged Trickbot developers and an in-depth Wired article that details alleged internal conversations from the group’s leadership, Trickbot is under more scrutiny than ever before.

Perhaps a combination of unwanted attention to Trickbot and the availability of newer, improved malware platforms has convinced the operators of Trickbot to abandon it. We suspect that the malware control infrastructure (C2) is being maintained because there is still some monetization value in the remaining bots.

Intel 471 will continue to track Trickbot and will report on any further observations in the future.