Date: 07/23/2026
Severity: High
Summary
Researchers recently identified TrickBot variants that communicate with command-and-control (C2) servers using DNS tunneling instead of the HTTP protocol seen in earlier versions. The malware sends malformed DNS queries to conceal its network communications and evade detection. TrickBot's modular architecture enables it to extend its functionality by downloading and executing additional modules on compromised systems. Analysis of a captured sample revealed multiple obfuscation techniques designed to hinder reverse engineering and security analysis. The malware also establishes persistence to maintain long-term access to infected devices. The research further details how malformed DNS queries are generated and used to transport C2 commands and data through DNS traffic.
Indicators of Compromise (IOC) List
Domains/URLs | westurn.in |
Hash | DF527A5C2FBDE43816CD02F4CD49EEE4BB82FB4A3C7045021360888C7D504C98
6C677EB2B3FFD288083C59A13D7BB712D4754AF61A5563873F76C440962346F4
105F652E6B8F31C371F2385877E43B6772AFF5D3168D5D4635F8A1FCBB321421
33C331EDEDBF8EE9829895424423CE3FD17E359D2E784FCBCE396AACFF458CF5
3B19A82E1354AC14A3DA7C840CBDD0CE50DB38432D78E767B36F08E45024C23D
BF80245BA792992FBFE24ABAC33F8FD66F24CDEB5F0F21CFDF45A29D107C8D3B
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "westurn.in" or url like "westurn.in" or siteurl like "westurn.in" |
Detection Query 2 : | sha256hash IN ("BF80245BA792992FBFE24ABAC33F8FD66F24CDEB5F0F21CFDF45A29D107C8D3B","3B19A82E1354AC14A3DA7C840CBDD0CE50DB38432D78E767B36F08E45024C23D","DF527A5C2FBDE43816CD02F4CD49EEE4BB82FB4A3C7045021360888C7D504C98","105F652E6B8F31C371F2385877E43B6772AFF5D3168D5D4635F8A1FCBB321421","6C677EB2B3FFD288083C59A13D7BB712D4754AF61A5563873F76C440962346F4","33C331EDEDBF8EE9829895424423CE3FD17E359D2E784FCBCE396AACFF458CF5")
|
Reference:
https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2