Skip to content

Dridex

Dridex is a modular banking Trojan and malware delivery platform that emerged from the Cridex/Bugat lineage and became one of the most prevalent financial malware families targeting online banking users and financial institutions.

Profile source: Mallory opens in a new tab

Dridex

Family profile

Dridex is a modular banking Trojan and malware delivery platform that emerged from the Cridex/Bugat lineage and became one of the most prevalent financial malware families targeting online banking users and financial institutions. It is strongly associated with Evil Corp and has also been linked in industry reporting to TA505, while multiple threat actors have distributed it over time. Dridex has been used both for direct financial theft and as an access-enablement malware family in broader post-compromise operations, including ransomware deployment.

Dridex is primarily distributed through phishing and malspam campaigns that use business-themed lures and malicious attachments, often compressed archives containing macro-enabled Microsoft Office documents. Victims are commonly induced to enable macros or otherwise execute embedded content, after which Dridex retrieves and launches additional components. Recent activity has also included exploitation of Microsoft Office vulnerability CVE-2017-0199, and modified variants such as DoppelDridex have been delivered through payloads staged on trusted messaging-service CDNs using Excel 4.0 macro documents. Dridex has also been observed delivered by other malware distribution frameworks, including Emotet and SocGholish.

Functionally, Dridex is designed to steal banking credentials and facilitate fraud. It can inject into browser sessions, monitor access to online banking portals, use API hooking and keylogging to capture credentials, and collect screenshots and other victim data. Stolen information is packaged, encrypted, and transmitted over peer-to-peer communications. Dridex is modular and can download additional components after initial infection, enabling botnet participation and expanded functionality. Reported execution and persistence behaviors include use of regsvr32 to initiate malicious code, as well as techniques involving file modification, privilege escalation, and firewall-rule changes to support communications and continued access.

Beyond credential theft, Dridex has played a major role as an initial-access and follow-on malware enabler. It has been linked to delivery chains and operational overlap involving Locky and ransomware families such as BitPaymer and DoppelPaymer, and has been cited as a loader used to provide network access for later ransomware deployment. Victimology has historically been broad, with a notable concentration on English-speaking countries and the financial services sector, though Dridex-enabled operations have affected enterprises and government organizations across multiple industries.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 22, 2026
Feed role
C2 / Distribution
Host form
3 IP / 1 hostnames

Leading locations

  • IT2
  • DE1
  • TW1

Leading providers

  • Data Communication Business Group1
  • Explorer Servizi S.R.L1
  • Pegaso Srl1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

12 named in public reporting
TA505

A modified version of the banking trojan Dridex – named DoppelDridex – is being delivered via payloads staged on Slack and Discord CDNs.

DoppelSpider

A modified version of the banking trojan Dridex – named DoppelDridex – is being delivered via payloads staged on Slack and Discord CDNs.

INDRIK SPIDER

The Treasury Department has similarly said Maksim Yakubets, the alleged leader of the Evil Corp cybercrime organization, worked for the FSB and was tasked with projects on behalf of the Russian state while his organization carried out financially motivated attacks.

FIN7

Dridex — Malware-as-a-Service 2016-2018 — Pour distribuer Carbanak.

TA544

Typically, this group varies its payloads which appear to be targeted by region – for example, in 2021, all TA544 Ursnif campaigns have specifically targeted Italian organizations while Dridex payloads associated with this threat actor do not have specific geographic targeting.

TA575

The emails contained links to download Microsoft Excel documents containing macros that, when enabled, downloaded the Dridex malware designed to steal banking and other personal information.

DOPPEL SPIDER

Dridex, apparu en juin 2014, est la cinquième variante du code malveillant Bugat actif de 2010 à 2013, agrémenté de particularités propres à GameOverZeuS. Sa fonctionnalité première est celle d’un stealer, c’est-à-dire le vol de codes d’accès de banque en ligne.

TA551

Dridex, apparu en juin 2014, est la cinquième variante du code malveillant Bugat actif de 2010 à 2013, agrémenté de particularités propres à GameOverZeuS. Sa fonctionnalité première est celle d’un stealer, c’est-à-dire le vol de codes d’accès de banque en ligne.

SectorJ04

They are also known for using remote access Trojans (RATs) and malware downloaders that delivered the Dridex and Trick banking Trojans as secondary payloads during their campaigns...

Mustard Tempest

Active since 2017 and also known as FakeUpdates, SocGholish is a JavaScript (JS)-based downloader malware that typically serves as a conduit for next-stage malware from various threat actors like Evil Corp, LockBit, RansomHub, Dridex, and Raspberry Robin.

Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Dridex, a banking trojan

TA573

"TA573 is an affiliate distributor of Dridex, a malware strain that resurged in 2020... The malware itself is a creation of a Russian cyber crime group that calls itself Evil Corp..."

