Dridex is a long-running financially motivated cybercrime operation centered on the Dridex banking trojan and associated intrusion infrastructure. It is widely linked to the Evil Corp cybercriminal organization and has evolved from banking fraud into broader enterprise-focused intrusion activity, including ransomware deployment. Known aliases include Dridex and Dridex actors, and reporting has associated its operators with Evil Corp. The operation has also been tied to ransomware families including BitPaymer, DoppelPaymer, and FriedEx, with FriedEx widely identified as another name for BitPaymer. First observed in 2014, Dridex developed from a banking trojan into a sophisticated modular malware platform targeting Windows systems. It has been distributed at scale through malspam campaigns, commonly using phishing emails with malicious Office documents or links that retrieve follow-on payloads. Campaigns have used invoice, transaction, and travel-themed lures, and have frequently relied on compromised legitimate websites for malware hosting. Dridex has supported webinjects against online banking sessions and has incorporated advanced tradecraft including process injection, anti-analysis and obfuscation techniques, hashed API resolution, encrypted strings, and exploitation of Microsoft Word vulnerabilities. Reporting also notes the use of Atom Bombing injection in Dridex version 4. Operationally, Dridex has functioned as both banking malware and an access platform. It steals financial and other credentials, establishes backdoor access, and enables follow-on malware delivery. The operators have demonstrated resilience and payload diversification, with shared spam infrastructure also used to distribute other banking malware families such as Shifu and Ursnif. Dridex activity has rebounded rapidly after law-enforcement disruption, indicating a mature and segmented criminal ecosystem. High-confidence reporting links the developers behind Dridex to the FriedEx/BitPaymer ransomware family through extensive code overlap, shared build characteristics, and common implementation details. BitPaymer/FriedEx was used against higher-profile organizational victims and was commonly delivered after remote access compromise via brute-force attacks against exposed services. Dridex operators have also been associated with targeted, high-impact bank fraud and ransomware operations involving BitPaymer and DoppelPaymer. Overall, Dridex represents a major financially motivated threat cluster that bridges mass-distributed banking malware, enterprise intrusion, and ransomware monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cybercrime group described as a former Business Club offshoot that advanced the crimeware-as-a-service model and conducted bank fraud and ransomware operations.
Uses travel-themed phishing and malspam campaigns to distribute malware via malicious Excel attachments or links to download spreadsheets, establishing backdoor access that can later enable follow-on malware including ransomware.
The Dridex group is described as the developer of the Dridex banking trojan and, based on code and build similarities, also the creator of the FriedEx/BitPaymer ransomware. The group steadily updates Dridex and has expanded into ransomware operations targeting higher-profile organizations.
Resumed large-scale spam-driven malware operations after arrests and takedown attempts, operating multiple Dridex sub-botnets and also distributing Shifu and at least one Ursnif campaign via the same spam infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.