Skip to content
Malware family Windows

IcedID

IcedID, also known as BokBot, is a Windows malware family best known as a banking trojan and later as a modular loader used in financially motivated intrusion chains.

Profile source: Mallory opens in a new tab

IcedID

Family profile

IcedID, also known as BokBot, is a Windows malware family best known as a banking trojan and later as a modular loader used in financially motivated intrusion chains. It has been associated with the Lunar Spider ecosystem and has also appeared in operations linked to major cybercrime clusters including Wizard Spider, TA551, TA577, and Black Basta-related activity. The malware has been repeatedly observed as part of broader loader and botnet infrastructure targeted by international law-enforcement actions.

IcedID is used to establish footholds on victim systems and support follow-on payload delivery. Reported tradecraft includes staged unpacking and in-memory reconstruction of secondary modules, downloader functionality, and use in campaigns that ultimately deploy additional tooling such as Cobalt Strike. It has been observed using DLL sideloading with legitimate Microsoft Word binaries, process hollowing or similar code-injection tradecraft into Explorer, persistence via user logon script mechanisms, and automated data exfiltration over HTTP PUT and encrypted FTP. Analysis of unpacking behavior shows shellcode-style execution flow, memory allocation and copying, and byte-wise decryption operations before producing a clean PE for a second-stage downloader module.

Delivery has commonly relied on phishing and malspam campaigns using malicious Office documents with macros, as well as archive, ISO, and shortcut-based lures that require user execution. Campaign reporting also links IcedID distribution to HTML smuggling-adjacent tradecraft and Base64-encoded PowerShell execution in some intrusion chains. The malware has been used across financially motivated operations and ransomware precursor activity, making it relevant to enterprise defenders monitoring initial access and post-compromise loader ecosystems.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Initial Access
  • Persistence
  • Process Injection

Reported operators

Threat actors

18 named in public reporting
Maze

WizardSpider (Conti, Ryuk) Egregor DarkSide Maze Team (Maze & IcedID)

TA551

TA551, also known as Shathak or Gold Cabin, is an attacker group that is responsible for spreading a wide variety of malware families including IcedID, Valak, Ursnif and, more recently, BazarLoader.

Lunar Spider

IcedID aka Bokbot is also one of the most prevalent banking trojans in the last years. It is known to be associated with Lunar Spider threat actors.

TA577

TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.

TA571

In addition, TA571 has been associated with the distribution of other malware families, including variants of IcedID, NetSupportRAT, DarkGate and others.

TA579

Proofpoint has tracked a new malware loader called Bumblebee used by multiple crimeware threat actors previously observed delivering BazaLoader and IcedID.

TA578

Proofpoint has tracked a new malware loader called Bumblebee used by multiple crimeware threat actors previously observed delivering BazaLoader and IcedID.

WIZARD SPIDER

Most notable are the acquisitions of developers from Emotet, Qakbot, and IcedID, bringing them to the DEV-0193 umbrella.

Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... IcedID, a modular information-stealing malware

Lockean

In at least one known instance, Lockean used the IcedID malware distribution service to get access to the network.

TA544

IcedID is a malware originally classified as a banking trojan and was first observed in 2017. It also acts as a loader for other malware, including ransomware.

TA581

IcedID is a malware originally classified as a banking trojan and was first observed in 2017. It also acts as a loader for other malware, including ransomware.

Storm-0249

Microsoft attributes this campaign to Storm-0249... known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.

TA542

Proofpoint researchers have observed and documented, for the first time, three distinct variants of the malware known as IcedID. Proofpoint calls the two new variants recently identified “Forked” and “Lite” IcedID.

vacant_viper

“Vacant Viper is known to affiliate with TA571, for which the 404TDS delivered IcedID and other malware.”

Gold Dupont

By allowing the macro inside the document, it will attempt to download the IcedID trojan... As a common IcedID approach it used steganography as a method to deliver the payload through a .png file... For persistence, IcedID creates a scheduled task to run hourly...

UNC2198

Since its discovery in 2017 as a banking trojan, ICEDID evolved into a pernicious point of entry for financially motivated actors to conduct intrusion operations.

UNC2420

Since its discovery in 2017 as a banking trojan, ICEDID evolved into a pernicious point of entry for financially motivated actors to conduct intrusion operations.

