Ransomware EDP  •  Threat Actor Library
therenoproject.org  •  Analytical Profiles
Threat Actor Profile  •  Last updated July 2026
TrickBot
Modular Loader & Access Broker  •  Banking Trojan Heritage  •  Wizard Spider / GOLD BLACKBURN
Botnet Defunct Personnel Active Access Broker
First Observed
Oct 2016
Earliest samples Sep 2016
Botnet Shutdown
Mar 2022
Voluntary wind-down
Ecosystem Revenue
$724M+
Chainalysis, Feb 2023
Peak Botnet
~1M
Compromised machines
Sanctioned Members
18
US/UK, 2023 (2 actions)
LE Disruptions
Multiple
2020 takedowns, Endgame 2025
Lineage
Dyre
Direct descendant
01

Overview

TrickBot was a Russia-based, highly modular malware ecosystem operated by a financially motivated criminal enterprise from October 2016 until the botnet infrastructure was voluntarily abandoned on March 1, 2022. It began as a banking trojan targeting Australian financial institutions and evolved into the dominant initial-access and loader platform of its era, provisioning compromised networks to the Ryuk and Conti ransomware operations. The group functioned as a backend criminal service rather than a public-facing extortion brand: it never operated a data leak site in its own name, and ransom demands were issued under partner brands.

The group is tracked across the threat intelligence community under multiple designations. It is assessed with high confidence as a direct descendant of the Dyre banking trojan, and its core personnel were absorbed into Conti by early 2022 before dispersing into successor operations. As of July 2026, the TrickBot platform is defunct but its operators remain active in the broader ransomware ecosystem, and its alleged founder was publicly named by German authorities in May 2025.

AttributeDetail
Tracking aliases (group-specific)GOLD BLACKBURN (Secureworks, TrickBot operators), Periwinkle Tempest / DEV-0193 (Microsoft), UNC1878 and UNC2053 (Mandiant clusters). WIZARD SPIDER (CrowdStrike) and MITRE G0102 designate the broader parent syndicate, not TrickBot alone.
Predecessor lineageDirect descendant of Dyre / Dyreza banking trojan (2014 to 2015), assessed with high confidence by Secureworks, Fidelis, US Treasury, and UK FCDO
Operational modelClosed operator and access broker; not an open RaaS. Malware-as-a-service provisioning to trusted ransomware partners (Ryuk, Conti, Diavol)
Extortion mechanicNone directly. Extortion (including Conti double extortion) conducted by partner ransomware deployed on TrickBot-originated access
Assessed jurisdictionRussia (CONFIRMED by US/UK government designations); safe harbor throughout operational life
Operational statusBotnet defunct since March 2022; personnel migrated to Conti then to Black Basta, Royal, and other successors
Malware Artifacts, Attribution & Branding

TrickBot did not operate a public data leak site. In place of DLS imagery, the gallery below documents TrickBot-specific artifacts: its landmark UEFI firmware module, its firmware-reconnaissance code, and the attribution of its alleged founder.

02

Origin & Lineage

Emergence

TrickBot was first identified in the wild in October 2016, with the earliest samples (September 2016) targeting customers of Australian banks (ANZ, Westpac, St. George, NAB). It was first publicly reported by Fidelis Cybersecurity and Malwarebytes as a banking trojan. Early monetization was credential theft and banking fraud, not extortion. The malware evolved continuously across a six-year window, adding worm propagation, backdoors, and ransomware-delivery functionality.

Assessed Predecessor: Dyre / Dyreza
Confirmed: multi-vendor consensus, no meaningful dispute in public record

There is high-confidence, multi-vendor consensus that TrickBot is a direct descendant of the Dyre (Dyreza) banking trojan, active from June 2014 until Russian law enforcement disrupted it in November 2015 through raids on a Moscow film-distribution company assessed to be a front. Secureworks assesses GOLD BLACKBURN with high confidence as a direct descendant of Dyre. The US Treasury and UK FCDO official statements explicitly state TrickBot "evolved from the Dyre trojan."

