Last seven days
- First activity
- Sep 8, 2026
- Last activity
- Sep 8, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
IcedID, also known as BokBot, is a modular Windows banking trojan and information stealer first identified in 2017.
Profile source: Mallory opens in a new tabIcedID
IcedID, also known as BokBot, is a modular Windows banking trojan and information stealer first identified in 2017. It steals login credentials, banking data, personal information, and browser cookies, including through browser traffic interception and browser-hook components. Variants provide host and security-product discovery, command-shell and PowerShell execution, file and directory enumeration, Registry collection, process enumeration, shellcode injection, backconnect access, browser proxying, reverse-shell functionality, and VNC remote access. IcedID uses multistage loaders, encrypted configuration and payload data, custom in-memory payload formats, anti-analysis checks, and TLS certificate pinning. It commonly establishes persistence through scheduled tasks, with a Windows Run-key fallback. IcedID has been delivered through phishing attachments, including nested archive and disk-image chains, malicious Office documents, and OneNote documents; it has also been distributed through malvertising impersonating legitimate software. It can retrieve and execute secondary payloads such as Cobalt Strike and has been linked to ransomware operations. IcedID activity has been observed in campaigns associated with TA578, while Mealybug/Emotet has historically distributed it; reporting has also linked IcedID ransomware-related activity to UNC2198.
Samples
517be160e3cefc6fc47b65370c36b2fe6ac55eaf653ac399677cba07b41e7899 5b0ccbcd5f5a44397ed2e259e5e3ee1da269124961622021f13ee6d5782762c1 673d341a21b5cd67e1c4c454b4d1a954e5ec8874d87ffac7aa691776c295ab09 c4242d7eb8362ef0f92f0b396b0db50c4d67e126636f29bdf98bdbb2c5562214 ddf86c064aa88ba9e3ef21e58d48e6965a7fe417f370bd104aeb543add325e1c Reported operators
2022-06-28 (TUESDAY) - TA578 ICEDID (BOKBOT) WITH BACKCONNECT, ANUBIS VNC AND COBALT STRIKE
"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"
"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"
In 2017 it was the first group to deliver the IcedID (Trojan.IcedID) banking Trojan.
IcedID – a botnet loader known to arise from malicious documents and often leading to Cobalt Strike or other backdoors that position threat actors for ransomware deployment.
IcedID – a botnet loader known to arise from malicious documents and often leading to Cobalt Strike or other backdoors that position threat actors for ransomware deployment.
The Computer Emergency Response Team of Ukraine (CERT-UA) detected the new campaigns and attributed the IcedID phishing attack to the UAC-0041 threat cluster... This file is the GzipLoader malware, which fetches, decrypts, and executes the final payload, IcedID (aka BankBot).
Sur la période 2017-2018, Emotet aurait principalement distribué les codes malveillants IcedID, Nymaim et Gootkit.
In this Threat Analysis report, the GSOC provides details about three recent attack scenarios where fast-moving malicious actors used the malware loaders IcedID, QBot, and Emotet to deploy the Cobalt Strike framework on the compromised systems.
IcedID - also known as BokBot - emerged in late 2017. First, it served as a banking Trojan... Consequently, the IcedID developers transformed it into a downloader and it became part of the Malware-as-a-Service ecosystem (MaaS).
Microsoft attributes this campaign to Storm-0249, an access broker active since 2021 and known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.
The distribution of the IcedID malware has seen a spike recently due to a new campaign that hijacks existing email conversation threads and injects malicious payloads that are hard to spot. IcedID is a modular banking trojan first spotted back in 2017, used mainly to deploy second-stage malware such as other loaders or ransomware.
In a number of incidents we investigated, the actors established an initial foothold into the victim's network through common banking trojans such as IcedID or Trickbot.
Eli Salem says that the deployment techniques for Bumblebee are the same as for BazarLoader and IcedID, both seen in the past deploying Conti ransomware.
