TrickBot collects local files and information from the victim’s local machine.5
tool
TrickBot S0266
- Type
- malware
- Platform
- Windows
- Created
- 17 October 2018
- Last modified
- 10 April 2024
TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.[1][2][3][4]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S0266
TrickBot collects a list of install programs and services on the system’s machine.6
TrickBot can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers.7
TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine.8910
TrickBot has used a VNC module to monitor the victim and collect information to pivot to valuable systems on the network 1213
Standing S0266
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
99th percentile · 99% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
100th percentile · None of the 825 ATT&CK software entries has more tactics spanned — the highest in the population.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
38th percentile · 62% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S0266
1794 distinct rules cover the 55 techniques recorded for this tool. The 2128 technique-to-rule mappings resolve to 1794 distinct rules, because one rule can cover several techniques. 1148 Sigma · 646 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org