Skip to content

IcedID

IcedID, also known as BokBot, is a Windows banking trojan that evolved into a broadly used malware platform for credential theft, host profiling, payload delivery, and follow-on intrusion support.

Profile source: Mallory opens in a new tab

IcedID

Family profile

IcedID, also known as BokBot, is a Windows banking trojan that evolved into a broadly used malware platform for credential theft, host profiling, payload delivery, and follow-on intrusion support. It has been associated with the LUNAR SPIDER cybercrime ecosystem and has been widely used in financially motivated operations, including as an initial infection vector preceding hands-on-keyboard activity and ransomware deployment. Intrusions linked to Quantum and other ransomware operations have used IcedID to establish footholds, conduct reconnaissance, support credential access, and enable later deployment of frameworks such as Cobalt Strike and ransomware payloads.

IcedID is commonly delivered through phishing-driven infection chains and malspam campaigns, and it has appeared in distribution ecosystems used by groups such as TA551 and TA577. Observed tradecraft around campaigns involving IcedID includes abuse of shortcut files, ISO images, macro-enabled documents, HTML smuggling, and Base64-encoded PowerShell execution. The malware has also been delivered as a follow-on payload by other loaders, and more recent reporting indicates that Latrodectus is likely operated by the same ecosystem and has delivered IcedID as a secondary payload.

Technically, IcedID is known for staged execution and custom unpacking. Analysis of first-stage samples shows shellcode-related execution flow, memory allocation and protection changes, repeated memory copying, and byte-wise decryption operations that reconstruct a clean portable executable in memory. Its functionality has included automated exfiltration and downloader behavior, and it has been referred to internally by some operators as a loader or botnet component. IcedID has remained a significant element of the cybercrime loader ecosystem and has been the subject of repeated international disruption efforts targeting the broader malware supply chain.

Capabilities

  • Credential Theft
  • Exfiltration
  • Initial Access
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 26, 2026
Last activity
Jul 26, 2026
Feed role
C2
Host form
0 IP / 5 hostnames

Leading locations

  • US3

Leading providers

  • Amazon.com, Inc.2
  • Amazon.com, Inc.1

Infrastructure traits

  • Hosting 3

Samples

Recent associated samples

Reported operators

Threat actors

18 named in public reporting
Lunar Spider

Treat any Latrodectus hit as the first stage of a hands-on intrusion, it has delivered IcedID and Brute Ratel C4, and recent builds add a BackConnect (VNC) module.

Maze

WizardSpider (Conti, Ryuk) Egregor DarkSide Maze Team (Maze & IcedID)

TA551

TA551, also known as Shathak or Gold Cabin, is an attacker group that is responsible for spreading a wide variety of malware families including IcedID, Valak, Ursnif and, more recently, BazarLoader.

TA577

TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.

TA571

In addition, TA571 has been associated with the distribution of other malware families, including variants of IcedID, NetSupportRAT, DarkGate and others.

TA579

Proofpoint has tracked a new malware loader called Bumblebee used by multiple crimeware threat actors previously observed delivering BazaLoader and IcedID.

TA578

Proofpoint has tracked a new malware loader called Bumblebee used by multiple crimeware threat actors previously observed delivering BazaLoader and IcedID.

WIZARD SPIDER

Most notable are the acquisitions of developers from Emotet, Qakbot, and IcedID, bringing them to the DEV-0193 umbrella.

Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... IcedID, a modular information-stealing malware

Lockean

In at least one known instance, Lockean used the IcedID malware distribution service to get access to the network.

TA544

IcedID is a malware originally classified as a banking trojan and was first observed in 2017. It also acts as a loader for other malware, including ransomware.

TA581

IcedID is a malware originally classified as a banking trojan and was first observed in 2017. It also acts as a loader for other malware, including ransomware.

Storm-0249

Microsoft attributes this campaign to Storm-0249... known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.

TA542

Proofpoint researchers have observed and documented, for the first time, three distinct variants of the malware known as IcedID. Proofpoint calls the two new variants recently identified “Forked” and “Lite” IcedID.

vacant_viper

“Vacant Viper is known to affiliate with TA571, for which the 404TDS delivered IcedID and other malware.”

Gold Dupont

By allowing the macro inside the document, it will attempt to download the IcedID trojan... As a common IcedID approach it used steganography as a method to deliver the payload through a .png file... For persistence, IcedID creates a scheduled task to run hourly...

UNC2198

Since its discovery in 2017 as a banking trojan, ICEDID evolved into a pernicious point of entry for financially motivated actors to conduct intrusion operations.

UNC2420

Since its discovery in 2017 as a banking trojan, ICEDID evolved into a pernicious point of entry for financially motivated actors to conduct intrusion operations.

Exploited software

Vulnerabilities linked to IcedID

1 CVEs

MITRE ATT&CK

IcedID in ATT&CK

74 distinct techniques

Techniques

74 techniques
T1105 Ingress Tool Transfer T1583.003 Virtual Private Server T1218.011 Rundll32 T1082 System Information Discovery T1020 Automated Exfiltration T1547.001 Registry Run Keys / Startup Folder T1059.001 PowerShell T1027 Obfuscated Files or Information T1566 Phishing T1027.002 Software Packing T1140 Deobfuscate/Decode Files or Information T1055 Process Injection T1204.002 Malicious File T1071.001 Web Protocols T1016 System Network Configuration Discovery T1087.002 Domain Account T1018 Remote System Discovery T1204 User Execution T1598 Phishing for Information T1560 Archive Collected Data T1036 Masquerading T1583 Acquire Infrastructure T1036.005 Match Legitimate Resource Name or Location T1656 Impersonation T1566.001 Spearphishing Attachment T1059.005 Visual Basic T1566.002 Spearphishing Link T1112 Modify Registry T1573 Encrypted Channel T1047 Windows Management Instrumentation T1614.001 System Language Discovery T1053.005 Scheduled Task T1550 Use Alternate Authentication Material T1539 Steal Web Session Cookie T1071 Application Layer Protocol T1027.013 Encrypted/Encoded File T1005 Data from Local System T1555 Credentials from Password Stores T1059.007 JavaScript T1547.009 Shortcut Modification T1189 Drive-by Compromise T1518.001 Security Software Discovery T1587.001 Malware T1562 Impair Defenses T1069.001 Local Groups T1027.006 HTML Smuggling T1482 Domain Trust Discovery T1135 Network Share Discovery T1218.010 Regsvr32 T1059.003 Windows Command Shell T1553.002 Code Signing T1218.007 Msiexec T1033 System Owner/User Discovery T1070.004 File Deletion T1027.009 Embedded Payloads T1036.003 Rename Legitimate Utilities T1059 Command and Scripting Interpreter T1078 Valid Accounts T1562.001 Disable or Modify Tools T1087 Account Discovery T1218.005 Mshta T1053 Scheduled Task/Job T1027.003 Steganography T1497 Virtualization/Sandbox Evasion T1573.002 Asymmetric Cryptography T1055.012 Process Hollowing T1204.001 Malicious Link T1185 Browser Session Hijacking T1555.003 Credentials from Web Browsers T1560.001 Archive via Utility T1055.004 Asynchronous Procedure Call T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1106 Native API T1069 Permission Groups Discovery

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.