Last seven days
- First activity
- Aug 24, 2026
- Last activity
- Aug 24, 2026
- Feed role
- C2
- Host form
- 0 IP / 2 hostnames
Simda, also known as Shiz and sometimes associated with iBank naming in detections, is a Windows malware family and botnet used by cybercriminal operators since at least 2009.
Profile source: Mallory opens in a new tabSimda
Simda, also known as Shiz and sometimes associated with iBank naming in detections, is a Windows malware family and botnet used by cybercriminal operators since at least 2009. It is best known as an information-stealing threat that also provides remote backdoor access to compromised systems, enabling operators to reroute web traffic, inject or modify website content, harvest credentials and banking-related information, and deploy additional malware. Simda infections were historically widespread, with global botnet activity affecting large numbers of Windows hosts.
Simda has been associated with infections on systems running unpatched software and with a criminal pay-per-install ecosystem. Once established, it can support follow-on payload delivery and broader post-compromise activity through remote control of infected machines. Reporting also describes the malware as stealthy, with backdoor components changing their presence periodically to reduce antivirus detection.
Technically, Simda is notable for use of a domain generation algorithm for command-and-control resilience. Analyses describe generation of large sets of candidate domains based on sample-specific parameters such as key-derived values, domain length, and top-level domain. Simda samples have also used process injection, including DLL injection into the Windows Winlogon process via remote memory writing and remote thread creation, to execute malicious code within legitimate processes and evade defenses.
Simda has been described both as a malware family and as the botnet built from infected hosts under criminal control. Its operators used the resulting access for credential theft, traffic manipulation, malware installation, and resale or leasing of compromised-machine access to other criminals.
C2 tracking
Derp observations, rolling seven-day window
Samples
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.