Skip to main content
QUIETLYTIC
Malware

TrickBot

Trojan spyware program written in C++, per MITRE ATT&CK, first emerging in September 2016 as a possible successor to Dyre, later repurposed for "big game hunting" ransomware campaigns worldwide.

Threat Level
HIGH
Family
TrickBot
Type
TROJAN
Also Known As
Totbrick, TSPY_TRICKLOAD

Overview

TrickBot (MITRE ATT&CK ID S0266) is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre, per MITRE’s software profile. MITRE documents TrickBot as developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of “big game hunting” ransomware campaigns, per MITRE’s citations.

Actors documented using this tool (per MITRE ATT&CK relationship data)

Our ingested data links TrickBot to two distinct MITRE ATT&CK groups: TA505 and Wizard Spider — the latter being TrickBot’s original developer and operator per MITRE’s description.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques MITRE links to TrickBot in our data include Bootkit (T1542.003), Browser Session Hijacking (T1185), Code Signing (T1553.002), Component Object Model abuse (T1559.001), Credential API Hooking (T1056.004), Credential Stuffing (T1110.004), Credentials In Files (T1552.001), and Credentials from Web Browsers (T1555.003).

What we don’t have

MITRE’s description gives an explicit origin (September 2016) but our ingested data doesn’t carry it as a structured discovery-date field. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no current operational-status data following widely reported law-enforcement and industry disruption efforts against TrickBot infrastructure in past years.

Frequently Asked Questions

What is TrickBot? A C++ banking trojan, per MITRE ATT&CK, that first emerged in September 2016 as a possible Dyre successor, later repurposed for ransomware delivery (“big game hunting”) worldwide.

Who created TrickBot? Per MITRE’s software profile, TrickBot was developed and initially used by Wizard Spider.

Is TrickBot still a banking trojan today? MITRE’s description notes it “has since been used against all sectors worldwide as part of ‘big game hunting’ ransomware campaigns” — i.e., its documented use expanded well beyond banking-specific targeting.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), software ID S0266, aggregated August 25, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more malware profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Analyst tools