Trojan
IcedID
First seen: 2017-09 • Status: active
Currently Active Threat
IcedID started out stealing banking credentials but evolved into something more dangerous. Now it's mainly used as a doorway for ransomware gangs. When IcedID infects a company, the criminals often sell that access to ransomware operators. It's one of the top malware families that leads to major ransomware attacks.
Overview
IcedID (also known as BokBot) started as a banking trojan but has evolved into a sophisticated malware loader. It is commonly used as an initial access broker, providing access to compromised networks for ransomware operators. IcedID is frequently distributed through malspam campaigns and has strong ties to ransomware groups.
Also Known As
BokBot, IcedID Loader
How It Spreads
- • Malicious email attachments (Office docs, ISO files)
- • Stolen email thread hijacking
- • Malicious Google Ads
- • Contact form spam campaigns
- • Compromised websites with fake updates
What It Does
- • Establishes persistent access to victim network
- • Steals banking and financial credentials
- • Provides remote access for ransomware operators
- • Collects system and network information
- • Downloads and executes additional payloads
- • Moves laterally using stolen credentials
Is your business exposed?
Target Platforms
Windows 10, Windows 11
Detection Tips
- • Monitor for regsvr32 executing DLLs from temp folders
- • Alert on scheduled tasks with Base64-encoded commands
- • Detect msiexec downloading from suspicious URLs
- • Watch for web injection attempts in browser processes
- • Monitor for unusual WMI process creation
MITRE ATT&CK Techniques
T1566.001, T1185, T1055, T1069, T1021.006
If You're Infected
- 1.
IcedID often leads to ransomware - prepare defenses immediately
- 2.
Isolate infected systems and begin incident response
- 3.
Verify backup integrity and ensure offline copies exist
- 4.
Hunt for Cobalt Strike or similar post-exploitation tools
- 5.
Reset credentials for any accounts accessed from infected systems
- 6.
Block known IcedID C2 infrastructure at firewall
Related Malware
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required