Skip to content

Simda

Simda, also known as Shiz and sometimes associated with iBank naming in detections, is a Windows malware family and botnet used by cybercriminal operators since at least 2009.

Profile source: Mallory opens in a new tab

Simda

Family profile

Simda, also known as Shiz and sometimes associated with iBank naming in detections, is a Windows malware family and botnet used by cybercriminal operators since at least 2009. It is best known as an information-stealing threat that also provides remote backdoor access to compromised systems, enabling operators to reroute web traffic, inject or modify website content, harvest credentials and banking-related information, and deploy additional malware. Simda infections were historically widespread, with global botnet activity affecting large numbers of Windows hosts.

Simda has been associated with infections on systems running unpatched software and with a criminal pay-per-install ecosystem. Once established, it can support follow-on payload delivery and broader post-compromise activity through remote control of infected machines. Reporting also describes the malware as stealthy, with backdoor components changing their presence periodically to reduce antivirus detection.

Technically, Simda is notable for use of a domain generation algorithm for command-and-control resilience. Analyses describe generation of large sets of candidate domains based on sample-specific parameters such as key-derived values, domain length, and top-level domain. Simda samples have also used process injection, including DLL injection into the Windows Winlogon process via remote memory writing and remote thread creation, to execute malicious code within legitimate processes and evade defenses.

Simda has been described both as a malware family and as the botnet built from infected hosts under criminal control. Its operators used the resulting access for credential theft, traffic manipulation, malware installation, and resale or leasing of compromised-machine access to other criminals.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 24, 2026
Last activity
Aug 24, 2026
Feed role
C2
Host form
0 IP / 2 hostnames

Leading locations

  • CA1
  • US1

Leading providers

  • Google LLC1
  • Team Internet AG1

Infrastructure traits

  • Hosting 2
  • Anycast 1

Samples

Recent associated samples

MITRE ATT&CK

Simda in ATT&CK

11 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.