Inside a TrickBot Variant Using DNS Tunneling for C2
Fortinet, Wednesday, July 22nd, 2026
FortiGuard Labs analyzes a TrickBot variant that hides C2 traffic inside DNS queries to evade network defenses.
FortiGuard Labs dissects a TrickBot variant that swaps HTTP for DNS tunneling to conduct command-and-control, concealing malicious traffic inside legitimate-looking DNS queries and responses.
The malware uses encrypted strings, runtime API resolution, and Windows Task Scheduler persistence, while encoding command data via XOR and hex and embedding it in domain names and IPv4 response addresses.
Its modular design supports command execution, process injection, and PowerShell, giving attackers full control of the victim. Data transfer reaches roughly 30.7 KB/s over the DNS channel, enough to deliver additional malicious modules.