Skip to content

IcedID

IcedID, also known as BokBot, is a modular Windows banking trojan and information stealer first identified in 2017.

Profile source: Mallory opens in a new tab

IcedID

Family profile

IcedID, also known as BokBot, is a modular Windows banking trojan and information stealer first identified in 2017. It steals login credentials, banking data, personal information, and browser cookies, including through browser traffic interception and browser-hook components. Variants provide host and security-product discovery, command-shell and PowerShell execution, file and directory enumeration, Registry collection, process enumeration, shellcode injection, backconnect access, browser proxying, reverse-shell functionality, and VNC remote access. IcedID uses multistage loaders, encrypted configuration and payload data, custom in-memory payload formats, anti-analysis checks, and TLS certificate pinning. It commonly establishes persistence through scheduled tasks, with a Windows Run-key fallback. IcedID has been delivered through phishing attachments, including nested archive and disk-image chains, malicious Office documents, and OneNote documents; it has also been distributed through malvertising impersonating legitimate software. It can retrieve and execute secondary payloads such as Cobalt Strike and has been linked to ransomware operations. IcedID activity has been observed in campaigns associated with TA578, while Mealybug/Emotet has historically distributed it; reporting has also linked IcedID ransomware-related activity to UNC2198.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance
  • Session Hijacking

Observed infrastructure

Last seven days

First activity
Sep 8, 2026
Last activity
Sep 8, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Samples

Recent associated samples

Reported operators

Threat actors

30 named in public reporting
TA578

2022-06-28 (TUESDAY) - TA578 ICEDID (BOKBOT) WITH BACKCONNECT, ANUBIS VNC AND COBALT STRIKE

WIZARD SPIDER

"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"

Threat Group-3390

"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"

Mealybug

In 2017 it was the first group to deliver the IcedID (Trojan.IcedID) banking Trojan.

TA577

IcedID – a botnet loader known to arise from malicious documents and often leading to Cobalt Strike or other backdoors that position threat actors for ransomware deployment.

TA551

IcedID – a botnet loader known to arise from malicious documents and often leading to Cobalt Strike or other backdoors that position threat actors for ransomware deployment.

UAC-0041

The Computer Emergency Response Team of Ukraine (CERT-UA) detected the new campaigns and attributed the IcedID phishing attack to the UAC-0041 threat cluster... This file is the GzipLoader malware, which fetches, decrypts, and executes the final payload, IcedID (aka BankBot).

Lunar Spider

Sur la période 2017-2018, Emotet aurait principalement distribué les codes malveillants IcedID, Nymaim et Gootkit.

Conti

In this Threat Analysis report, the GSOC provides details about three recent attack scenarios where fast-moving malicious actors used the malware loaders IcedID, QBot, and Emotet to deploy the Cobalt Strike framework on the compromised systems.

Shatak

IcedID - also known as BokBot - emerged in late 2017. First, it served as a banking Trojan... Consequently, the IcedID developers transformed it into a downloader and it became part of the Malware-as-a-Service ecosystem (MaaS).

Storm-0249

Microsoft attributes this campaign to Storm-0249, an access broker active since 2021 and known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.

TR

The distribution of the IcedID malware has seen a spike recently due to a new campaign that hijacks existing email conversation threads and injects malicious payloads that are hard to spot. IcedID is a modular banking trojan first spotted back in 2017, used mainly to deploy second-stage malware such as other loaders or ransomware.

PyXie

In a number of incidents we investigated, the actors established an initial foothold into the victim's network through common banking trojans such as IcedID or Trickbot.

TA579

Eli Salem says that the deployment techniques for Bumblebee are the same as for BazarLoader and IcedID, both seen in the past deploying Conti ransomware.

UAC-0098

GzipLoader, яка, в свою чергу, здійснить завантаження, дешифрування та запуск шкідливої програми IcedID. Згадана шкідлива програма (також відома як BankBot) відноситься до класу "банківських троянських програм", та, серед іншого, забезпечує викрадення автентифікаційних даних.

Emotet

ICEDID was originally used for banking credential theft with a later pivot as a reconnaissance tool for pre-ransomware intrusions... this malware is most often associated with ransomware incidents.

Gold Dupont

In a number of incidents we investigated, the actors established an initial foothold into the victim's network through common banking trojans such as IcedID or Trickbot.

GoldCabin

In the last six months, there have been several reports of REvil ransomware deployment following an initial IcedID or Qakbot infection.

fin12

UAC-0098 is a threat actor that historically delivered the IcedID banking trojan, leading to human-operated ransomware attacks.

Karakurt

IcedID (a.k.a. BokBot) is a popular Trojan who first emerged in 2017 as an Emotet delivery. Originally described as a banking Trojan, IcedID shifted its focus to embrace the extortion/ransom trend and nowadays acts as an initial access broker mostly delivered through malspam campaigns.

Maze

WizardSpider (Conti, Ryuk) Egregor DarkSide Maze Team (Maze & IcedID)

TA571

In addition, TA571 has been associated with the distribution of other malware families, including variants of IcedID, NetSupportRAT, DarkGate and others.

Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... IcedID, a modular information-stealing malware

Lockean

In at least one known instance, Lockean used the IcedID malware distribution service to get access to the network.

TA544

IcedID is a malware originally classified as a banking trojan and was first observed in 2017. It also acts as a loader for other malware, including ransomware.

TA581

IcedID is a malware originally classified as a banking trojan and was first observed in 2017. It also acts as a loader for other malware, including ransomware.

TA542

Proofpoint researchers have observed and documented, for the first time, three distinct variants of the malware known as IcedID. Proofpoint calls the two new variants recently identified “Forked” and “Lite” IcedID.

Vacant Viper

“Vacant Viper is known to affiliate with TA571, for which the 404TDS delivered IcedID and other malware.”

UNC2198

Since its discovery in 2017 as a banking trojan, ICEDID evolved into a pernicious point of entry for financially motivated actors to conduct intrusion operations.

UNC2420

Since its discovery in 2017 as a banking trojan, ICEDID evolved into a pernicious point of entry for financially motivated actors to conduct intrusion operations.

Exploited software

Vulnerabilities linked to IcedID

4 CVEs

MITRE ATT&CK

IcedID in ATT&CK

96 distinct techniques

Techniques

96 techniques
T1218.010 Regsvr32 T1012 Query Registry T1620 Reflective Code Loading T1218.011 Rundll32 T1557 Adversary-in-the-Middle T1090 Proxy T1083 File and Directory Discovery T1047 Windows Management Instrumentation T1027 Obfuscated Files or Information T1018 Remote System Discovery T1059.001 PowerShell T1057 Process Discovery T1135 Network Share Discovery T1566.001 Spearphishing Attachment T1059 Command and Scripting Interpreter T1059.003 Windows Command Shell T1497 Virtualization/Sandbox Evasion T1555 Credentials from Password Stores T1518 Software Discovery T1055 Process Injection T1071.001 Web Protocols T1053.005 Scheduled Task T1069 Permission Groups Discovery T1087 Account Discovery T1219 Remote Access Tools T1105 Ingress Tool Transfer T1555.003 Credentials from Web Browsers T1547.001 Registry Run Keys / Startup Folder T1204.002 Malicious File T1016 System Network Configuration Discovery T1082 System Information Discovery T1573 Encrypted Channel T1218.005 Mshta T1056.004 Credential API Hooking T1036 Masquerading T1583.001 Domains T1021 Remote Services T1566 Phishing T1059.005 Visual Basic T1539 Steal Web Session Cookie T1189 Drive-by Compromise T1071 Application Layer Protocol T1553.002 Code Signing T1021.005 VNC T1566.003 Spearphishing via Service T1218.007 Msiexec T1106 Native API T1112 Modify Registry T1055.012 Process Hollowing T1204 User Execution T1518.001 Security Software Discovery T1583 Acquire Infrastructure T1027.003 Steganography T1033 System Owner/User Discovery T1140 Deobfuscate/Decode Files or Information T1218.001 Compiled HTML File T1218 System Binary Proxy Execution T1053 Scheduled Task/Job T1547.009 Shortcut Modification T1041 Exfiltration Over C2 Channel T1185 Browser Session Hijacking T1059.007 JavaScript T1572 Protocol Tunneling T1027.013 Encrypted/Encoded File T1543 Create or Modify System Process T1562 Impair Defenses T1204.001 Malicious Link T1056.003 Web Portal Capture T1129 Shared Modules T1132 Data Encoding T1055.004 Asynchronous Procedure Call T1027.002 Software Packing T1552 Unsecured Credentials T1560.001 Archive via Utility T1564 Hide Artifacts T1482 Domain Trust Discovery T1566.002 Spearphishing Link T1564.001 Hidden Files and Directories T1497.001 System Checks T1078 Valid Accounts T1087.002 Domain Account T1056 Input Capture T1543.003 Windows Service T1565 Data Manipulation T1027.007 Dynamic API Resolution T1005 Data from Local System T1548.002 Bypass User Account Control T1001 Data Obfuscation T1046 Network Service Discovery T1090.003 Multi-hop Proxy T1486 Data Encrypted for Impact T1587.001 Malware T1069.001 Local Groups T1586.002 Email Accounts T1027.005 Indicator Removal from Tools T1622 Debugger Evasion

Reporting

Research mentioning IcedID

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jun 23
Github Web

DE-TH-Aura/Defender for Endpoint/ExternalData - Cert Central, CertReport.md at main · SecurityAura/DE-TH-Aura · GitHub

Jun 22
Squiblydoo

Using the Cert Graveyard - Squiblydoo.blog

May 19
Trellix Other

Qakbot Evolves to OneNote Malware Distribution

Qakbot operators repeatedly changed their intrusion chains between March and May 2023, using malspam and a rotating set of attachment and container formats including PDF, HTML, ZIP, OneNote, WSF/HTA, and XLL files to deliver the malware. Researchers observed HTML smuggling, obfuscated JavaScript, PowerShell, and DLL-based payload staging in March, followed by ZIP-to-XLL chains that rebuilt payloads from split DAT files and created scheduled tasks for persistence. By April and May, the malware’s operators had shifted from base64-encoded PowerShell toward hex-encoded XMLHTTP requests delivered through WSF files, and used a OneNote-to-MSI lure posing as a Microsoft Azure installer. Later campaigns added stronger defense evasion, including indirect command execution through conhost.exe, DLL side-loading, and curl-based payload retrieval. Researchers also noted that Pikabot samples seen in mid-May shared similar tradecraft, but said the available evidence did not support attributing both malware families to the same actor.

May 13
Splunk Research

Detection: Net Localgroup Discovery | Splunk Security Content

Splunk has removed two Windows discovery analytics from its Threat Research content library and replaced them with updated detections for attacker use of built-in net commands to enumerate users and groups. The deprecated rules, Local Account Discovery with Net and Net Localgroup Discovery, identified execution of net.exe or net1.exe with arguments such as user, users, and localgroup, activity commonly used to list local accounts and group memberships on compromised hosts. The changes align with well-documented adversary behavior in MITRE ATT&CK techniques T1087.001 and T1069.001, where threat actors use commands like net user, net user /domain, and net localgroup administrators to gather account and privilege information that can support privilege escalation and lateral movement. Splunk said the removed analytics were deprecated in version 5.2.0 in favor of Windows User Discovery Via Net and Windows Group Discovery Via Net, with the original detections having relied on EDR process telemetry, Sysmon Event ID 1, Windows Security Event ID 4688, and related endpoint data sources.

May 13
Splunk Research

Detection: Local Account Discovery with Net | Splunk Security Content

Apr 1
Squiblydoo

The CertGraveyard - Squiblydoo.blog

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.