LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0266: TrickBot

TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.CitationS2 Grupo TrickBot June 2017CitationFidelis TrickBot Oct 2016CitationIBM TrickBot Nov 2016CitationCrowdStrike Wizard Spider October 2020

EnterpriseS0266MalwareObject v2.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

TrickBot matters because ATT&CK describes it as Windows Trojan spyware that evolved from banking-focused activity into use across sectors as part of “big game hunting” ransomware campaigns. For leaders, the decision value is not just malware blocking; it is whether the organization can recognize the discovery, credential collection, persistence, command-and-control, lateral movement, and exfiltration behaviors that ATT&CK associates with this software before an intrusion becomes a business interruption event.

Executive priority

Prioritize TrickBot as a resilience and incident-readiness scenario for Windows environments. The ATT&CK relationships show behavior spanning credential access, discovery, persistence through scheduled tasks, stealth through obfuscation and process injection, C2 over web protocols and fallback channels, VNC-based lateral movement, and exfiltration over C2. Executives should ask whether SOC monitoring, identity controls, endpoint hardening, and incident response playbooks can produce evidence across these stages, not only whether a malware signature exists.

Technical view

Validate coverage against the ATT&CK techniques linked to TrickBot: Scheduled Task, Process Injection and Process Hollowing, Credential API Hooking, PowerShell, Windows Command Shell, service/process/user/network/system discovery, remote system discovery, permission group discovery, VNC, web-protocol C2, fallback channels, exfiltration over C2, masquerading, and obfuscated/packed/encrypted files. Because the official detection field is not provided, detection engineering should be behavior-led and environment-specific, focused on Windows endpoint activity, process lineage, task creation, suspicious command execution, network egress patterns, and authentication or remote-control activity that aligns with these relationships.

Likely telemetry

  • Windows endpoint process creation and parent-child process lineage
  • Scheduled task creation, modification, and execution events
  • PowerShell and Windows command shell execution logs
  • Endpoint alerts or forensic evidence for process injection, process hollowing, packing, obfuscation, and masquerading
  • Windows service, process, user, group, system, and network discovery command evidence

Detection direction

  • Do not rely only on known TrickBot indicators; the ATT&CK relationships emphasize behaviors that can vary by environment and by malware version.
  • Tune detections around suspicious scheduled tasks, unusual PowerShell or cmd execution, discovery bursts, and abnormal child processes from user-facing or system processes.
  • Correlate endpoint behavior with outbound web traffic and fallback communication attempts to reduce false positives from legitimate administrative activity.
  • Review whether VNC use is expected, inventoried, and monitored; unexpected VNC activity can be material when paired with discovery or credential-access behavior.
  • Account for false positives from administrators, software deployment tools, monitoring agents, and legitimate remote support; require context such as process lineage, timing, host role, and user identity.

Mitigation priorities

  • Start with visibility: confirm Windows endpoint, command execution, scheduled task, authentication, remote access, and egress telemetry are retained and available to SOC and IR teams.
  • Reduce credential exposure by hardening credential handling and monitoring for abnormal credential access patterns consistent with the ATT&CK-linked Credential API Hooking behavior.
  • Restrict and monitor administrative scripting, command shell use, scheduled task creation, and remote-control tools such as VNC according to business need.
  • Harden egress controls and monitoring for web-protocol C2 and alternate/fallback channels, with escalation paths for suspicious outbound communication from workstations and servers.
  • Prepare IR playbooks that treat TrickBot-like behavior as a multi-stage intrusion risk: isolate affected Windows hosts, preserve endpoint and network evidence, assess credential exposure, and hunt for discovery, lateral movement, persistence, and exfiltration behaviors.
Additional notes and limits

ATT&CK identifies TrickBot as a C++ Trojan spyware program first emerging in September 2016, initially associated with banking targeting and later used across sectors in ransomware campaign contexts. Relationships supplied here associate TrickBot with TA505 and Wizard Spider and with many enterprise techniques across discovery, execution, persistence, privilege escalation, credential access, collection, command and control, lateral movement, stealth, and exfiltration. The strongest defensive use is to map these relationships to concrete telemetry and response readiness in the local Windows environment.

The official ATT&CK object lists Windows as the platform but provides no official detection text and no object-level tactics. This take is based only on the supplied description, external references, and relationship context. Local validation is required to determine actual exposure, control coverage, false-positive patterns, and whether any observed activity is TrickBot, another tool, or legitimate administration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

TrickBot

TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.CitationS2 Grupo TrickBot June 2017CitationFidelis TrickBot Oct 2016CitationIBM TrickBot Nov 2016CitationCrowdStrike Wizard Spider October 2020

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.2
Created
Modified
Raw hash
5668738896683613...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.