Last seven days
- First activity
- Sep 7, 2026
- Last activity
- Sep 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 999 hostnames
Simda, also known as Shiz and sometimes associated with iBank naming in detections, is a Windows malware family and botnet used by cybercriminal operators since at least 2009.
Profile source: Mallory opens in a new tabSimda
Simda, also known as Shiz and sometimes associated with iBank naming in detections, is a Windows malware family and botnet used by cybercriminal operators since at least 2009. It is best known as an information-stealing threat that also provides remote backdoor access to compromised systems, enabling operators to reroute web traffic, inject or modify website content, harvest credentials and banking-related information, and deploy additional malware. Simda infections were historically widespread, with global botnet activity affecting large numbers of Windows hosts.
Simda has been associated with infections on systems running unpatched software and with a criminal pay-per-install ecosystem. Once established, it can support follow-on payload delivery and broader post-compromise activity through remote control of infected machines. Reporting also describes the malware as stealthy, with backdoor components changing their presence periodically to reduce antivirus detection.
Technically, Simda is notable for use of a domain generation algorithm for command-and-control resilience. Analyses describe generation of large sets of candidate domains based on sample-specific parameters such as key-derived values, domain length, and top-level domain. Simda samples have also used process injection, including DLL injection into the Windows Winlogon process via remote memory writing and remote thread creation, to execute malicious code within legitimate processes and evade defenses.
Simda has been described both as a malware family and as the botnet built from infected hosts under criminal control. Its operators used the resulting access for credential theft, traffic manipulation, malware installation, and resale or leasing of compromised-machine access to other criminals.
C2 tracking
Derp observations, rolling seven-day window
Samples
2af10f0c0ef1328fc8bcf798139c53b82fc75e22fa321b046f398063a49c3f70 4471cebc9bf6c027f7a8810aae9fd53b922c5b4baf13d5223187ee74eb926666 7444f1d720924299c9867e04a54867c4b67c40a4e97ec101c0f4083b23d7b947 82a3c4694ae6edd7e64ff2cd4149476e998ea4a9f4590691e29bee51044a2fbd b30917f47523431b05576f5d0baacd71fa482e74a3839b5ce761ba6c21d5ad97 fbacee2facdd850e09e5c6cd6d29d69cfba76b95d9e700383d267d0b5e413580 032e98f0e9901b188a69cdb9407ab8028623cfe77f047a0d9edd625175c63db0 9587180099b7f6055acfcc44a09ce40011a7a95df1492d6e2c0427f145213b56 ae6cf0cd39c8de36bb2d0c1fbcb23fe3671b451447cefbe43528d5f270d0577a caeb4da4db7e2b872a1f97cd0fe69427ccd9b04c9d7edf5edbf3ac9bdf55aac7 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.