TrickBot Ditches HTTP for DNS Tunneling in Latest Variant
2026-07-22T20:52:13Z•a7434d56b9f59ce4317e84ae23a099a85fdb8194f24efec2aa9fd9669deb3394
ai-securityc2cisacodemendercruciferracryptominingdeepfakedns tunnelingevasionfortinethollowgraphjadempufferjailbroken-claudelocal-privilege-escalationmicrosoft-graphmicrosoft-patch-tuesdayopenaipatchingphishingransomwaresecure-boot-bypasssnap-confinetrickbotubuntuuefi
What happened
A broad set of active threats and systemic risks were reported: a new TrickBot variant moved C2 to DNS tunneling, HollowGraph abused Microsoft 365 calendars/Graph API for covert C2, and multiple malware campaigns (ransomware, crypters, macOS stealers, trojans) continue to evolve evasion techniques. Privilege/escalation issues were highlighted by an Ubuntu snap‑confine race condition allowing local root, and eleven Microsoft‑signed UEFI shims that can bypass Secure Boot. Governments and vendors are responding: CISA issued urgent patching for actively exploited Fortinet flaws and Microsoft fixed
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- a7434d56b9f59ce4317e84ae23a099a85fdb8194f24efec2aa9fd9669deb3394
- Enrichment time
- 2026-07-22T20:52:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.