As cited
Copy frozen at (site build).
TrickBot Ditches HTTP for DNS Tunneling in Latest Variant
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
TrickBot Ditches HTTP for DNS Tunneling in Latest Variant
A new TrickBot variant uses DNS tunneling to conceal command and control (C2) communication, moving away from the HTTP-based approach the malware has relied on for over a decade. This technique allows attackers to hide their C2 traffic within normal-looking DNS queries, making detection more difficult for network monitoring tools.
Why it matters: Organizations defending against TrickBot infections need to update detection signatures and DNS monitoring to identify tunneled C2 traffic, as traditional HTTP-based indicators of compromise (IOCs) will no longer catch this variant.
- Source published
- First seen by Cybersecurity Tracker