Dyre Lineage: Evidentiary Pillars
Pillar 1: Confirmed
Code Overlap
Fidelis (September 2016) documented "staggering" similarity between TrickBot and Dyre: shared loader architecture, custom encryptors, hashing functions, and C2 encryption. TrickLoader was near-identical to Dyre's loader. Main differences were more C++ code and use of Microsoft CryptoAPI for AES/SHA-256.
Pillar 2: Credible
Timing Continuity
Dyre ceased November 2015; TrickBot appeared September 2016, roughly ten months later, consistent with surviving developers reconstituting after evading the 2015 arrests. Fidelis assessed with moderate confidence that one or more original Dyre developers were involved, not necessarily the whole team.
Pillar 3: Confirmed
Infrastructure Reuse
TrickLoader was also used by Vawtrak, Pushdo, and Cutwail, all previously tied to the Dyre ecosystem. This infrastructure reuse strongly implies personnel continuity across the two operations.
Pillar 4: Authoritative
Government Confirmation
US Treasury and UK FCDO statements (February and September 2023) explicitly state TrickBot evolved from Dyre and identify Moscow-based individuals as the operational continuity. Secureworks corroborates independently.
Vendor Designation Disambiguation
Scoping caution: Vendor labels differ in scope and must not be conflated. WIZARD SPIDER (CrowdStrike) and GOLD ULRICK (Secureworks) describe the broader Conti parent syndicate, not TrickBot specifically. GOLD ULRICK is Secureworks' designation for Conti; it is distinct from GOLD BLACKBURN.

GOLD BLACKBURN (Secureworks) is the group-specific designation for the TrickBot botnet operators, assessed as authors and operators of TrickBot from 2016 to March 2022 and of BazarLoader, Anchor, and related tooling. Periwinkle Tempest (formerly DEV-0193) is Microsoft's designation for the same actor responsible for developing and managing TrickBot, BazarLoader, AnchorDNS, Ryuk, Conti, and Diavol. Mandiant tracked the TrickBot-to-Ryuk intrusion activity as UNC1878, with UNC2053 as a related cluster designation. CrowdStrike's WIZARD SPIDER (equivalent to MITRE ATT&CK G0102) spans TrickBot, Ryuk, and Conti as sequential campaigns of one organization.

03

Operational Model

Structure: Closed Operator with Ransomware Partnerships

TrickBot operated as a closed operator, not an open RaaS platform. It developed and maintained its own malware infrastructure and provided access to select ransomware partners rather than openly advertising affiliate slots. The BKA assessed that, at times, the group exceeded 100 members and worked in an organized, hierarchically structured, project- and profit-oriented manner. By 2020 to 2021, the group had become a de facto access broker exclusively serving the Conti syndicate, which ultimately acquired the operation.

  • Developer core: Structured hierarchy with named roles: administrators (Stern / Kovalev), team leads for coders, test leads, HR and finance managers, infrastructure procurement, and server administrators.
  • Ransomware partnerships: Ryuk from 2018; near-exclusive provisioning to Conti by 2020; also linked to Diavol (FBI-confirmed, January 2022).
  • Talent structure: Investigators assess at least 17 members in functional roles including malware managers, developers, crypters, and spammers; BKA cites more than 100 at peak.
Affiliate Recruitment and Vetting

TrickBot did not run a public affiliate recruitment program in the manner of LockBit or REvil. Collaboration was through controlled partnerships with trusted ransomware groups. BazarLoader, developed as TrickBot's stealthier successor, was similarly operated as a closed platform. No public forum recruitment advertisements have been attributed to TrickBot specifically; the group maintained operational secrecy about its internal structure.

