
TrickBot Disguises Scheduled Task as Wireshark Update to Maintain Windows Persistence
FortiGuard researchers captured malicious samples that sent malformed DNS queries and identified them as TrickBot variants. Unlike older TrickBot campaigns that mainly used HTTP for command-and-control communications, this version hides its traffic in DNS requests and responses. TrickBot is a modular malware family that can download extra components after infecting a device. This design lets […]
The post TrickBot Disguises Scheduled Task as Wireshark Update to Maintain Windows Persistence appeared first on Cyber Security News.