Advisory: Trickbot
How organisations can protect their networks from the ‘Trickbot’ banking trojan.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

Trickbot is an established banking trojan used in cyber attacks against businesses and individuals in the UK and overseas. Trickbot attacks are designed to access online accounts, including bank accounts, in order to obtain personally identifiable information (PII). Criminals use PII to commit identity fraud.
In some cases, Trickbot is used to infiltrate a network. Once inside it can be used to deploy other malware, including ransomware and post-exploitation toolkits.
Trickbot targets victims with well-crafted phishing emails, designed to appear as though sent from trusted commercial or government brands. These emails will often contain an attachment (or link to an attachment) which victims are instructed to open, leading to their machine being exploited.
Trickbot can download new capabilities onto a victim’s device (as well as updating those it has already deployed) without interaction from the victim.
Trickbot can:
Victims of Trickbot have observed a number of malicious activities, including:
To protect business and personal banking facilities (including where employees have accessed personal banking from work devices) you should:
If you (or your employees) have been the victim of fraud, report it to Action Fraud.
Run a full scan on all devices using up-to-date antivirus software, such as Windows Defender. This should detect and remove any Trickbot infection.