Revenue Model
PhasePeriodMonetization
Direct fraud2016 to 2018Credential theft from banking customers; wire transfer fraud
Access broker / MaaS2018 to 2022Initial access and persistence sold to ransomware operators for revenue share
Ransomware revenue share2018 to 2022Share of ransoms extorted by Ryuk and Conti from TrickBot-originated access
Analyst Inference: exact split ratios not publicly documented

Specific revenue-split terms between TrickBot and its ransomware partners have not been publicly documented in court filings or leaked data. Chainalysis identified cryptocurrency payments from Conti, Ryuk, Diavol, and Karakurt wallets flowing to administrator "Stern" (Kovalev), corroborating revenue sharing, but exact ratios remain unconfirmed from public sources.

Negotiation and Extortion Behavior

TrickBot did not conduct ransom negotiations directly; these were handled by the ransomware partners deploying payloads onto TrickBot-compromised networks. Under the Conti partnership, extortion followed a double-extortion model: data exfiltration preceding encryption, with publication threats on Conti's "Conti News" leak site. Ransom amounts were set by the partner and ranged from hundreds of thousands to tens of millions of dollars depending on victim revenue. Per US Treasury, group members "publicly gloated" over the speed of ransom payments from healthcare victims during the COVID-19 pandemic.

04

Technical Profile

Malware Architecture

TrickBot was a highly modular malware ecosystem. The core bot loaded plugin modules dynamically, allowing operators to deploy capabilities selectively against high-value targets. This modularity made complete takedown and detection significantly harder than for monolithic malware. Configuration files used a rolling 4-byte XOR scheme for C2 obfuscation, with key and config length hardcoded at fixed offsets.

Initial Access Vectors
VectorDetail
Phishing / spearphishingPrimary delivery: macro-enabled Office documents; fake invoices, bank documents, COVID-19 lures
Emotet deliveryFrom mid-2018, Emotet installed TrickBot as a secondary payload; the Emotet to TrickBot to Ryuk/Conti chain was a dominant attack pattern
SMB exploitation (EternalBlue)Worm component for lateral movement and self-propagation using leaked NSA exploits
TrickBooster spam moduleDiscovered 2019; used infected machines to propagate further TrickBot infections
Malicious Google Docs linksDocumented delivery vector
Key CVEs Exploited
CVEProductTypeUse
CVE-2017-0144Windows SMBv1 (MS17-010)Remote code executionEternalBlue; worm propagation within networks (NVD-verified)
CVE-2017-0145Windows SMBv1 (MS17-010)Remote code executionEternalRomance; lateral movement (NVD-verified)
CVE-2020-14871Oracle Solaris PAMBuffer overflowAttributed primarily to UNC1945; ecosystem capability only, not confirmed for TrickBot core (single-source)
TrickBoot: UEFI Firmware Module
Confirmed: discovered October 2020 by AdvIntel and Eclypsium

TrickBoot (internally "PermaDll" / user_platform_check.dll) was a landmark module able to read, write, and erase UEFI/BIOS firmware. It used the RwDrv.sys driver from the public RWEverything tool to interact with the SPI controller governing system firmware, the same driver used by the state-linked LoJax rootkit. This enabled persistence that survives OS reinstalls and drive replacement. At time of discovery, the module was only observed checking whether BIOS write protection was enabled (reconnaissance), making TrickBot the first non-state-sponsored, financially motivated actor to probe UEFI-level persistence in real-world deployments. Prior UEFI implants (LoJax, MosaicRegressor) had been observed only in nation-state operations.

Persistence and Lateral Movement
  • Registry run-key persistence and scheduled tasks (Task Scheduler)
  • Mimikatz for Windows credential harvesting (NTLM hashes, Kerberos tickets)
  • Cobalt Strike for post-exploitation lateral movement and network mapping
  • SMB-based worm propagation using EternalBlue
  • Active Directory credential theft module (Windows 10 UAC bypass, January 2020)
  • Theft of OpenSSH and OpenVPN keys (November 2019); VNC, PuTTY, and RDP credentials
Encryption (via Partners)

TrickBot's own malware was a loader and access tool, not a ransomware encryptor. Encryption was performed by deployed partners: Ryuk (AES-256 for files, RSA-2048 for keys); Conti (AES-256, ChaCha20 in later variants, multi-threaded fast encryption via asynchronous I/O); Diavol (asynchronous I/O file queuing with command-line parameters nearly identical to Conti, per IBM X-Force; appends the .lock64 extension).

