Back in July, FortiGuard Labs observed several malicious samples that were sending malformed DNS queries. After conducting an in-depth analysis, it was determined that these samples are TrickBot variants that use DNS tunneling to communicate with their command-and-control (C2) servers.
TrickBot is a modular malware family that FortiGuard Labs has repeatedly captured over the past decade. Its modular architecture enables it to extend its capabilities by downloading and executing additional modules on compromised devices. Previously observed TrickBot variants primarily relied on HTTP to communicate with its C2 servers.
While DNS-based TrickBot variants, including Anchor DNS, have been publicly documented previously, this analysis focuses on recently observed samples and provides an in-depth technical analysis of their implementation and behavior.
Link to Full Report: IR-26-257-001_TrickBot.pdf
Comments