Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Google Makes CodeMender Available as Managed AI Security Agent

July 22, 2026

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

July 22, 2026

TrickBot Ditches HTTP for DNS Tunneling in Latest Variant

July 22, 2026
Facebook X (Twitter) Instagram
Thursday, July 23
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»TrickBot Ditches HTTP for DNS Tunneling in Latest Variant
News

TrickBot Ditches HTTP for DNS Tunneling in Latest Variant

Team-CWDBy Team-CWDJuly 22, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A TrickBot variant has been observed swapping the HTTP command-and-control (C2) channel the malware has used for the better part of a decade for a bespoke DNS tunneling scheme that hides beacons and payloads inside malformed DNS queries.

According to new research from Fortinet’s FortiGuard Labs published on July 22, the samples reveal a modular architecture consistent with earlier TrickBot campaigns but with the transport layer redesigned around encrypted data smuggled through DNS packets to a public resolver.

The redesign is significant given the family’s history. Microsoft coordinated a court-ordered takedown of the TrickBot botnet in 2020 after infections exceeded one million devices, and public reporting had largely written the family off. This variant shows operators still iterating on the platform.

John Bambenek, president at cybersecurity consultancy Bambenek Consulting, said the malware family’s survival came down to operator adaptation.

“TrickBot has been a long-running malware family that has survived because the adversary adapts,” he said, adding that passive DNS analysis of the C2 identified in the report showed extensive exploitation activity and reinforced the case for enterprises controlling their own DNS resolution.

Read more on DNS tunneling: New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

Encoded Commands Inside DNS Queries

Once launched, the malware disguised outbound C2 messages as ordinary domain-name lookups and read the responses back from what looked like ordinary IP addresses.

The outbound channel encrypted each command with a single-byte XOR key, hex-encoded the result, then broke it into 63-character chunks separated by periods to mimic a valid domain, before prepending the whole string to a hardcoded C2 domain.

Three packet types carried the traffic: 0x30 for command requests, 0x31 for size queries and 0x32 for response data.

Inbound traffic exploited the DNS specification’s allowance for multiple IPv4 addresses per reply. TrickBot treated the first byte of each returned “address” as an ordering index so it could re-sort the resolver’s shuffled reply, and read the remaining three bytes as raw payload.

FortiGuard measured throughput at around 30.7 KB per second in its lab, moving a 1.2 MB file in 40 seconds.

Persistence and Modular Execution

Persistence relied on the Windows Task Scheduler. TrickBot generated a task name by combining a randomly picked %AppData% folder name, the string “autoupdate #” and a random number, producing entries such as “Wireshark autoupdate #72784” that ran every five minutes.

It stored the task name and executable path in two NTFS Alternate Data Streams (ADS) so subsequent executions rebuilt the same scheduled task rather than creating duplicates.

Command handling stayed close to the HTTP-era design. FortiGuard documented 12 response commands, including downloading and executing EXE modules, running DLLs through rundll32.exe, injecting into processes via process hollowing or process doppelganging, executing PowerShell through anonymous pipes to cmd.exe and running raw shellcode in memory.

Runtime-decrypted strings and hash-based Windows API resolution were designed to defeat static analysis. The DNS tunneling shift preserved the modular capabilities that have made TrickBot a persistent threat.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNew ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
Next Article n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
Team-CWD
  • Website

Related Posts

News

Google Makes CodeMender Available as Managed AI Security Agent

July 22, 2026
News

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

July 22, 2026
News

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

July 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

It’s all fun and games until someone gets hacked

September 26, 2025

Is it OK to let your children post selfies online?

February 17, 2026

Why geopolitical turmoil is a gift for scammers, and how to stay safe

May 15, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.