Inside a TrickBot Variant Using DNS Tunneling for C2
A TrickBot malware variant has been identified that uses DNS tunneling for command-and-control (C2) communications, bypassing traditional HTTP channels. It persists on infected Windows systems by creating disguised scheduled tasks that run at startup and every five minutes. Configuration data is hidden in NTFS Alternate Data Streams to evade detection. The malware uses multiple obfuscation methods, including encrypted strings and runtime API resolution, and supports a modular architecture with twelve control commands enabling advanced capabilities such as module downloads, process injection via hollowing and doppelgänging, PowerShell execution, and raw machine code execution. Data transfer occurs through crafted DNS queries to public DNS servers, encoding commands in malformed domain names and receiving responses in multiple IPv4 addresses, achieving transfer speeds of about 30.7 KB/s.
AI Analysis
Technical Summary
This TrickBot variant employs DNS tunneling for C2 communications instead of conventional HTTP protocols, enhancing stealth and evasion. It maintains persistence through Windows Task Scheduler by creating disguised tasks that execute at startup and every five minutes. Configuration data is stored in NTFS Alternate Data Streams, complicating detection. The malware uses encrypted strings, hash-based runtime API resolution, and dynamically calculated constants for obfuscation. Its modular design supports twelve control commands, enabling capabilities such as downloading modules, process injection via hollowing and doppelgänging techniques, PowerShell script execution, and raw machine code execution. Command and control data is transmitted via specially crafted DNS queries to public DNS servers, encoding commands in malformed domain names and receiving responses embedded in multiple IPv4 addresses, with transfer speeds around 30.7 KB/s.
Potential Impact
The malware enables persistent, stealthy control over infected Windows systems, allowing attackers to execute arbitrary code, inject into processes, download additional modules, and run PowerShell scripts. Its use of DNS tunneling for C2 communications can evade traditional network security monitoring focused on HTTP/S traffic. The obfuscation techniques and storage of configuration data in NTFS Alternate Data Streams further complicate detection and forensic analysis. This increases the difficulty of identifying and mitigating infections, potentially allowing prolonged unauthorized access and control.
Mitigation Recommendations
No official patch or remediation is indicated for this malware variant. Mitigation should focus on detecting and blocking suspicious DNS tunneling activity, monitoring for unusual scheduled tasks especially those disguised or running frequently, and scanning for NTFS Alternate Data Streams containing hidden data. Endpoint detection and response (EDR) solutions capable of identifying process injection techniques such as hollowing and doppelgänging, as well as PowerShell abuse, can aid in detection. Network defenses should be configured to monitor and restrict anomalous DNS queries to public DNS servers. Since this is malware, standard patching does not apply; incident response and malware removal procedures are recommended upon detection.
Indicators of Compromise
- domain: westurn.in
- hash: 8d5b3a0512744efc132afa6fc75c64d8
- hash: f7f2f482f3bc6345a44e4a6d647731ae
- hash: 48fd2036b6556c6747197e07f1706bcf58a27518
- hash: 105f652e6b8f31c371f2385877e43b6772aff5d3168d5d4635f8a1fcbb321421
- hash: 33c331ededbf8ee9829895424423ce3fd17e359d2e784fcbce396aacff458cf5
- hash: 3b19a82e1354ac14a3da7c840cbdd0ce50db38432d78e767b36f08e45024c23d
- hash: 6c677eb2b3ffd288083c59a13d7bb712d4754af61a5563873f76c440962346f4
- hash: bf80245ba792992fbfe24abac33f8fd66f24cdeb5f0f21cfdf45a29d107c8d3b
- hash: df527a5c2fbde43816cd02f4cd49eee4bb82fb4a3c7045021360888c7d504c98
Inside a TrickBot Variant Using DNS Tunneling for C2
Description
A TrickBot malware variant has been identified that uses DNS tunneling for command-and-control (C2) communications, bypassing traditional HTTP channels. It persists on infected Windows systems by creating disguised scheduled tasks that run at startup and every five minutes. Configuration data is hidden in NTFS Alternate Data Streams to evade detection. The malware uses multiple obfuscation methods, including encrypted strings and runtime API resolution, and supports a modular architecture with twelve control commands enabling advanced capabilities such as module downloads, process injection via hollowing and doppelgänging, PowerShell execution, and raw machine code execution. Data transfer occurs through crafted DNS queries to public DNS servers, encoding commands in malformed domain names and receiving responses in multiple IPv4 addresses, achieving transfer speeds of about 30.7 KB/s.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This TrickBot variant employs DNS tunneling for C2 communications instead of conventional HTTP protocols, enhancing stealth and evasion. It maintains persistence through Windows Task Scheduler by creating disguised tasks that execute at startup and every five minutes. Configuration data is stored in NTFS Alternate Data Streams, complicating detection. The malware uses encrypted strings, hash-based runtime API resolution, and dynamically calculated constants for obfuscation. Its modular design supports twelve control commands, enabling capabilities such as downloading modules, process injection via hollowing and doppelgänging techniques, PowerShell script execution, and raw machine code execution. Command and control data is transmitted via specially crafted DNS queries to public DNS servers, encoding commands in malformed domain names and receiving responses embedded in multiple IPv4 addresses, with transfer speeds around 30.7 KB/s.
Potential Impact
The malware enables persistent, stealthy control over infected Windows systems, allowing attackers to execute arbitrary code, inject into processes, download additional modules, and run PowerShell scripts. Its use of DNS tunneling for C2 communications can evade traditional network security monitoring focused on HTTP/S traffic. The obfuscation techniques and storage of configuration data in NTFS Alternate Data Streams further complicate detection and forensic analysis. This increases the difficulty of identifying and mitigating infections, potentially allowing prolonged unauthorized access and control.
Mitigation Recommendations
No official patch or remediation is indicated for this malware variant. Mitigation should focus on detecting and blocking suspicious DNS tunneling activity, monitoring for unusual scheduled tasks especially those disguised or running frequently, and scanning for NTFS Alternate Data Streams containing hidden data. Endpoint detection and response (EDR) solutions capable of identifying process injection techniques such as hollowing and doppelgänging, as well as PowerShell abuse, can aid in detection. Network defenses should be configured to monitor and restrict anomalous DNS queries to public DNS servers. Since this is malware, standard patching does not apply; incident response and malware removal procedures are recommended upon detection.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2"]
- Adversary
- null
- Pulse Id
- 6a6120390f602b6ee56739c3
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainwesturn.in | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash8d5b3a0512744efc132afa6fc75c64d8 | — | |
hashf7f2f482f3bc6345a44e4a6d647731ae | — | |
hash48fd2036b6556c6747197e07f1706bcf58a27518 | — | |
hash105f652e6b8f31c371f2385877e43b6772aff5d3168d5d4635f8a1fcbb321421 | — | |
hash33c331ededbf8ee9829895424423ce3fd17e359d2e784fcbce396aacff458cf5 | — | |
hash3b19a82e1354ac14a3da7c840cbdd0ce50db38432d78e767b36f08e45024c23d | — | |
hash6c677eb2b3ffd288083c59a13d7bb712d4754af61a5563873f76c440962346f4 | — | |
hashbf80245ba792992fbfe24abac33f8fd66f24cdeb5f0f21cfdf45a29d107c8d3b | — | |
hashdf527a5c2fbde43816cd02f4cd49eee4bb82fb4a3c7045021360888c7d504c98 | — |
Threat ID: 6a61429b9c2644c7f8c94c89
Added to database: 07/22/2026, 22:22:19 UTC
Last enriched: 07/22/2026, 22:42:20 UTC
Last updated: 07/23/2026, 01:08:54 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.