Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 22, 2026
- Feed role
- C2 / Distribution
- Host form
- 3 IP / 1 hostnames
Dridex is a modular banking Trojan and malware delivery platform that emerged from the Cridex/Bugat lineage and became one of the most prevalent financial malware families targeting online banking users and financial institutions.
Profile source: Mallory opens in a new tabDridex
Dridex is a modular banking Trojan and malware delivery platform that emerged from the Cridex/Bugat lineage and became one of the most prevalent financial malware families targeting online banking users and financial institutions. It is strongly associated with Evil Corp and has also been linked in industry reporting to TA505, while multiple threat actors have distributed it over time. Dridex has been used both for direct financial theft and as an access-enablement malware family in broader post-compromise operations, including ransomware deployment.
Dridex is primarily distributed through phishing and malspam campaigns that use business-themed lures and malicious attachments, often compressed archives containing macro-enabled Microsoft Office documents. Victims are commonly induced to enable macros or otherwise execute embedded content, after which Dridex retrieves and launches additional components. Recent activity has also included exploitation of Microsoft Office vulnerability CVE-2017-0199, and modified variants such as DoppelDridex have been delivered through payloads staged on trusted messaging-service CDNs using Excel 4.0 macro documents. Dridex has also been observed delivered by other malware distribution frameworks, including Emotet and SocGholish.
Functionally, Dridex is designed to steal banking credentials and facilitate fraud. It can inject into browser sessions, monitor access to online banking portals, use API hooking and keylogging to capture credentials, and collect screenshots and other victim data. Stolen information is packaged, encrypted, and transmitted over peer-to-peer communications. Dridex is modular and can download additional components after initial infection, enabling botnet participation and expanded functionality. Reported execution and persistence behaviors include use of regsvr32 to initiate malicious code, as well as techniques involving file modification, privilege escalation, and firewall-rule changes to support communications and continued access.
Beyond credential theft, Dridex has played a major role as an initial-access and follow-on malware enabler. It has been linked to delivery chains and operational overlap involving Locky and ransomware families such as BitPaymer and DoppelPaymer, and has been cited as a loader used to provide network access for later ransomware deployment. Victimology has historically been broad, with a notable concentration on English-speaking countries and the financial services sector, though Dridex-enabled operations have affected enterprises and government organizations across multiple industries.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
A modified version of the banking trojan Dridex – named DoppelDridex – is being delivered via payloads staged on Slack and Discord CDNs.
A modified version of the banking trojan Dridex – named DoppelDridex – is being delivered via payloads staged on Slack and Discord CDNs.
The Treasury Department has similarly said Maksim Yakubets, the alleged leader of the Evil Corp cybercrime organization, worked for the FSB and was tasked with projects on behalf of the Russian state while his organization carried out financially motivated attacks.
Dridex — Malware-as-a-Service 2016-2018 — Pour distribuer Carbanak.
Typically, this group varies its payloads which appear to be targeted by region – for example, in 2021, all TA544 Ursnif campaigns have specifically targeted Italian organizations while Dridex payloads associated with this threat actor do not have specific geographic targeting.
The emails contained links to download Microsoft Excel documents containing macros that, when enabled, downloaded the Dridex malware designed to steal banking and other personal information.
Dridex, apparu en juin 2014, est la cinquième variante du code malveillant Bugat actif de 2010 à 2013, agrémenté de particularités propres à GameOverZeuS. Sa fonctionnalité première est celle d’un stealer, c’est-à -dire le vol de codes d’accès de banque en ligne.
Dridex, apparu en juin 2014, est la cinquième variante du code malveillant Bugat actif de 2010 à 2013, agrémenté de particularités propres à GameOverZeuS. Sa fonctionnalité première est celle d’un stealer, c’est-à -dire le vol de codes d’accès de banque en ligne.
They are also known for using remote access Trojans (RATs) and malware downloaders that delivered the Dridex and Trick banking Trojans as secondary payloads during their campaigns...
Active since 2017 and also known as FakeUpdates, SocGholish is a JavaScript (JS)-based downloader malware that typically serves as a conduit for next-stage malware from various threat actors like Evil Corp, LockBit, RansomHub, Dridex, and Raspberry Robin.
Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Dridex, a banking trojan
"TA573 is an affiliate distributor of Dridex, a malware strain that resurged in 2020... The malware itself is a creation of a Russian cyber crime group that calls itself Evil Corp..."
Exploited software
MITRE ATT&CK
Reporting
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.
Researchers detailed BackSwap, a banking trojan linked to the TinBa malware family, that targeted online banking users by hiding inside trojanized legitimate Windows applications such as 7-Zip, FileZilla, and Notepad++. First observed in 2018, the malware focused on Polish banks and later shifted heavily toward Spanish financial institutions, while also occasionally targeting cryptocurrency wallet users. Its operators used compromised legitimate websites as command-and-control infrastructure and repeatedly changed encryption keys, payload storage, and exfiltration methods to evade detection. BackSwap stood out for avoiding classic browser memory injection and instead manipulating browser sessions through Windows UI monitoring and simulated user actions. It delivered malicious JavaScript into active banking sessions, stole credentials, logged browser window titles and URLs, hijacked clipboard data, and replaced recipient account numbers to redirect transactions to attacker-controlled IBANs. Analysts said the malware stored XOR-obfuscated or encrypted web-injects in the .rsrc section, sometimes concealed shellcode in BMP images, and used position-independent code plus custom Windows API resolution to reduce its forensic footprint and bypass antivirus heuristics.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.