CIS Exclusion Behavior
Credible: confirmed for BazarLoader; inferred for TrickBot core

BazarLoader (TrickBot's successor tool) is confirmed by MITRE ATT&CK (S0534) to check whether the OS keyboard and language settings are Russian, halting execution if detected, a standard CIS-exclusion behavior. For the TrickBot core binary, the operational behavior of avoiding Russian and CIS victims was consistent and deliberate (per US Treasury), but explicit technical documentation of a Russian keyboard kill switch in the core binary (distinct from BazarLoader) is not uniformly confirmed across public vendor reports. Analysts should treat the core-binary kill switch as inferred, not confirmed.

Linux and Cross-Platform Variants
  • TrickBot Linux variant: TrickBot began infecting Linux systems as of July 2020; a Linux port was actively deployed.
  • Anchor Linux: The Anchor backdoor (first observed August 2018) had a confirmed Linux variant (anchor_linux), extending reach to Linux servers.
  • ESXi/VMware: Primary ESXi targeting was conducted by Conti (Linux ESXi encryptor); TrickBot provided the initial access that enabled Conti to reach ESXi environments.
05

Targeting

Primary Sectors
SectorNotes
Healthcare / hospitalsMost intensively targeted during 2020 COVID-19 pandemic; ~428 US hospitals targeted per research cited by Wired; three Minnesota medical centers disrupted, ambulances diverted
Financial servicesOriginal banking trojan function; credential theft from banking customers globally
Government / public sectorUS government entities; 27 Costa Rican institutions (via Conti); UK local authorities
EducationSchools and districts; Los Angeles Unified School District attack linked to the TrickBot group
Critical infrastructureLaw enforcement, EMS, 911 dispatch (per US advisories); 16 attacks on US emergency responders documented
Retail and manufacturingAnchor backdoor campaigns specifically targeted financial, manufacturing, and retail sectors
Geographic Distribution and Exclusions

Primary target geographies were the United States (healthcare, government, financial), the United Kingdom (149 confirmed NCA victims), and Europe (Germany, Netherlands). Documented targeting also reached India and Australia. Russian, Belarusian, and CIS-region entities were operationally excluded as victims, consistent with a state-tolerated operator model. The UK government assessed that targeting of the International Olympic Committee "almost certainly aligns with Russian state objectives."

Victim Size Profile

In its initial phase (2016 to 2018) TrickBot primarily hit small and medium businesses and individual banking customers. In its evolved phase (2019 to 2022) targeting shifted toward mid-market and large enterprise, government, and critical infrastructure, reflecting the ransomware-deployment model where victim size determines ransom viability.

06

Victim Data

Machines Infected
Millions
Peak botnet over 1M machines
UK Victims (NCA)
149
Hospitals, schools, businesses
US Hospitals Targeted
~428
2020, per research cited by Wired
Conti Operations Ecosystem
1,000+
Largely via TrickBot access
Notable Victims
VictimSectorNotes
Three Minnesota medical facilitiesHealthcare2020; ambulances diverted, networks and phones disrupted
Universal Health Services (UHS)Healthcare250 facilities affected
Los Angeles Unified School DistrictEducationSecond-largest US school district
Government of Costa RicaGovernment27 institutions; $20M demand (via Conti)
Scripps HealthHealthcareConti on TrickBot-originated access; Galochkin separately indicted in S. California
Sonoma Valley, Hackensack Meridian, Enloe, Sturdy Memorial, UF HealthHealthcareDocumented healthcare victims
07

Financial Profile

Payment Types

Bitcoin (BTC) was the primary payment currency for ransomware demands under the Ryuk and Conti partnerships. TrickBot also deployed an XMRig Monero mining module from January 2018 to generate passive revenue from infected endpoints; some Conti demands accepted Monero.

