The TrickBot malware operation has been shut down after its core developers moved to the Conti ransomware gang to focus development on the stealthy BazarBackdoor and Anchor malware families.
See also: SockDetour malware used as a Windows backdoor

TrickBot is a notorious Windows malware infection that has dominated the threat landscape since 2016.
The malware is usually installed via malicious phishing emails or other malware and will run silently on the victim's computer while downloading modules to perform different tasks.
These modules perform a wide range of malicious activities, such as stealing a domain's Active Directory Services database, spreading laterally across a network, locking the screen, stealing browser cookies and passwords, and stealing OpenSSH keys.
TrickBot has a long-standing relationship with ransomware operations that collaborated with the TrickBot group to gain initial access to networks infected by the malware.
See also: Malware has infiltrated the Microsoft Store using game clones
In 2019, the TrickBot group partnered with the Ryuk ransomware operation to provide the ransomware gang with initial access to networks. In 2020, the Conti ransomware group, believed to be a rebrand of Ryuk, partnered with TrickBot for initial access.
In 2021, TrickBot attempted to start its own ransomware operation called Diavol, which didn't go too well, likely because one of its developers was arrested.
Despite numerous takedown attempts by law enforcement, TrickBot successfully rebuilt its botnet and continued to terrorize Windows networks.
This was the case until December 2021, when its distribution campaigns suddenly stopped.
TrickBot's business is being shut down
Over the past year, Conti has become one of the most resilient and profitable ransomware, responsible for numerous attacks on high-profile victims – it has collected hundreds of millions of dollars in ransom payments.
As reported by BleepingComputer, due to the vast wealth and capital at their disposal and the TrickBot primarily used by Conti, the ransomware gang slowly took control of the business.
However, Conti did not hire these “elite programmers and administrators” to work on the TrickBot malware, but to work on the more stealthy BazarBackdoor and Anchor malware families, as evidenced by internal conversations shared by cybersecurity firm AdvIntel.
AdvIntel explained last week that the change in deployment is because the TrickBot malware is very easily detected by security software and that the operation will be terminated soon.
Yesterday, AdvIntel CEO Vitali Kremez told BleepingComputer that the TrickBot group had shut down all infrastructure for running the TrickBot malware.
See also: Nvidia: Tool that overturns GPU restrictions was actually malware
In a conversation with Kremez, BleepingComputer was informed that the Conti ransomware is now controlling the development of the TrickBot malware for its own needs.
With this termination, Kremez explained that the TrickBot ring is now focused almost entirely on ransomware and hacking networks.
A report published yesterday by the company Intel471 confirmed that the business would be terminated in favor of more profitable platforms.
While it's obviously a good thing that a malware operation is shut down, almost always the hackers have already moved on to another ransomware gang.
BazarBackdoor's email distribution has already increased over the past six months, but with TrickBot's shutdown, we'll likely see it spread further.
Information source: bleepingcomputer.com
