Overview
TrickBot was a Russia-based, highly modular malware ecosystem operated by a financially motivated criminal enterprise from October 2016 until the botnet infrastructure was voluntarily abandoned on March 1, 2022. It began as a banking trojan targeting Australian financial institutions and evolved into the dominant initial-access and loader platform of its era, provisioning compromised networks to the Ryuk and Conti ransomware operations. The group functioned as a backend criminal service rather than a public-facing extortion brand: it never operated a data leak site in its own name, and ransom demands were issued under partner brands.
The group is tracked across the threat intelligence community under multiple designations. It is assessed with high confidence as a direct descendant of the Dyre banking trojan, and its core personnel were absorbed into Conti by early 2022 before dispersing into successor operations. As of July 2026, the TrickBot platform is defunct but its operators remain active in the broader ransomware ecosystem, and its alleged founder was publicly named by German authorities in May 2025.
| Attribute | Detail |
|---|---|
| Tracking aliases (group-specific) | GOLD BLACKBURN (Secureworks, TrickBot operators), Periwinkle Tempest / DEV-0193 (Microsoft), UNC1878 and UNC2053 (Mandiant clusters). WIZARD SPIDER (CrowdStrike) and MITRE G0102 designate the broader parent syndicate, not TrickBot alone. |
| Predecessor lineage | Direct descendant of Dyre / Dyreza banking trojan (2014 to 2015), assessed with high confidence by Secureworks, Fidelis, US Treasury, and UK FCDO |
| Operational model | Closed operator and access broker; not an open RaaS. Malware-as-a-service provisioning to trusted ransomware partners (Ryuk, Conti, Diavol) |
| Extortion mechanic | None directly. Extortion (including Conti double extortion) conducted by partner ransomware deployed on TrickBot-originated access |
| Assessed jurisdiction | Russia (CONFIRMED by US/UK government designations); safe harbor throughout operational life |
| Operational status | Botnet defunct since March 2022; personnel migrated to Conti then to Black Basta, Royal, and other successors |
TrickBot did not operate a public data leak site. In place of DLS imagery, the gallery below documents TrickBot-specific artifacts: its landmark UEFI firmware module, its firmware-reconnaissance code, and the attribution of its alleged founder.
Origin & Lineage
TrickBot was first identified in the wild in October 2016, with the earliest samples (September 2016) targeting customers of Australian banks (ANZ, Westpac, St. George, NAB). It was first publicly reported by Fidelis Cybersecurity and Malwarebytes as a banking trojan. Early monetization was credential theft and banking fraud, not extortion. The malware evolved continuously across a six-year window, adding worm propagation, backdoors, and ransomware-delivery functionality.
There is high-confidence, multi-vendor consensus that TrickBot is a direct descendant of the Dyre (Dyreza) banking trojan, active from June 2014 until Russian law enforcement disrupted it in November 2015 through raids on a Moscow film-distribution company assessed to be a front. Secureworks assesses GOLD BLACKBURN with high confidence as a direct descendant of Dyre. The US Treasury and UK FCDO official statements explicitly state TrickBot "evolved from the Dyre trojan."
GOLD BLACKBURN (Secureworks) is the group-specific designation for the TrickBot botnet operators, assessed as authors and operators of TrickBot from 2016 to March 2022 and of BazarLoader, Anchor, and related tooling. Periwinkle Tempest (formerly DEV-0193) is Microsoft's designation for the same actor responsible for developing and managing TrickBot, BazarLoader, AnchorDNS, Ryuk, Conti, and Diavol. Mandiant tracked the TrickBot-to-Ryuk intrusion activity as UNC1878, with UNC2053 as a related cluster designation. CrowdStrike's WIZARD SPIDER (equivalent to MITRE ATT&CK G0102) spans TrickBot, Ryuk, and Conti as sequential campaigns of one organization.
Operational Model
TrickBot operated as a closed operator, not an open RaaS platform. It developed and maintained its own malware infrastructure and provided access to select ransomware partners rather than openly advertising affiliate slots. The BKA assessed that, at times, the group exceeded 100 members and worked in an organized, hierarchically structured, project- and profit-oriented manner. By 2020 to 2021, the group had become a de facto access broker exclusively serving the Conti syndicate, which ultimately acquired the operation.
- Developer core: Structured hierarchy with named roles: administrators (Stern / Kovalev), team leads for coders, test leads, HR and finance managers, infrastructure procurement, and server administrators.
- Ransomware partnerships: Ryuk from 2018; near-exclusive provisioning to Conti by 2020; also linked to Diavol (FBI-confirmed, January 2022).