Revenue Scale
SourceFigureScopeConfidence
Chainalysis (Feb 2023)$724M+Strains related to TrickBot across lifetime; second-highest-earning cybercrime group after LazarusConfirmed
UK NCA£27M (~$33M)149 UK victimsConfirmed
UK NCA$180M+Extorted from victims globallyConfirmed
Dunaev plea agreement$3.4M+Documented fraud, Oct 2018 to Feb 2021 (not total ransomware revenue)Confirmed
Analytical note: The $724M+ figure conflates TrickBot access revenues and Ryuk/Conti/Diavol/Karakurt ransomware revenues. Clean attribution of revenue solely to TrickBot's infrastructure-provision role is not publicly documented. Figures cannot be cleanly disaggregated from public data.
On-Chain Laundering: Documented Evolution
I
Pre-2020: Unregulated Exchanges
Primarily unregulated cryptocurrency exchanges and peer-to-peer markets for cash-out.
II
2020 to 2022: Layered Networks
Ransomware wallets (Conti, Ryuk, Diavol, Karakurt) sent funds to administrator "Stern" (Kovalev), who redistributed to sanctioned individuals including Vakhromeyev (Mushroom), Mikhailov (Baget), Karyagin (Globus), and Sedletski (Strix). Layering used exchanges, mixers, and intermediary wallets.
III
Dedicated Facilitators: PM2BTC and Cryptex
US prosecutors charged Sergey Ivanov ("Taleon") in September 2024 for operating PM2BTC, UAPS, and PinPays, used by Conti and TrickBot to launder proceeds. Ivanov's services processed over $1.15B; TRM Labs estimated over $500M laundered through UAPS/PinPays between 2022 and 2024. Dutch authorities seized the Cryptex exchange (which facilitated ~$1.4B in transactions) in September 2024.
IV
Post-2022: Conti Diaspora Sophistication
Conti diaspora (inheriting TrickBot infrastructure and personnel) adopted cross-chain bridges and privacy-enhancing protocols per TRM Labs reporting.
Wallet designations: OFAC and UK OFSI did not include specific cryptocurrency addresses in the February or September 2023 designations. Chainalysis and TRM Labs independently identified associated wallets using proprietary blockchain analysis.
08

Attribution & Nexus

Assessed Jurisdiction
Confirmed: Russia

Russian jurisdiction is confirmed by US and UK government designations. Russia provided effective safe harbor throughout TrickBot's operational life; all known members residing in Russia have remained protected from extradition. Some members were also based in or operated from Ukraine, Belarus, and Suriname.

Russian Intelligence Services Nexus
Credible: association assessed by US/UK; specific agency and tasking not publicly confirmed

The US Treasury (February 2023) stated that "Members of the Trickbot Group are associated with Russian Intelligence Services" and that their 2020 preparations "aligned them to Russian state objectives and targeting previously conducted by Russian Intelligence Services," including targeting the US government. The UK FCDO used stronger language: key members "highly likely maintain links to the Russian Intelligence Services from whom they have likely received tasking."

  • CIS targeting exclusion: operational avoidance of Russian and CIS victims, consistent with state tolerance
  • 2020 alignment: targeting of US government and healthcare during an election year correlated with Russian state interests
  • Olympic Committee targeting: aligns with documented Russian grievances over Olympic doping sanctions
  • Non-prosecution: despite extensive public identification, no Russian law enforcement action against members has occurred
Evidentiary Gaps
ANALYST INFERENCE: The formal link to specific agencies (FSB, SVR, GRU) is not publicly confirmed by Western governments, which reference "Russian Intelligence Services" collectively. The TrickLeaks "FSB cooperation" claim (March 2022) is single-source and unverified from open sources. The nexus is best characterized as moderate-high confidence that TrickBot operated under Russian state tolerance and probable tasking or coordination, without confirmed evidence of direct operational control by a named service.
Named Individuals
IndividualAlias(es)RoleStatus
Vitaly KovalevStern, Ben, Bentley, Bergen, Alex KonorAssessed founder and leaderBKA-named May 2025; INTERPOL Red Notice; at large in Russia
Alla WitteMax, Alla KlimovaDeveloper; Diavol codeArrested Feb 2021 (Miami); sentenced 2 years 8 months
Vladimir DunaevFFXBrowser-injection developerExtradited Oct 2021; sentenced Jan 2024 to 5 years 4 months
09

