Back in July, FortiGuard Labs observed several malicious samples that were sending malformed DNS queries. After conducting an in-depth analysis, it was determined that these samples are TrickBot variants that use DNS tunneling to communicate with their command-and-control (C2) servers.
TrickBot is a modular malware family that FortiGuard Labs has repeatedly captured over the past decade. Its modular architecture enables it to extend its capabilities by downloading and executing additional modu