Exploited software

Vulnerabilities linked to Dridex

4 CVEs

MITRE ATT&CK

Dridex in ATT&CK

99 distinct techniques

Techniques

99 techniques
T1204.002 Malicious File T1059.005 Visual Basic T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1204 User Execution T1021 Remote Services T1657 Financial Theft T1587.001 Malware T1056 Input Capture T1584.005 Botnet T1566 Phishing T1539 Steal Web Session Cookie T1105 Ingress Tool Transfer T1027 Obfuscated Files or Information T1056.001 Keylogging T1562.004 Disable or Modify System Firewall T1185 Browser Session Hijacking T1059 Command and Scripting Interpreter T1027.009 Embedded Payloads T1566.002 Spearphishing Link T1048 Exfiltration Over Alternative Protocol T1213 Data from Information Repositories T1056.004 Credential API Hooking T1113 Screen Capture T1560 Archive Collected Data T1059.003 Windows Command Shell T1082 System Information Discovery T1189 Drive-by Compromise T1059.001 PowerShell T1497 Virtualization/Sandbox Evasion T1218.010 Regsvr32 T1071.001 Web Protocols T1622 Debugger Evasion T1573 Encrypted Channel T1106 Native API T1090.003 Multi-hop Proxy T1547.001 Registry Run Keys / Startup Folder T1555 Credentials from Password Stores T1041 Exfiltration Over C2 Channel T1027.002 Software Packing T1071 Application Layer Protocol T1095 Non-Application Layer Protocol T1218.011 Rundll32 T1204.001 Malicious Link T1027.007 Dynamic API Resolution T1056.003 Web Portal Capture T1497.003 Time Based Checks T1055 Process Injection T1574.001 DLL T1055.004 Asynchronous Procedure Call T1140 Deobfuscate/Decode Files or Information T1497.001 System Checks T1518 Software Discovery T1053.005 Scheduled Task T1055.012 Process Hollowing T1059.007 JavaScript T1091 Replication Through Removable Media T1480.002 Mutual Exclusion T1574 Hijack Execution Flow T1112 Modify Registry T1090 Proxy T1570 Lateral Tool Transfer T1548.002 Bypass User Account Control T1620 Reflective Code Loading T1001 Data Obfuscation T1218 System Binary Proxy Execution T1219 Remote Access Tools T1114 Email Collection T1190 Exploit Public-Facing Application T1055.003 Thread Execution Hijacking T1562 Impair Defenses T1485 Data Destruction T1537 Transfer Data to Cloud Account T1036 Masquerading T1070 Indicator Removal T1584 Compromise Infrastructure T1036.005 Match Legitimate Resource Name or Location T1012 Query Registry T1047 Windows Management Instrumentation T1218.005 Mshta T1543 Create or Modify System Process T1059.006 Python T1033 System Owner/User Discovery T1069 Permission Groups Discovery T1583.001 Domains T1217 Browser Information Discovery T1137.006 Add-ins T1486 Data Encrypted for Impact T1583 Acquire Infrastructure T1548 Abuse Elevation Control Mechanism T1568.001 Fast Flux DNS T1572 Protocol Tunneling T1090.001 Internal Proxy T1090.004 Domain Fronting T1573.001 Symmetric Cryptography T1053 Scheduled Task/Job T1573.002 Asymmetric Cryptography T1555.003 Credentials from Web Browsers T1568.002 Domain Generation Algorithms

Reporting

Research mentioning Dridex

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

Aug 12
Hookphish

Ransomware Group clop Hits: LARGAN.COM.TW

Jan 1
Cert Polska

Backswap malware analysis | CERT Polska

Researchers detailed BackSwap, a banking trojan linked to the TinBa malware family, that targeted online banking users by hiding inside trojanized legitimate Windows applications such as 7-Zip, FileZilla, and Notepad++. First observed in 2018, the malware focused on Polish banks and later shifted heavily toward Spanish financial institutions, while also occasionally targeting cryptocurrency wallet users. Its operators used compromised legitimate websites as command-and-control infrastructure and repeatedly changed encryption keys, payload storage, and exfiltration methods to evade detection. BackSwap stood out for avoiding classic browser memory injection and instead manipulating browser sessions through Windows UI monitoring and simulated user actions. It delivered malicious JavaScript into active banking sessions, stole credentials, logged browser window titles and URLs, hijacked clipboard data, and replaced recipient account numbers to redirect transactions to attacker-controlled IBANs. Analysts said the malware stored XOR-obfuscated or encrypted web-injects in the .rsrc section, sometimes concealed shellcode in BMP images, and used position-independent code plus custom Windows API resolution to reduce its forensic footprint and bypass antivirus heuristics.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.