- Talent structure: Investigators assess at least 17 members in functional roles including malware managers, developers, crypters, and spammers; BKA cites more than 100 at peak.
TrickBot did not run a public affiliate recruitment program in the manner of LockBit or REvil. Collaboration was through controlled partnerships with trusted ransomware groups. BazarLoader, developed as TrickBot's stealthier successor, was similarly operated as a closed platform. No public forum recruitment advertisements have been attributed to TrickBot specifically; the group maintained operational secrecy about its internal structure.
| Phase | Period | Monetization |
|---|---|---|
| Direct fraud | 2016 to 2018 | Credential theft from banking customers; wire transfer fraud |
| Access broker / MaaS | 2018 to 2022 | Initial access and persistence sold to ransomware operators for revenue share |
| Ransomware revenue share | 2018 to 2022 | Share of ransoms extorted by Ryuk and Conti from TrickBot-originated access |
Specific revenue-split terms between TrickBot and its ransomware partners have not been publicly documented in court filings or leaked data. Chainalysis identified cryptocurrency payments from Conti, Ryuk, Diavol, and Karakurt wallets flowing to administrator "Stern" (Kovalev), corroborating revenue sharing, but exact ratios remain unconfirmed from public sources.
TrickBot did not conduct ransom negotiations directly; these were handled by the ransomware partners deploying payloads onto TrickBot-compromised networks. Under the Conti partnership, extortion followed a double-extortion model: data exfiltration preceding encryption, with publication threats on Conti's "Conti News" leak site. Ransom amounts were set by the partner and ranged from hundreds of thousands to tens of millions of dollars depending on victim revenue. Per US Treasury, group members "publicly gloated" over the speed of ransom payments from healthcare victims during the COVID-19 pandemic.
Technical Profile
TrickBot was a highly modular malware ecosystem. The core bot loaded plugin modules dynamically, allowing operators to deploy capabilities selectively against high-value targets. This modularity made complete takedown and detection significantly harder than for monolithic malware. Configuration files used a rolling 4-byte XOR scheme for C2 obfuscation, with key and config length hardcoded at fixed offsets.
| Vector | Detail |
|---|---|
| Phishing / spearphishing | Primary delivery: macro-enabled Office documents; fake invoices, bank documents, COVID-19 lures |
| Emotet delivery | From mid-2018, Emotet installed TrickBot as a secondary payload; the Emotet to TrickBot to Ryuk/Conti chain was a dominant attack pattern |
| SMB exploitation (EternalBlue) | Worm component for lateral movement and self-propagation using leaked NSA exploits |
| TrickBooster spam module | Discovered 2019; used infected machines to propagate further TrickBot infections |
| Malicious Google Docs links | Documented delivery vector |
| CVE | Product | Type | Use |
|---|---|---|---|
| CVE-2017-0144 | Windows SMBv1 (MS17-010) | Remote code execution | EternalBlue; worm propagation within networks (NVD-verified) |
| CVE-2017-0145 | Windows SMBv1 (MS17-010) | Remote code execution | EternalRomance; lateral movement (NVD-verified) |
| CVE-2020-14871 | Oracle Solaris PAM | Buffer overflow | Attributed primarily to UNC1945; ecosystem capability only, not confirmed for TrickBot core (single-source) |
TrickBoot (internally "PermaDll" / user_platform_check.dll) was a landmark module able to read, write, and erase UEFI/BIOS firmware. It used the RwDrv.sys driver from the public RWEverything tool to interact with the SPI controller governing system firmware, the same driver used by the state-linked LoJax rootkit. This enabled persistence that survives OS reinstalls and drive replacement. At time of discovery, the module was only observed checking whether BIOS write protection was enabled (reconnaissance), making TrickBot the first non-state-sponsored, financially motivated actor to probe UEFI-level persistence in real-world deployments. Prior UEFI implants (LoJax, MosaicRegressor) had been observed only in nation-state operations.
- Registry run-key persistence and scheduled tasks (Task Scheduler)
- Mimikatz for Windows credential harvesting (NTLM hashes, Kerberos tickets)
- Cobalt Strike for post-exploitation lateral movement and network mapping
- SMB-based worm propagation using EternalBlue
- Active Directory credential theft module (Windows 10 UAC bypass, January 2020)
- Theft of OpenSSH and OpenVPN keys (November 2019); VNC, PuTTY, and RDP credentials
TrickBot's own malware was a loader and access tool, not a ransomware encryptor. Encryption was performed by deployed partners: Ryuk (AES-256 for files, RSA-2048 for keys); Conti (AES-256, ChaCha20 in later variants, multi-threaded fast encryption via asynchronous I/O); Diavol (asynchronous I/O file queuing with command-line parameters nearly identical to Conti, per IBM X-Force; appends the .lock64 extension).