GzipLoader, яка, в свою чергу, здійснить завантаження, дешифрування та запуск шкідливої програми IcedID. Згадана шкідлива програма (також відома як BankBot) відноситься до класу "банківських троянських програм", та, серед іншого, забезпечує викрадення автентифікаційних даних.
ICEDID was originally used for banking credential theft with a later pivot as a reconnaissance tool for pre-ransomware intrusions... this malware is most often associated with ransomware incidents.
In a number of incidents we investigated, the actors established an initial foothold into the victim's network through common banking trojans such as IcedID or Trickbot.
In the last six months, there have been several reports of REvil ransomware deployment following an initial IcedID or Qakbot infection.
UAC-0098 is a threat actor that historically delivered the IcedID banking trojan, leading to human-operated ransomware attacks.
IcedID (a.k.a. BokBot) is a popular Trojan who first emerged in 2017 as an Emotet delivery. Originally described as a banking Trojan, IcedID shifted its focus to embrace the extortion/ransom trend and nowadays acts as an initial access broker mostly delivered through malspam campaigns.
WizardSpider (Conti, Ryuk) Egregor DarkSide Maze Team (Maze & IcedID)
In addition, TA571 has been associated with the distribution of other malware families, including variants of IcedID, NetSupportRAT, DarkGate and others.
Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... IcedID, a modular information-stealing malware
In at least one known instance, Lockean used the IcedID malware distribution service to get access to the network.
IcedID is a malware originally classified as a banking trojan and was first observed in 2017. It also acts as a loader for other malware, including ransomware.
IcedID is a malware originally classified as a banking trojan and was first observed in 2017. It also acts as a loader for other malware, including ransomware.
Proofpoint researchers have observed and documented, for the first time, three distinct variants of the malware known as IcedID. Proofpoint calls the two new variants recently identified “Forked” and “Lite” IcedID.
“Vacant Viper is known to affiliate with TA571, for which the 404TDS delivered IcedID and other malware.”
Since its discovery in 2017 as a banking trojan, ICEDID evolved into a pernicious point of entry for financially motivated actors to conduct intrusion operations.
Since its discovery in 2017 as a banking trojan, ICEDID evolved into a pernicious point of entry for financially motivated actors to conduct intrusion operations.
Exploited software
MITRE ATT&CK
Reporting
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Qakbot operators repeatedly changed their intrusion chains between March and May 2023, using malspam and a rotating set of attachment and container formats including PDF, HTML, ZIP, OneNote, WSF/HTA, and XLL files to deliver the malware. Researchers observed HTML smuggling, obfuscated JavaScript, PowerShell, and DLL-based payload staging in March, followed by ZIP-to-XLL chains that rebuilt payloads from split DAT files and created scheduled tasks for persistence. By April and May, the malware’s operators had shifted from base64-encoded PowerShell toward hex-encoded XMLHTTP requests delivered through WSF files, and used a OneNote-to-MSI lure posing as a Microsoft Azure installer. Later campaigns added stronger defense evasion, including indirect command execution through conhost.exe, DLL side-loading, and curl-based payload retrieval. Researchers also noted that Pikabot samples seen in mid-May shared similar tradecraft, but said the available evidence did not support attributing both malware families to the same actor.
Splunk has removed two Windows discovery analytics from its Threat Research content library and replaced them with updated detections for attacker use of built-in net commands to enumerate users and groups. The deprecated rules, Local Account Discovery with Net and Net Localgroup Discovery, identified execution of net.exe or net1.exe with arguments such as user, users, and localgroup, activity commonly used to list local accounts and group memberships on compromised hosts. The changes align with well-documented adversary behavior in MITRE ATT&CK techniques T1087.001 and T1069.001, where threat actors use commands like net user, net user /domain, and net localgroup administrators to gather account and privilege information that can support privilege escalation and lateral movement. Splunk said the removed analytics were deprecated in version 5.2.0 in favor of Windows User Discovery Via Net and Windows Group Discovery Via Net, with the original detections having relied on EDR process telemetry, Sysmon Event ID 1, Windows Security Event ID 4688, and related endpoint data sources.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.