Trojan

IcedID

First seen: 2017-09 • Status: active

Currently Active Threat

IcedID started out stealing banking credentials but evolved into something more dangerous. Now it's mainly used as a doorway for ransomware gangs. When IcedID infects a company, the criminals often sell that access to ransomware operators. It's one of the top malware families that leads to major ransomware attacks.

Overview

IcedID (also known as BokBot) started as a banking trojan but has evolved into a sophisticated malware loader. It is commonly used as an initial access broker, providing access to compromised networks for ransomware operators. IcedID is frequently distributed through malspam campaigns and has strong ties to ransomware groups.

Also Known As

BokBot, IcedID Loader

How It Spreads

  • Malicious email attachments (Office docs, ISO files)
  • Stolen email thread hijacking
  • Malicious Google Ads
  • Contact form spam campaigns
  • Compromised websites with fake updates

What It Does

  • Establishes persistent access to victim network
  • Steals banking and financial credentials
  • Provides remote access for ransomware operators
  • Collects system and network information
  • Downloads and executes additional payloads
  • Moves laterally using stolen credentials

Is your business exposed?

Target Platforms

Windows 10, Windows 11

Detection Tips

  • Monitor for regsvr32 executing DLLs from temp folders
  • Alert on scheduled tasks with Base64-encoded commands
  • Detect msiexec downloading from suspicious URLs
  • Watch for web injection attempts in browser processes
  • Monitor for unusual WMI process creation

MITRE ATT&CK Techniques

T1566.001, T1185, T1055, T1069, T1021.006

If You're Infected

  1. 1.

    IcedID often leads to ransomware - prepare defenses immediately

  2. 2.

    Isolate infected systems and begin incident response

  3. 3.

    Verify backup integrity and ensure offline copies exist

  4. 4.

    Hunt for Cobalt Strike or similar post-exploitation tools

  5. 5.

    Reset credentials for any accounts accessed from infected systems

  6. 6.

    Block known IcedID C2 infrastructure at firewall

Related Malware

Trickbot, Emotet, Cobalt Strike

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required