Skip to content

Dridex

Dridex is a banking trojan/financial malware family associated with the Russian cybercriminal group Evil Corp.

Profile source: Mallory opens in a new tab

Dridex

Family profile

Dridex is a banking trojan/financial malware family associated with the Russian cybercriminal group Evil Corp. The provided content states that U.S. authorities said Dridex caused more than $100 million in financial losses worldwide, and that Evil Corp was sanctioned in 2019 for developing and distributing the malware. Dridex has been delivered through spearphishing and spam emails with malicious attachments or links, relying on user execution. The content also states that Dridex uses encoded PowerShell commands to download and execute malicious payloads, and that it has used HTTPS and HTTP POST requests for command-and-control communications. Multiple references describe Dridex as part of the broader initial-access and malware-delivery ecosystem: it has been used by TA505 in large-scale campaigns, has been rented or used by other criminal operators, and has served as first-stage malware whose access may later be sold to ransomware operators. The content further places Dridex among banking trojans that shifted over time from pure banking fraud toward loader and ransomware-enablement roles. Dridex is repeatedly linked in the content to Evil Corp’s wider criminal operations, including ransomware and money laundering. The alias provided in the content is bugat_v5.

Reported operators

Threat actors

6 named in public reporting
Indrik Spider

Global Network had become a pain to work with and RM3_boss decided to rent Dridex for a few months until RM3 became ready.

TA575

These criminal threat actors compromise victim organizations with first-stage malware like The Trick, Dridex, or Buer Loader and will then sell their access to ransomware operators to deploy data theft and encryption operations.

TA505

the messages and the delivery suggest they were sent by threat actor TA505, known for sending large-scale Dridex, Locky, and GlobeImposter campaigns, among others, over the last four years.

TA544

These criminal threat actors compromise victim organizations with first-stage malware like The Trick, Dridex, or Buer Loader and will then sell their access to ransomware operators to deploy data theft and encryption operations.

Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Dridex, a banking trojan

TA573

"TA573 is an affiliate distributor of Dridex, a malware strain that resurged in 2020... The malware itself is a creation of a Russian cyber crime group that calls itself Evil Corp..."

Exploited software

Vulnerabilities linked to Dridex

2 CVEs

MITRE ATT&CK

Dridex in ATT&CK

51 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.