FortiGuard Labs identified a TrickBot variant that uses DNS tunneling for C2 communication instead of HTTP, embedding XOR-encrypted data in DNS queries and encoding response payloads within IPv4 address octets. The malware establishes persistence via Windows Task Scheduler disguised as software updates, stores configuration in NTFS Alternate Data Streams, and employs runtime string decryption and hash-based API resolution to evade analysis. Its modular architecture supports process injection (hollowing, doppelgänging), DLL execution via rundll32, PowerShell execution, and raw shellcode execution, retaining the full capability set of the TrickBot family.
process-injection
1 post
Inside a TrickBot Variant Using DNS Tunneling for C2