Netskope Threat Labs

TrickBot

ATP Sandbox Adv. HeuristicsAVNetskope IPS

TrickBot is a modular banking trojan and malware loader that has been active since 2016, evolving from credential theft into the core of a major criminal ecosystem. Its module system added reconnaissance, lateral movement, and delivery capabilities, and it fed access and payloads to operations such as Ryuk and Conti. Repeated takedown efforts disrupted its infrastructure, yet rebuilt versions and successor tooling keep its tactics alive in modern campaigns.

First seen
February 2022
Last seen
October 2026
TotbrickTrickbot

55 techniques across 12 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

  • T1543Create or Modify System Process
  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1007System Service Discovery
  • T1016System Network Configuration Discovery
  • T1018Remote System Discovery
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1069Permission Groups Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1087Account Discovery
  • T1135Network Share Discovery
  • T1482Domain Trust Discovery

TA0008 Lateral Movement

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0040 Impact

TA0112 Defense Impairment

Alert Name
ByteCode-MSIL.Spyware.Trickbot
ByteCode-MSIL.Spyware.TrickBot
ByteCode-MSIL.Trojan.TrickBot
DeepScan:Generic.TrickBot.1832592A
Document-Excel.Downloader.TrickBot
Document-Excel.Trojan.TrickBot
Document-Office.Downloader.TrickBot
Document-Office.Trojan.TrickBot
Document-Word.Trojan.TrickBot
Dump:Generic.TrickBot.1832592A