BazarLoader (TrickBot's successor tool) is confirmed by MITRE ATT&CK (S0534) to check whether the OS keyboard and language settings are Russian, halting execution if detected, a standard CIS-exclusion behavior. For the TrickBot core binary, the operational behavior of avoiding Russian and CIS victims was consistent and deliberate (per US Treasury), but explicit technical documentation of a Russian keyboard kill switch in the core binary (distinct from BazarLoader) is not uniformly confirmed across public vendor reports. Analysts should treat the core-binary kill switch as inferred, not confirmed.
- TrickBot Linux variant: TrickBot began infecting Linux systems as of July 2020; a Linux port was actively deployed.
- Anchor Linux: The Anchor backdoor (first observed August 2018) had a confirmed Linux variant (anchor_linux), extending reach to Linux servers.
- ESXi/VMware: Primary ESXi targeting was conducted by Conti (Linux ESXi encryptor); TrickBot provided the initial access that enabled Conti to reach ESXi environments.
Targeting
| Sector | Notes |
|---|---|
| Healthcare / hospitals | Most intensively targeted during 2020 COVID-19 pandemic; ~428 US hospitals targeted per research cited by Wired; three Minnesota medical centers disrupted, ambulances diverted |
| Financial services | Original banking trojan function; credential theft from banking customers globally |
| Government / public sector | US government entities; 27 Costa Rican institutions (via Conti); UK local authorities |
| Education | Schools and districts; Los Angeles Unified School District attack linked to the TrickBot group |
| Critical infrastructure | Law enforcement, EMS, 911 dispatch (per US advisories); 16 attacks on US emergency responders documented |
| Retail and manufacturing | Anchor backdoor campaigns specifically targeted financial, manufacturing, and retail sectors |
Primary target geographies were the United States (healthcare, government, financial), the United Kingdom (149 confirmed NCA victims), and Europe (Germany, Netherlands). Documented targeting also reached India and Australia. Russian, Belarusian, and CIS-region entities were operationally excluded as victims, consistent with a state-tolerated operator model. The UK government assessed that targeting of the International Olympic Committee "almost certainly aligns with Russian state objectives."
In its initial phase (2016 to 2018) TrickBot primarily hit small and medium businesses and individual banking customers. In its evolved phase (2019 to 2022) targeting shifted toward mid-market and large enterprise, government, and critical infrastructure, reflecting the ransomware-deployment model where victim size determines ransom viability.
Victim Data
| Victim | Sector | Notes |
|---|---|---|
| Three Minnesota medical facilities | Healthcare | 2020; ambulances diverted, networks and phones disrupted |
| Universal Health Services (UHS) | Healthcare | 250 facilities affected |
| Los Angeles Unified School District | Education | Second-largest US school district |
| Government of Costa Rica | Government | 27 institutions; $20M demand (via Conti) |
| Scripps Health | Healthcare | Conti on TrickBot-originated access; Galochkin separately indicted in S. California |
| Sonoma Valley, Hackensack Meridian, Enloe, Sturdy Memorial, UF Health | Healthcare | Documented healthcare victims |
Financial Profile
Bitcoin (BTC) was the primary payment currency for ransomware demands under the Ryuk and Conti partnerships. TrickBot also deployed an XMRig Monero mining module from January 2018 to generate passive revenue from infected endpoints; some Conti demands accepted Monero.
| Source | Figure | Scope | Confidence |
|---|---|---|---|
| Chainalysis (Feb 2023) | $724M+ | Strains related to TrickBot across lifetime; second-highest-earning cybercrime group after Lazarus | Confirmed |
| UK NCA | £27M (~$33M) | 149 UK victims | Confirmed |
| UK NCA | $180M+ | Extorted from victims globally | Confirmed |
| Dunaev plea agreement | $3.4M+ | Documented fraud, Oct 2018 to Feb 2021 (not total ransomware revenue) | Confirmed |
Attribution & Nexus
Russian jurisdiction is confirmed by US and UK government designations. Russia provided effective safe harbor throughout TrickBot's operational life; all known members residing in Russia have remained protected from extradition. Some members were also based in or operated from Ukraine, Belarus, and Suriname.
