TrickBot DNS tunneling C2 variant
Malware Activity
Summary
Hide ▲
Show ▼
The TrickBot malware family has switched its C2 from HTTP to a bespoke DNS tunneling channel, hiding beacons and payloads in malformed queries. The redesign routes encrypted traffic through a public resolver and preserves the family’s modular execution model. On July 22, 2026, the change raised detection risk while showing the malware remains actively maintained.
Related Happenings
A0Backdoor malware deployed through signed MSI sideloading and DNS MX C2
Malware Activity
H score22
First: 10.03.2026 00:50
Last: 10.03.2026 00:50
Sources 1
About this happening:
The A0Backdoor malware was deployed on Windows endpoints through digitally signed MSI installers and DLL sideloading, giving the operators a stealthier path to exe...
A0Backdoor malware deployed through signed MSI sideloading and DNS MX C2
Malware ActivityAbout this happening: The A0Backdoor malware was deployed on Windows endpoints through digitally signed MSI installers and DLL sideloading, giving the operators a stealthier path to exe...
ClickFix nslookup-delivered ModeloRAT activity
Malware Activity
H score24
First: 17.02.2026 19:03
Last: 17.02.2026 19:03
Sources 1
About this happening:
The ClickFix infection chain now uses nslookup to deliver ModeloRAT, increasing the chance that Windows users will self-infect and hand attackers remote control. T...
ClickFix nslookup-delivered ModeloRAT activity
Malware ActivityAbout this happening: The ClickFix infection chain now uses nslookup to deliver ModeloRAT, increasing the chance that Windows users will self-infect and hand attackers remote control. T...
Timeline
-
22.07.2026 18:00 2 articles · 1h ago
TrickBot variant switches command-and-control to DNS tunneling
Initial DisclosureA TrickBot variant replaces HTTP command-and-control with bespoke DNS tunneling, hiding beacons and payloads inside malformed DNS queries sent to a public resolver. The sample keeps a modular architecture consistent with earlier TrickBot campaigns while moving encrypted C2 traffic through DNS packets.
Show sources
- TrickBot Ditches HTTP for DNS Tunneling in Latest Variant — www.infosecurity-magazine.com — 22.07.2026 18:00
- TrickBot Ditches HTTP for DNS Tunneling in Latest Variant — www.infosecurity-magazine.com — 22.07.2026 18:00