S0266: TrickBot
TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.CitationS2 Grupo TrickBot June 2017CitationFidelis TrickBot Oct 2016CitationIBM TrickBot Nov 2016CitationCrowdStrike Wizard Spider October 2020
Security context for executives and security teams
TrickBot matters because ATT&CK describes it as Windows Trojan spyware that evolved from banking-focused activity into use across sectors as part of “big game hunting” ransomware campaigns. For leaders, the decision value is not just malware blocking; it is whether the organization can recognize the discovery, credential collection, persistence, command-and-control, lateral movement, and exfiltration behaviors that ATT&CK associates with this software before an intrusion becomes a business interruption event.
Executive priority
Prioritize TrickBot as a resilience and incident-readiness scenario for Windows environments. The ATT&CK relationships show behavior spanning credential access, discovery, persistence through scheduled tasks, stealth through obfuscation and process injection, C2 over web protocols and fallback channels, VNC-based lateral movement, and exfiltration over C2. Executives should ask whether SOC monitoring, identity controls, endpoint hardening, and incident response playbooks can produce evidence across these stages, not only whether a malware signature exists.
Technical view
Validate coverage against the ATT&CK techniques linked to TrickBot: Scheduled Task, Process Injection and Process Hollowing, Credential API Hooking, PowerShell, Windows Command Shell, service/process/user/network/system discovery, remote system discovery, permission group discovery, VNC, web-protocol C2, fallback channels, exfiltration over C2, masquerading, and obfuscated/packed/encrypted files. Because the official detection field is not provided, detection engineering should be behavior-led and environment-specific, focused on Windows endpoint activity, process lineage, task creation, suspicious command execution, network egress patterns, and authentication or remote-control activity that aligns with these relationships.
Likely telemetry
- Windows endpoint process creation and parent-child process lineage
- Scheduled task creation, modification, and execution events
- PowerShell and Windows command shell execution logs
- Endpoint alerts or forensic evidence for process injection, process hollowing, packing, obfuscation, and masquerading
- Windows service, process, user, group, system, and network discovery command evidence
Detection direction
- Do not rely only on known TrickBot indicators; the ATT&CK relationships emphasize behaviors that can vary by environment and by malware version.
- Tune detections around suspicious scheduled tasks, unusual PowerShell or cmd execution, discovery bursts, and abnormal child processes from user-facing or system processes.
- Correlate endpoint behavior with outbound web traffic and fallback communication attempts to reduce false positives from legitimate administrative activity.
- Review whether VNC use is expected, inventoried, and monitored; unexpected VNC activity can be material when paired with discovery or credential-access behavior.
- Account for false positives from administrators, software deployment tools, monitoring agents, and legitimate remote support; require context such as process lineage, timing, host role, and user identity.
Mitigation priorities
- Start with visibility: confirm Windows endpoint, command execution, scheduled task, authentication, remote access, and egress telemetry are retained and available to SOC and IR teams.
- Reduce credential exposure by hardening credential handling and monitoring for abnormal credential access patterns consistent with the ATT&CK-linked Credential API Hooking behavior.
- Restrict and monitor administrative scripting, command shell use, scheduled task creation, and remote-control tools such as VNC according to business need.
- Harden egress controls and monitoring for web-protocol C2 and alternate/fallback channels, with escalation paths for suspicious outbound communication from workstations and servers.
- Prepare IR playbooks that treat TrickBot-like behavior as a multi-stage intrusion risk: isolate affected Windows hosts, preserve endpoint and network evidence, assess credential exposure, and hunt for discovery, lateral movement, persistence, and exfiltration behaviors.
Additional notes and limits
ATT&CK identifies TrickBot as a C++ Trojan spyware program first emerging in September 2016, initially associated with banking targeting and later used across sectors in ransomware campaign contexts. Relationships supplied here associate TrickBot with TA505 and Wizard Spider and with many enterprise techniques across discovery, execution, persistence, privilege escalation, credential access, collection, command and control, lateral movement, stealth, and exfiltration. The strongest defensive use is to map these relationships to concrete telemetry and response readiness in the local Windows environment.
The official ATT&CK object lists Windows as the platform but provides no official detection text and no object-level tactics. This take is based only on the supplied description, external references, and relationship context. Local validation is required to determine actual exposure, control coverage, false-positive patterns, and whether any observed activity is TrickBot, another tool, or legitimate administration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
TrickBot
TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.CitationS2 Grupo TrickBot June 2017CitationFidelis TrickBot Oct 2016CitationIBM TrickBot Nov 2016CitationCrowdStrike Wizard Spider October 2020
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
