THE report from FortiGuard Labs details a new variant of TrickBot malware that utilizes DNS tunneling for command and control (C2) communication, moving away from traditional HTTP methods. This variant embeds encrypted command data in malformed DNS queries and leverages NTFS Alternate Data Streams to hide its configuration. Six samples were analyzed, all exhibiting similar PE characteristics and behaviors.
The malware is capable of executing various operations like code injection and shell command execution, while also establishing persistence via scheduled tasks disguised as legitimate updates. Detection strategies include monitoring DNS queries for anomalies and reviewing scheduled tasks.