Last seven days
- First activity
- Jul 26, 2026
- Last activity
- Jul 26, 2026
- Feed role
- C2
- Host form
- 0 IP / 5 hostnames
IcedID, also known as BokBot, is a Windows banking trojan that evolved into a broadly used malware platform for credential theft, host profiling, payload delivery, and follow-on intrusion support.
Profile source: Mallory opens in a new tabIcedID
IcedID, also known as BokBot, is a Windows banking trojan that evolved into a broadly used malware platform for credential theft, host profiling, payload delivery, and follow-on intrusion support. It has been associated with the LUNAR SPIDER cybercrime ecosystem and has been widely used in financially motivated operations, including as an initial infection vector preceding hands-on-keyboard activity and ransomware deployment. Intrusions linked to Quantum and other ransomware operations have used IcedID to establish footholds, conduct reconnaissance, support credential access, and enable later deployment of frameworks such as Cobalt Strike and ransomware payloads.
IcedID is commonly delivered through phishing-driven infection chains and malspam campaigns, and it has appeared in distribution ecosystems used by groups such as TA551 and TA577. Observed tradecraft around campaigns involving IcedID includes abuse of shortcut files, ISO images, macro-enabled documents, HTML smuggling, and Base64-encoded PowerShell execution. The malware has also been delivered as a follow-on payload by other loaders, and more recent reporting indicates that Latrodectus is likely operated by the same ecosystem and has delivered IcedID as a secondary payload.
Technically, IcedID is known for staged execution and custom unpacking. Analysis of first-stage samples shows shellcode-related execution flow, memory allocation and protection changes, repeated memory copying, and byte-wise decryption operations that reconstruct a clean portable executable in memory. Its functionality has included automated exfiltration and downloader behavior, and it has been referred to internally by some operators as a loader or botnet component. IcedID has remained a significant element of the cybercrime loader ecosystem and has been the subject of repeated international disruption efforts targeting the broader malware supply chain.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Treat any Latrodectus hit as the first stage of a hands-on intrusion, it has delivered IcedID and Brute Ratel C4, and recent builds add a BackConnect (VNC) module.
WizardSpider (Conti, Ryuk) Egregor DarkSide Maze Team (Maze & IcedID)
TA551, also known as Shathak or Gold Cabin, is an attacker group that is responsible for spreading a wide variety of malware families including IcedID, Valak, Ursnif and, more recently, BazarLoader.
TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.
In addition, TA571 has been associated with the distribution of other malware families, including variants of IcedID, NetSupportRAT, DarkGate and others.
Proofpoint has tracked a new malware loader called Bumblebee used by multiple crimeware threat actors previously observed delivering BazaLoader and IcedID.
Proofpoint has tracked a new malware loader called Bumblebee used by multiple crimeware threat actors previously observed delivering BazaLoader and IcedID.
Most notable are the acquisitions of developers from Emotet, Qakbot, and IcedID, bringing them to the DEV-0193 umbrella.
Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... IcedID, a modular information-stealing malware
In at least one known instance, Lockean used the IcedID malware distribution service to get access to the network.
IcedID is a malware originally classified as a banking trojan and was first observed in 2017. It also acts as a loader for other malware, including ransomware.
IcedID is a malware originally classified as a banking trojan and was first observed in 2017. It also acts as a loader for other malware, including ransomware.
Microsoft attributes this campaign to Storm-0249... known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.
Proofpoint researchers have observed and documented, for the first time, three distinct variants of the malware known as IcedID. Proofpoint calls the two new variants recently identified “Forked” and “Lite” IcedID.
“Vacant Viper is known to affiliate with TA571, for which the 404TDS delivered IcedID and other malware.”
By allowing the macro inside the document, it will attempt to download the IcedID trojan... As a common IcedID approach it used steganography as a method to deliver the payload through a .png file... For persistence, IcedID creates a scheduled task to run hourly...
Since its discovery in 2017 as a banking trojan, ICEDID evolved into a pernicious point of entry for financially motivated actors to conduct intrusion operations.
Since its discovery in 2017 as a banking trojan, ICEDID evolved into a pernicious point of entry for financially motivated actors to conduct intrusion operations.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.