IcedID, also known as BokBot, is a Windows banking trojan and information stealer first identified in 2017. It steals login credentials, banking data, and other personal information, including through x86 and x64 browser-hook components. IcedID uses custom encrypted formats and nonstandard PE representations to conceal configuration and payload data, and variants have employed process injection, including injection into a suspended Windows Installer process for command-and-control communications. It can establish persistence through a scheduled task configured to run hourly.
IcedID has been delivered through email-borne malicious attachments, including nested archive, disk-image, and compiled-help-file chains, as well as malicious macro-enabled Word documents. It has also been distributed through Emotet infrastructure and in campaigns associated with TA578. IcedID infections have been observed alongside BackConnect, VNC payloads, and Cobalt Strike, and the family has been linked to delivery of additional malware including DarkVNC and Cobalt Strike. IcedID activity has also been associated with UNC2198 and ransomware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Kevin Beaumont reported on this conversation hijacking technique back in November 2021 being used to distribute Qakbot. Through the investigation, he confirmed that the Microsoft Exchange servers where the emails originated from had evidence of being exploited by ProxyShell... The majority of the originating Exchange servers we have observed appear to also be unpatched and publicly exposed, making the ProxyShell vector a good theory.
In November 2021, a Trend Micro report described a wave of attacks using ProxyShell and ProxyLogon vulnerabilities in exposed Microsoft Exchange servers to hijack internal email reply-chains and spread malware-laced documents. | The distribution of the IcedID malware has seen a spike recently due to a new campaign that hijacks existing email conversation threads and injects malicious payloads that are hard to spot. IcedID is a modular banking trojan first spotted back in 2017, used mainly to deploy second-stage malware such as other loaders or ransomware.
the seller offered two types of weaponized Microsoft Office documents (maldocs) to users: one that exploits a known vulnerability in Microsoft Office (CVE-2017-8570) and another that uses a malicious macro.
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
30 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2022-06-28 (TUESDAY) - TA578 ICEDID (BOKBOT) WITH BACKCONNECT, ANUBIS VNC AND COBALT STRIKE
"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"
"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"
In 2017 it was the first group to deliver the IcedID (Trojan.IcedID) banking Trojan.
IcedID – a botnet loader known to arise from malicious documents and often leading to Cobalt Strike or other backdoors that position threat actors for ransomware deployment.
IcedID – a botnet loader known to arise from malicious documents and often leading to Cobalt Strike or other backdoors that position threat actors for ransomware deployment.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Drive by social-engineering attacks remains a popular vector for various malware loaders.
The Trojan is distributed using convincingly crafted phishing emails that contain malicious word documents.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
the malware was delivered via email in an attached Microsoft Word document containing malicious VBA macros.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
«злоумышленники конструируют файл, который можно прочитать разными способами, например он одновременно является корректным архивом ZIP и корректным исполнимым файлом ... чтобы избежать детектирования защитными решениями и обмануть пользователя».
“The ICEDID fake GZip is a file that masquerades as a valid GZip file” by encapsulating the actual data with GZip headers and footers.
IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
В кампании IcedID: «из [ISO] распаковывается файл CHM ... корректно обрабатывается как приложение mshta ... которое уже скачивает основное вредоносное ПО».
eSentire Threat Intelligence team has observed and disrupted two incidents earlier this week that utilized Google ads to deliver malware (Vidar Stealer & IcedID leading to Cobalt Strike).
“This configuration contains two C2 domains: alishaskainz[.]com villageskaier[.]com. For this sample, the beaconing URI that ICEDID uses is ‘/news/’.”
В цепочке IcedID «mshta ... уже скачивает основное вредоносное ПО».
The C2 activity can lead to BackConnect traffic, Cobalt Strike and Virtual Network Computing (VNC) activity ... However, this pcap does not contain any indicators of Cobalt Strike. | The C2 activity can lead to BackConnect traffic, Cobalt Strike and Virtual Network Computing (VNC) activity. | Undetected IcedID infections lead to follow-up activity like BackConnect traffic ... Previous IcedID infections also reveal this threat can generate VNC traffic over the same IP address used by BackConnect traffic.
1,269 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer distributed through a nested attachment chain designed to evade detection: ZIP archive, ISO disk image, and CHM file that is handled by mshta to download the primary payload.
Infostealer distributed through a nested polyglot attachment chain: ZIP archive to ISO image to a CHM file that is also processed as an mshta application, which downloads the primary payload.
A banking trojan and malware dropper spread primarily through phishing emails with malicious Office documents. In this campaign it used benign-looking macros that extracted obfuscated JavaScript from the document, dropped and executed an HTA via mshta.exe, downloaded a DLL disguised as a .jpg file, and then stole and exfiltrated host and credential-related data to C2 infrastructure.
Browser-hooking banking trojan associated with remote thread creation into browser processes to steal sensitive information such as banking details.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.