Law Enforcement & Disruption History

Infrastructure Takedowns
  • October 2020, Microsoft-led coalition: DCU, FS-ISAC, ESET, Lumen/Black Lotus Labs, NTT, and Symantec conducted a court-authorized seizure/redirect of ~94% of TrickBot's C2 infrastructure (120 of 128 servers). TrickBot rebuilt but at reduced scale.
  • October 2020, US Cyber Command: Concurrent operation pushing poisoned configuration files to bots, replacing C2 IP lists with reserved/loopback addresses; reportedly timed to protect 2020 US election infrastructure.
  • September 2024, PM2BTC / Cryptex: Dutch police seized Cryptex servers; US prosecutors charged Sergey Ivanov for laundering TrickBot/Conti proceeds.
  • May 2025, Operation Endgame: Multi-nation action (US, Germany, France, Canada, UK, Denmark, Netherlands), May 19 to 22; ~300 servers and €3.5M seized during the action week (€21.2M cumulative). BKA publicly named Kovalev as founder; INTERPOL Red Notice issued.
Sanctions and Indictments
ActionDateDetail
First US/UK joint cyber sanctionsFeb 9, 20237 individuals incl. Kovalev, Mikhailov (Baget), Karyagin (Globus), Iskritskiy (Tropa), Pleshevskiy (Iseldor), Vakhromeyev (Mushroom), Sedletski (Strix)
Second joint US/UK actionSep 7, 202311 individuals incl. Zhuykov (Dif), Galochkin (Bentley/Crypt), Rudenskiy, Tsarev (Mango), Putilin, Khaliullin, Loguntsov, Valiakhmetov, Kurov, Chernov (Bullet), Mozhaev (Green)
DOJ indictments unsealedSep 20239 individuals across three federal jurisdictions

Total US/UK designated: 18 individuals across the two 2023 actions, made under Executive Order 13694 as amended. All indicted individuals remain at large in Russia, where extradition is unavailable.

Decryptor Availability
Confirmed: no practical decryptor for active TrickBot-delivered campaigns

TrickBot itself was not an encryptor, so no decryptor applies to it directly. No public decryptor for TrickBot-delivered Conti or Ryuk was released for active campaigns. A Conti decryptor was briefly circulated by a researcher after the ContiLeaks but was of limited practical use.

10

Status & Trajectory

Botnet defunct, personnel active. The TrickBot botnet was voluntarily abandoned on March 1, 2022 after months of internal deliberation. Secureworks (GOLD BLACKBURN) noted the group "retains the capability to reconstitute the botnet at any time." Core personnel migrated to Conti and then dispersed into successor operations. As of July 2026, former TrickBot/Conti operators remain active across the ransomware ecosystem.
Botnet Status
Defunct
Since March 1, 2022
Personnel Status
Active
Via successor groups
Founder Status
Named
Kovalev, Red Notice May 2025
Reconstitution Risk
Retained
Per Secureworks
Dissolution Drivers (2022)
  • Antivirus detection saturation: TrickBot became easily detected; effectiveness as an access tool declined sharply
  • BazarBackdoor maturation: a stealthier, purpose-built replacement was already in use
  • Conti acquisition: core talent had migrated to Conti; the platform was no longer needed standalone
  • Microsoft and Cyber Command disruption (Oct 2020): imposed operational burden and accelerated detection
  • Law enforcement pressure: arrests of Witte and Dunaev, indictments, and sanctions raised personal risk
Connected Group Cluster

Anchor relationships (Dyre predecessor, Emotet distribution partner, Ryuk and Conti ransomware partners, Diavol, BazarLoader/Anchor successor tooling) are assessed with high confidence and multi-source corroboration. Extension claims into later successors carry lower confidence.

