Skip to content

Latest commit

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

TrickBot Malware Analysis

This research paper investigates TrickBot malware—originally a banking trojan and now a sophisticated, modular cyber threat often used by groups like Wizard Spider and UNC1878. TrickBot has evolved to support ransomware delivery (e.g., Ryuk, Conti), data theft, and network propagation via SMB.


FULL PAPER: TrickBot_MichaelTwining.pdf


📌 Key Topics Covered

  • 👥 Threat Actor Attribution: Wizard Spider, UNC1878, Gold Blackburn
  • 💣 Capabilities: Banking trojan, credential theft, ransomware delivery, C2 infrastructure
  • 🔁 Propagation: Exploits SMB protocol (worm-like behavior)
  • 🧰 MITRE ATT&CK Mapping: Initial access, execution, persistence, evasion
  • 🧬 Modular Architecture: Adaptable for use by other ransomware gangs
  • 🔐 Detection & Defense: Network indicators, phishing training, SMB hardening

🔧 Techniques & Tools Discussed

TacticTechnique
Initial AccessSpear phishing with attachments/links
ExecutionMacros, JS files, Windows API abuse
PersistenceAutostart services, scheduled tasks
Defense EvasionProcess hollowing, registry modification
Credential AccessEnumeration of stored passwords
Command & ControlEncrypted HTTP traffic, C2 rotation

🧠 Key Insight

TrickBot’s strength lies in its modularity and evasion—allowing attackers to revisit and reinfect targets even after incident response efforts. The paper emphasizes hardening endpoints, proactive detection, and layered defenses.


📎 References


📘 Written by Michael Twining | LinkedIn
Part of my Cybersecurity Portfolio

About

In-depth malware research report analyzing TrickBot's evolution from a banking trojan to a modular threat tool used in ransomware campaigns. Covers threat actor attribution, MITRE ATT&CK mapping, propagation techniques, and defensive strategies.

Topics

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors