Skip to content

IcedID

Also known as: BokBot, IceID

According to Proofpoint, IcedID (aka BokBot) is a malware originally classified as a banking malware and was first observed in 2017. It also acts as a loader for other malware, including ransomware. The well-known IcedID version consists of an initial loader which contacts a Loader C2 server, downloads the standard DLL Loader, which then delivers the standard IcedID Bot. IcedID is developed and operated by the actor named LUNAR SPIDER.

As previously published, historically there has been just one version of IcedID that has remained constant since 2017.

* In November 2022, Proofpoint researchers observed the first new variant of IcedID Proofpoint dubbed 'IcedID Lite' distributed as a follow-on payload in a TA542 Emotet campaign. It was dropped by the Emotet malware soon after the actor returned to the e-crime landscape after a nearly four-month break.

* The IcedID Lite Loader observed in November 2022 contains a static URL to download a 'Bot Pack' file with a static name (botpack.dat) which results in the IcedID Lite DLL Loader, and then delivers the Forked version of IcedID Bot, leaving out the webinjects and backconnect functionality that would typically be used for banking fraud.

* Starting in February 2023, Proofpoint observed the new Forked variant of IcedID. This variant was distributed by TA581 and one unattributed threat activity cluster which acted as initial access facilitators. The campaigns used a variety of email attachments such as Microsoft OneNote attachments and somewhat rare to see .URL attachments, which led to the Forked variant of IcedID.

Linked Threat Actors

GOLD CABINLunar Spider

C2 Infrastructure

Hosting/VPS 100%

Last 7 days

Jun 8, 2026
C2 Hosts: 1

Further Reading

PROSPERO & Proton66: Uncovering the links between bulletproof networks opens in a new tab

Key findings   This report presents: The Russian autonomous system PROSPERO (AS200593) could be linked […]

intrinsec.com
Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself | Microsoft Security Blog opens in a new tab

Microsoft coined the term “human-operated ransomware” to clearly define a class of attack driven by expert human intelligence at every step of the attack chain and culminate in intentional business...

microsoft.com
[CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko opens in a new tab

The document discusses the cyber threat landscape in Japan, highlighting significant malware such as Emotet and Lokibot, which target financial institutions and gather sensitive data. It outlines r...

slideshare.net
Ransomware Operators Found Using New Franchise Business Model opens in a new tab
trendmicro.com
Ransomware Spotlight: RansomEXX | Trend Micro (US) opens in a new tab

RansomEXX is a ransomware variant that gained notoriety after a spate of attacks in 2020 and continues to be active today. With its targeted nature and history for choosing high-profile victims, we...

trendmicro.com
IcedID Campaign Spotted Being Spiced With Excel 4 Macros opens in a new tab

Uptycs Threat Research has observed a trend with IcedID, a banking trojan, where threat actors are now using xlsm file distribution layered with stealthy evasion techniques.

uptycs.com
OneNote | ThreatLabz opens in a new tab

Zscaler ThreatLabz team observed multiple OneNote malware campaign spreading RATs, Bankers, and Stealer category malware with multi-layer obfuscation.

zscaler.com
Affordable Malware RE Training | 0ffset Training Solutions opens in a new tab

We assist individuals, SMEs, and F500s alike by providing professional training within the niche field of malware analysis and reverse engineering, without breaking the bank.

zero2auto.com