CONFIRMED anchor relationships: Dyre (predecessor), Emotet (distribution), Ryuk and Conti (ransomware partners; Conti acquirer), Diavol (FBI-linked Jan 2022), BazarLoader and Anchor (successor tooling). Corroborated by multiple vendors and leaked internal communications.
CREDIBLE extension (Black Basta): Black Basta emerged April 2022; the dominant assessment is that a senior subset of Conti/TrickBot operators formed it, taking tooling and affiliates. Assessed with moderate-high confidence by AdvIntel, CrowdStrike, Secureworks, and BKA. The "permadll" naming-continuity claim between TrickBoot and Black Basta is single-source (Scott Scheferman) and not independently confirmed.
ANALYST INFERENCE (QakBot overlap): QakBot was used by Black Basta as an initial access vector (2022 to 2023), with some infrastructure overlap to TrickBot/Conti-adjacent networks documented during Operation Endgame. Moderate confidence on specific infrastructure overlap; neither Mandiant nor Recorded Future have published a formal TrickBot-QakBot organizational-continuity assessment.
Intelligence Gaps
  • Agency-specific nexus (FSB vs. SVR vs. GRU) not publicly confirmed
  • Revenue disaggregation: the $724M+ figure conflates TrickBot and partner ransomware revenues
  • US/UK had not publicly linked Kovalev to the "Stern" handle before the German BKA did so in May 2025
  • TrickBoot was confirmed to check BIOS write protection but never confirmed to destructively write firmware in the wild
  • CIS kill switch confirmed in BazarLoader; inferred but not uniformly confirmed in the TrickBot core binary

Sources

Primary Government Sources
[1]US Treasury OFAC: TrickBot designations, Feb 9 & Sep 7, 2023 – home.treasury.gov
[2]UK NCA: Ransomware criminals sanctioned in joint UK/US crackdown, 2023 – nationalcrimeagency.gov.uk
[3]German BKA: Operation Endgame, Kovalev ("Stern") identification, May 2025 – bka.de
[4]FBI Flash: Indicators of Compromise Associated with Diavol Ransomware, Jan 19, 2022 – aha.org
[5]US Treasury: PM2BTC and Cryptex coordinated actions, Sep 2024 – home.treasury.gov
[6]NVD: CVE-2017-0144 (EternalBlue, MS17-010) – nvd.nist.gov
[7]MITRE ATT&CK G0102 (Wizard Spider) – attack.mitre.org
Vendor Intelligence and Threat Research
[8]Secureworks: GOLD BLACKBURN threat profile – secureworks.com
[9]Microsoft: Periwinkle Tempest (formerly DEV-0193) threat actor – microsoft.com
[10]Chainalysis: US and UK sanction Russia-based TrickBot cybercrime gang, Feb 2023 – chainalysis.com
[11]TRM Labs: US Treasury actions against PM2BTC and Cryptex, 2024 – trmlabs.com
[12]Eclypsium / AdvIntel: TrickBoot: Persist, Brick, Profit, Dec 2020 – eclypsium.com
[13]BleepingComputer: TrickBoot module infects UEFI firmware, Dec 2020 – bleepingcomputer.com
[14]BleepingComputer: Germany doxxes Conti/TrickBot ring leader, May 2025 – bleepingcomputer.com
[15]BleepingComputer: US and UK sanction 11 TrickBot and Conti members, Sep 2023 – bleepingcomputer.com
[16]Fidelis Cybersecurity: TrickBot / Dyre code-overlap analysis, Sep 2016
[17]IBM X-Force / ESET: Anchor, Bazar, and TrickBot technical analysis (VB2020)
[18]Recorded Future: Dark Covenant 3.0, Oct 2025 – recordedfuture.com
Research Basis
[19]Perplexity Deep Research: TrickBot deep-dive (primary research document), Jul 2026
[20]Vladimir Dunaev plea agreement and sentencing documents (DOJ)