Inside a TrickBot Variant Using DNS Tunneling for C2

    Date: 07/23/2026

    Severity: High

    Summary

    Researchers recently identified TrickBot variants that communicate with command-and-control (C2) servers using DNS tunneling instead of the HTTP protocol seen in earlier versions. The malware sends malformed DNS queries to conceal its network communications and evade detection. TrickBot's modular architecture enables it to extend its functionality by downloading and executing additional modules on compromised systems. Analysis of a captured sample revealed multiple obfuscation techniques designed to hinder reverse engineering and security analysis. The malware also establishes persistence to maintain long-term access to infected devices. The research further details how malformed DNS queries are generated and used to transport C2 commands and data through DNS traffic.

    Indicators of Compromise (IOC) List

    Domains/URLs

    westurn.in

    Hash  

    DF527A5C2FBDE43816CD02F4CD49EEE4BB82FB4A3C7045021360888C7D504C98

    6C677EB2B3FFD288083C59A13D7BB712D4754AF61A5563873F76C440962346F4

    105F652E6B8F31C371F2385877E43B6772AFF5D3168D5D4635F8A1FCBB321421

    33C331EDEDBF8EE9829895424423CE3FD17E359D2E784FCBCE396AACFF458CF5

    3B19A82E1354AC14A3DA7C840CBDD0CE50DB38432D78E767B36F08E45024C23D

    BF80245BA792992FBFE24ABAC33F8FD66F24CDEB5F0F21CFDF45A29D107C8D3B

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "westurn.in" or url like "westurn.in" or siteurl like "westurn.in"

    Detection Query 2 :

    sha256hash IN ("BF80245BA792992FBFE24ABAC33F8FD66F24CDEB5F0F21CFDF45A29D107C8D3B","3B19A82E1354AC14A3DA7C840CBDD0CE50DB38432D78E767B36F08E45024C23D","DF527A5C2FBDE43816CD02F4CD49EEE4BB82FB4A3C7045021360888C7D504C98","105F652E6B8F31C371F2385877E43B6772AFF5D3168D5D4635F8A1FCBB321421","6C677EB2B3FFD288083C59A13D7BB712D4754AF61A5563873F76C440962346F4","33C331EDEDBF8EE9829895424423CE3FD17E359D2E784FCBCE396AACFF458CF5")

    Reference:    

    https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2                        


    Tags

    MalwareObfuscation

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags