Find notable cyber news and cases, enriched with sources, timelines, and signals.

TrickBot DNS tunneling C2 variant

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

The TrickBot malware family has switched its C2 from HTTP to a bespoke DNS tunneling channel, hiding beacons and payloads in malformed queries. The redesign routes encrypted traffic through a public resolver and preserves the family’s modular execution model. On July 22, 2026, the change raised detection risk while showing the malware remains actively maintained.

Related Happenings

A0Backdoor malware deployed through signed MSI sideloading and DNS MX C2

Malware Activity
H score22 First: 10.03.2026 00:50 Last: 10.03.2026 00:50 Sources 1

About this happening: The A0Backdoor malware was deployed on Windows endpoints through digitally signed MSI installers and DLL sideloading, giving the operators a stealthier path to exe...

ClickFix nslookup-delivered ModeloRAT activity

Malware Activity
H score24 First: 17.02.2026 19:03 Last: 17.02.2026 19:03 Sources 1

About this happening: The ClickFix infection chain now uses nslookup to deliver ModeloRAT, increasing the chance that Windows users will self-infect and hand attackers remote control. T...

Timeline

  1. 22.07.2026 18:00 2 articles · 1h ago

    TrickBot variant switches command-and-control to DNS tunneling

    Initial Disclosure

    A TrickBot variant replaces HTTP command-and-control with bespoke DNS tunneling, hiding beacons and payloads inside malformed DNS queries sent to a public resolver. The sample keeps a modular architecture consistent with earlier TrickBot campaigns while moving encrypted C2 traffic through DNS packets.

    Show sources