Overview
TrickBot infected a host, enumerated the network, harvested credentials and then handed off to Conti or Ryuk for encryption.\nIts module system meant operators could push new capability without redeploying the binary.\nIt repeatedly survived takedowns by patching itself from its own command servers.
Indicators of Compromise
Signals that suggest this is present on a system.
- Injected banking modules in memory
- Reconnaissance of domain controllers shortly after infection
- Group policy enumeration from a workstation