#TrickBot

Malware/Tool

2019-12-10 • The Deadly Planeswalker: How The TrickBot Group United High-Tech Crimeware & APT

One operation progressed from a TrickBot infection into hands-on activity against sensitive financial and point-of-sale systems, including takeover of critical network assets. High-profile targets selectively received Anchor_DNS, a backdoor that used DNS for covert command-and-control communication. Reporting on the Anchor Project also describes a possible operational link between the TrickBot organization and North Korea's Lazarus group, with Anchor tools used to deploy malware possibly associated with the North Korean regime. MITRE ATT&CK S0266.

Tagged Reports

« Back