securityonline.info 7/29/2026, 10:11:20 AM · external

New TrickBot variant hides in DNS queries and NTFS streams

New TrickBot variant hides in DNS queries and NTFS streams
Developing story malware 2 articles tracked
TrickBot malware adopts DNS tunneling for covert C2 communication
CyberSIXT Evidence Panel
Primary Source fortinet.com

THE report from FortiGuard Labs details a new variant of TrickBot malware that utilizes DNS tunneling for command and control (C2) communication, moving away from traditional HTTP methods. This variant embeds encrypted command data in malformed DNS queries and leverages NTFS Alternate Data Streams to hide its configuration. Six samples were analyzed, all exhibiting similar PE characteristics and behaviors.

The malware is capable of executing various operations like code injection and shell command execution, while also establishing persistence via scheduled tasks disguised as legitimate updates. Detection strategies include monitoring DNS queries for anomalies and reviewing scheduled tasks.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline