WizardSpider (Conti, Ryuk) Egregor DarkSide Maze Team (Maze & IcedID)
IcedID
IcedID, also known as BokBot, is a Windows malware family best known as a banking trojan and later as a modular loader used in financially motivated intrusion chains.
Profile source: Mallory opens in a new tabIcedID
Family profile
IcedID, also known as BokBot, is a Windows malware family best known as a banking trojan and later as a modular loader used in financially motivated intrusion chains. It has been associated with the Lunar Spider ecosystem and has also appeared in operations linked to major cybercrime clusters including Wizard Spider, TA551, TA577, and Black Basta-related activity. The malware has been repeatedly observed as part of broader loader and botnet infrastructure targeted by international law-enforcement actions.
IcedID is used to establish footholds on victim systems and support follow-on payload delivery. Reported tradecraft includes staged unpacking and in-memory reconstruction of secondary modules, downloader functionality, and use in campaigns that ultimately deploy additional tooling such as Cobalt Strike. It has been observed using DLL sideloading with legitimate Microsoft Word binaries, process hollowing or similar code-injection tradecraft into Explorer, persistence via user logon script mechanisms, and automated data exfiltration over HTTP PUT and encrypted FTP. Analysis of unpacking behavior shows shellcode-style execution flow, memory allocation and copying, and byte-wise decryption operations before producing a clean PE for a second-stage downloader module.
Delivery has commonly relied on phishing and malspam campaigns using malicious Office documents with macros, as well as archive, ISO, and shortcut-based lures that require user execution. Campaign reporting also links IcedID distribution to HTML smuggling-adjacent tradecraft and Base64-encoded PowerShell execution in some intrusion chains. The malware has been used across financially motivated operations and ransomware precursor activity, making it relevant to enterprise defenders monitoring initial access and post-compromise loader ecosystems.
Capabilities
- Defense Evasion
- Dll Sideloading
- Exfiltration
- Initial Access
- Persistence
- Process Injection
Reported operators
Threat actors
18 named in public reportingTA551, also known as Shathak or Gold Cabin, is an attacker group that is responsible for spreading a wide variety of malware families including IcedID, Valak, Ursnif and, more recently, BazarLoader.
IcedID aka Bokbot is also one of the most prevalent banking trojans in the last years. It is known to be associated with Lunar Spider threat actors.
TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.
In addition, TA571 has been associated with the distribution of other malware families, including variants of IcedID, NetSupportRAT, DarkGate and others.
Proofpoint has tracked a new malware loader called Bumblebee used by multiple crimeware threat actors previously observed delivering BazaLoader and IcedID.
Proofpoint has tracked a new malware loader called Bumblebee used by multiple crimeware threat actors previously observed delivering BazaLoader and IcedID.
Most notable are the acquisitions of developers from Emotet, Qakbot, and IcedID, bringing them to the DEV-0193 umbrella.
Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... IcedID, a modular information-stealing malware
In at least one known instance, Lockean used the IcedID malware distribution service to get access to the network.
IcedID is a malware originally classified as a banking trojan and was first observed in 2017. It also acts as a loader for other malware, including ransomware.
IcedID is a malware originally classified as a banking trojan and was first observed in 2017. It also acts as a loader for other malware, including ransomware.
Microsoft attributes this campaign to Storm-0249... known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.
Proofpoint researchers have observed and documented, for the first time, three distinct variants of the malware known as IcedID. Proofpoint calls the two new variants recently identified “Forked” and “Lite” IcedID.
“Vacant Viper is known to affiliate with TA571, for which the 404TDS delivered IcedID and other malware.”
By allowing the macro inside the document, it will attempt to download the IcedID trojan... As a common IcedID approach it used steganography as a method to deliver the payload through a .png file... For persistence, IcedID creates a scheduled task to run hourly...
Since its discovery in 2017 as a banking trojan, ICEDID evolved into a pernicious point of entry for financially motivated actors to conduct intrusion operations.
Since its discovery in 2017 as a banking trojan, ICEDID evolved into a pernicious point of entry for financially motivated actors to conduct intrusion operations.
Exploited software
Vulnerabilities linked to IcedID
1 CVEsMITRE ATT&CK
IcedID in ATT&CK
73 distinct techniquesTechniques
73 techniquesReporting
Research mentioning IcedID
ATT&CK Navigator: gap-анализ TTP за один вечер
для T1020 (Automated Exfiltration) - IcedID Botnet HTTP PUT, Exfiltration via Encrypted FTP
Millenium: A RAT Rewritten, a Threat Multiplied | Community Portal | Gurucul
IcedID1
Targeting Cybercrime ‘Assembly Lines:’ Europol Announces Malware Crackdown - Decipher
Previously, the FBI and Europol targeted loaders like Bumblebee (in 2024), as well as others in the dropper/loader ecosystem like IcedID, Pikabot, and Smokeloader.
Правоохранители очистили 15 000 сайтов, зараженных SocGholish - Хакер
Также в прошлые годы операция затрагивала инфраструктуру SmokeLoader, DanaBot, IcedID, Pikabot, Trickbot, Bumblebee, SystemBC...
Operation Endgame Disrupts SocGholish Malware Infrastructure
In May 2024, the operation resulted in seizing around 100 servers belonging to dropper networks, including IcedID, SystemBC, Smokeloader, Trickbot, Pikabot, and Bumblebee
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
Previously, Operation Endgame has also targeted ransomware infrastructure, Smokeloader botnet customers and servers, the AVCheck site, and various other major malware operations, including DanaBot, IcedID, Pikabot, Trickbot, Smokeloader, Bumblebee, and SystemBC.
Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges - SecurityWeek
The Conti operation was linked to numerous other malware families, including TrickBot, which was also associated with Bazarloader, SystemBC, IcedID, Ryuk, and Diavol.
Украденные учётные данные: от инфостилера до domain admin
Operation Endgame затронула несколько ботнетов-дропперов (SmokeLoader, IcedID, Pikabot и др.).