The US Treasury (February 2023) stated that "Members of the Trickbot Group are associated with Russian Intelligence Services" and that their 2020 preparations "aligned them to Russian state objectives and targeting previously conducted by Russian Intelligence Services," including targeting the US government. The UK FCDO used stronger language: key members "highly likely maintain links to the Russian Intelligence Services from whom they have likely received tasking."
- CIS targeting exclusion: operational avoidance of Russian and CIS victims, consistent with state tolerance
- 2020 alignment: targeting of US government and healthcare during an election year correlated with Russian state interests
- Olympic Committee targeting: aligns with documented Russian grievances over Olympic doping sanctions
- Non-prosecution: despite extensive public identification, no Russian law enforcement action against members has occurred
| Individual | Alias(es) | Role | Status |
|---|---|---|---|
| Vitaly Kovalev | Stern, Ben, Bentley, Bergen, Alex Konor | Assessed founder and leader | BKA-named May 2025; INTERPOL Red Notice; at large in Russia |
| Alla Witte | Max, Alla Klimova | Developer; Diavol code | Arrested Feb 2021 (Miami); sentenced 2 years 8 months |
| Vladimir Dunaev | FFX | Browser-injection developer | Extradited Oct 2021; sentenced Jan 2024 to 5 years 4 months |
Law Enforcement & Disruption History
- October 2020, Microsoft-led coalition: DCU, FS-ISAC, ESET, Lumen/Black Lotus Labs, NTT, and Symantec conducted a court-authorized seizure/redirect of ~94% of TrickBot's C2 infrastructure (120 of 128 servers). TrickBot rebuilt but at reduced scale.
- October 2020, US Cyber Command: Concurrent operation pushing poisoned configuration files to bots, replacing C2 IP lists with reserved/loopback addresses; reportedly timed to protect 2020 US election infrastructure.
- September 2024, PM2BTC / Cryptex: Dutch police seized Cryptex servers; US prosecutors charged Sergey Ivanov for laundering TrickBot/Conti proceeds.
- May 2025, Operation Endgame: Multi-nation action (US, Germany, France, Canada, UK, Denmark, Netherlands), May 19 to 22; ~300 servers and €3.5M seized during the action week (€21.2M cumulative). BKA publicly named Kovalev as founder; INTERPOL Red Notice issued.
| Action | Date | Detail |
|---|---|---|
| First US/UK joint cyber sanctions | Feb 9, 2023 | 7 individuals incl. Kovalev, Mikhailov (Baget), Karyagin (Globus), Iskritskiy (Tropa), Pleshevskiy (Iseldor), Vakhromeyev (Mushroom), Sedletski (Strix) |
| Second joint US/UK action | Sep 7, 2023 | 11 individuals incl. Zhuykov (Dif), Galochkin (Bentley/Crypt), Rudenskiy, Tsarev (Mango), Putilin, Khaliullin, Loguntsov, Valiakhmetov, Kurov, Chernov (Bullet), Mozhaev (Green) |
| DOJ indictments unsealed | Sep 2023 | 9 individuals across three federal jurisdictions |
Total US/UK designated: 18 individuals across the two 2023 actions, made under Executive Order 13694 as amended. All indicted individuals remain at large in Russia, where extradition is unavailable.
TrickBot itself was not an encryptor, so no decryptor applies to it directly. No public decryptor for TrickBot-delivered Conti or Ryuk was released for active campaigns. A Conti decryptor was briefly circulated by a researcher after the ContiLeaks but was of limited practical use.
Status & Trajectory
- Antivirus detection saturation: TrickBot became easily detected; effectiveness as an access tool declined sharply
- BazarBackdoor maturation: a stealthier, purpose-built replacement was already in use
- Conti acquisition: core talent had migrated to Conti; the platform was no longer needed standalone
- Microsoft and Cyber Command disruption (Oct 2020): imposed operational burden and accelerated detection
- Law enforcement pressure: arrests of Witte and Dunaev, indictments, and sanctions raised personal risk
Anchor relationships (Dyre predecessor, Emotet distribution partner, Ryuk and Conti ransomware partners, Diavol, BazarLoader/Anchor successor tooling) are assessed with high confidence and multi-source corroboration. Extension claims into later successors carry lower confidence.
- Agency-specific nexus (FSB vs. SVR vs. GRU) not publicly confirmed
- Revenue disaggregation: the $724M+ figure conflates TrickBot and partner ransomware revenues
- US/UK had not publicly linked Kovalev to the "Stern" handle before the German BKA did so in May 2025
- TrickBoot was confirmed to check BIOS write protection but never confirmed to destructively write firmware in the wild
- CIS kill switch confirmed in BazarLoader; inferred but not uniformly confirmed in the TrickBot core binary