#TrickBot
Malware/Tool
2019-12-10 • The Deadly Planeswalker: How The TrickBot Group United High-Tech Crimeware & APT
One operation progressed from a TrickBot infection into hands-on activity against sensitive financial and point-of-sale systems, including takeover of critical network assets. High-profile targets selectively received Anchor_DNS, a backdoor that used DNS for covert command-and-control communication. Reporting on the Anchor Project also describes a possible operational link between the TrickBot organization and North Korea's Lazarus group, with Anchor tools used to deploy malware possibly associated with the North Korean regime. MITRE ATT&CK S0266.
-
4
Tagged Reports
-
4
Unique Authors
-
280
Active Days