TrickBot Ditches HTTP for DNS Tunneling in Latest Variant

2026-07-22T20:52:13Za7434d56b9f59ce4317e84ae23a099a85fdb8194f24efec2aa9fd9669deb3394
ai-securityc2cisacodemendercruciferracryptominingdeepfakedns tunnelingevasionfortinethollowgraphjadempufferjailbroken-claudelocal-privilege-escalationmicrosoft-graphmicrosoft-patch-tuesdayopenaipatchingphishingransomwaresecure-boot-bypasssnap-confinetrickbotubuntuuefi

What happened

A broad set of active threats and systemic risks were reported: a new TrickBot variant moved C2 to DNS tunneling, HollowGraph abused Microsoft 365 calendars/Graph API for covert C2, and multiple malware campaigns (ransomware, crypters, macOS stealers, trojans) continue to evolve evasion techniques. Privilege/escalation issues were highlighted by an Ubuntu snap‑confine race condition allowing local root, and eleven Microsoft‑signed UEFI shims that can bypass Secure Boot. Governments and vendors are responding: CISA issued urgent patching for actively exploited Fortinet flaws and Microsoft fixed

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
a7434d56b9f59ce4317e84ae23a099a85fdb8194f24efec2aa9fd9669deb3394
Enrichment time
2026-07-22T20:52:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.