Exploited software

Vulnerabilities linked to IcedID

1 CVEs

MITRE ATT&CK

IcedID in ATT&CK

73 distinct techniques

Techniques

73 techniques
T1020 Automated Exfiltration T1547.001 Registry Run Keys / Startup Folder T1082 System Information Discovery T1059.001 PowerShell T1027 Obfuscated Files or Information T1566 Phishing T1027.002 Software Packing T1140 Deobfuscate/Decode Files or Information T1055 Process Injection T1105 Ingress Tool Transfer T1218.011 Rundll32 T1204.002 Malicious File T1071.001 Web Protocols T1016 System Network Configuration Discovery T1087.002 Domain Account T1018 Remote System Discovery T1204 User Execution T1598 Phishing for Information T1560 Archive Collected Data T1036 Masquerading T1583 Acquire Infrastructure T1036.005 Match Legitimate Resource Name or Location T1656 Impersonation T1566.001 Spearphishing Attachment T1059.005 Visual Basic T1566.002 Spearphishing Link T1112 Modify Registry T1573 Encrypted Channel T1047 Windows Management Instrumentation T1614.001 System Language Discovery T1053.005 Scheduled Task T1550 Use Alternate Authentication Material T1539 Steal Web Session Cookie T1071 Application Layer Protocol T1027.013 Encrypted/Encoded File T1005 Data from Local System T1555 Credentials from Password Stores T1059.007 JavaScript T1547.009 Shortcut Modification T1189 Drive-by Compromise T1518.001 Security Software Discovery T1587.001 Malware T1562 Impair Defenses T1069.001 Local Groups T1027.006 HTML Smuggling T1482 Domain Trust Discovery T1135 Network Share Discovery T1218.010 Regsvr32 T1059.003 Windows Command Shell T1553.002 Code Signing T1218.007 Msiexec T1033 System Owner/User Discovery T1070.004 File Deletion T1027.009 Embedded Payloads T1036.003 Rename Legitimate Utilities T1059 Command and Scripting Interpreter T1078 Valid Accounts T1562.001 Disable or Modify Tools T1087 Account Discovery T1218.005 Mshta T1053 Scheduled Task/Job T1027.003 Steganography T1497 Virtualization/Sandbox Evasion T1573.002 Asymmetric Cryptography T1055.012 Process Hollowing T1204.001 Malicious Link T1185 Browser Session Hijacking T1555.003 Credentials from Web Browsers T1560.001 Archive via Utility T1055.004 Asynchronous Procedure Call T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1106 Native API T1069 Permission Groups Discovery

Reporting

Research mentioning IcedID

Jul 16
Codeby

ATT&CK Navigator: gap-анализ TTP за один вечер

для T1020 (Automated Exfiltration) - IcedID Botnet HTTP PUT, Exfiltration via Encrypted FTP

Jul 7
Gurucul Threat Research

Millenium: A RAT Rewritten, a Threat Multiplied | Community Portal | Gurucul

IcedID1

Jun 25
Decipher Sc

Targeting Cybercrime ‘Assembly Lines:’ Europol Announces Malware Crackdown - Decipher

Previously, the FBI and Europol targeted loaders like Bumblebee (in 2024), as well as others in the dropper/loader ecosystem like IcedID, Pikabot, and Smokeloader.

Jun 22
Xakep

Правоохранители очистили 15 000 сайтов, зараженных SocGholish - Хакер

Также в прошлые годы операция затрагивала инфраструктуру SmokeLoader, DanaBot, IcedID, Pikabot, Trickbot, Bumblebee, SystemBC...

Jun 18
Hackread

Operation Endgame Disrupts SocGholish Malware Infrastructure

In May 2024, the operation resulted in seizing around 100 servers belonging to dropper networks, including IcedID, SystemBC, Smokeloader, Trickbot, Pikabot, and Bumblebee

Jun 18
Bleeping Computer

Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp

Previously, Operation Endgame has also targeted ransomware infrastructure, Smokeloader botnet customers and servers, the AVCheck site, and various other major malware operations, including DanaBot, IcedID, Pikabot, Trickbot, Smokeloader, Bumblebee, and SystemBC.

Jun 15
Security Week

Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges - SecurityWeek

The Conti operation was linked to numerous other malware families, including TrickBot, which was also associated with Bazarloader, SystemBC, IcedID, Ryuk, and Diavol.

Jun 15
Codeby

Украденные учётные данные: от инфостилера до domain admin

Operation Endgame затронула несколько ботнетов-дропперов (SmokeLoader, IcedID, Pikabot и др.).

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.