Global Network had become a pain to work with and RM3_boss decided to rent Dridex for a few months until RM3 became ready.
Dridex
Dridex is a banking trojan/financial malware family associated with the Russian cybercriminal group Evil Corp.
Profile source: Mallory opens in a new tabDridex
Family profile
Dridex is a banking trojan/financial malware family associated with the Russian cybercriminal group Evil Corp. The provided content states that U.S. authorities said Dridex caused more than $100 million in financial losses worldwide, and that Evil Corp was sanctioned in 2019 for developing and distributing the malware. Dridex has been delivered through spearphishing and spam emails with malicious attachments or links, relying on user execution. The content also states that Dridex uses encoded PowerShell commands to download and execute malicious payloads, and that it has used HTTPS and HTTP POST requests for command-and-control communications. Multiple references describe Dridex as part of the broader initial-access and malware-delivery ecosystem: it has been used by TA505 in large-scale campaigns, has been rented or used by other criminal operators, and has served as first-stage malware whose access may later be sold to ransomware operators. The content further places Dridex among banking trojans that shifted over time from pure banking fraud toward loader and ransomware-enablement roles. Dridex is repeatedly linked in the content to Evil Corp’s wider criminal operations, including ransomware and money laundering. The alias provided in the content is bugat_v5.
Reported operators
Threat actors
6 named in public reportingThese criminal threat actors compromise victim organizations with first-stage malware like The Trick, Dridex, or Buer Loader and will then sell their access to ransomware operators to deploy data theft and encryption operations.
the messages and the delivery suggest they were sent by threat actor TA505, known for sending large-scale Dridex, Locky, and GlobeImposter campaigns, among others, over the last four years.
These criminal threat actors compromise victim organizations with first-stage malware like The Trick, Dridex, or Buer Loader and will then sell their access to ransomware operators to deploy data theft and encryption operations.
Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Dridex, a banking trojan
"TA573 is an affiliate distributor of Dridex, a malware strain that resurged in 2020... The malware itself is a creation of a Russian cyber crime group that calls itself Evil Corp..."
Exploited software
Vulnerabilities linked to Dridex
2 CVEsMITRE ATT&CK