IcedID, also known as BokBot, is a Windows banking trojan that evolved into a broadly used malware loader and initial-access platform in cybercrime operations. It is widely associated with the Lunar Spider threat actor and has been repeatedly observed as an entry vector for follow-on intrusions involving Cobalt Strike and ransomware operators. Campaign reporting and intrusion case studies show IcedID being used to establish an initial foothold, collect host and system information, enable follow-on payload delivery, and support rapid progression to credential theft, lateral movement, and ransomware deployment by downstream operators.
IcedID has been delivered through phishing-driven infection chains and has appeared in campaigns using archive files, shortcut-file lures, and other socially engineered delivery mechanisms. It has also been distributed by spam-centric threat groups such as TA551 and TA577. In enterprise intrusions, IcedID infections have been followed by reconnaissance activity, credential access from LSASS, remote movement across hosts, and staging of additional tooling. Multiple ransomware ecosystems have relied on IcedID as an access mechanism, including operations linked to Conti, Quantum, Black Basta, DarkSide, Egregor, Maze, and related criminal clusters.
Technical analysis shows IcedID using custom unpacking and staged execution. Observed samples allocate memory, copy and transform embedded data in memory, and reconstruct a clean portable executable for a subsequent downloader stage. Reported unpacking behavior includes shellcode-related execution flow, repeated memory copying, and byte-wise deobfuscation operations. Operationally, IcedID has been associated with automated exfiltration behavior and downloader or botnet functionality in addition to its banking-trojan heritage.
IcedID remains notable because it bridges commodity malware distribution and high-impact post-compromise operations. Its role in modern intrusion chains is not limited to financial theft; it has functioned as a reliable access broker and malware delivery component for broader criminal campaigns targeting enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA551, also known as Shathak or Gold Cabin, is an attacker group that is responsible for spreading a wide variety of malware families including IcedID, Valak, Ursnif and, more recently, BazarLoader.
IcedID aka Bokbot is also one of the most prevalent banking trojans in the last years. It is known to be associated with Lunar Spider threat actors.
TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.
In addition, TA571 has been associated with the distribution of other malware families, including variants of IcedID, NetSupportRAT, DarkGate and others.
Proofpoint has tracked a new malware loader called Bumblebee used by multiple crimeware threat actors previously observed delivering BazaLoader and IcedID.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
As well as conning search engines to try and get their malicious sites near the top of search results, they can also pay for the privilege: buying paid ads so that their sites are guaranteed to appear prominently. This attack – known as ‘malvertising’ – is often aimed at users looking to download popular software applications.
The basic flow is as follows: An attacker sends a phishing email containing a .one file attachment.
Proofpoint researchers observed hundreds of emails attempting to deliver malicious Microsoft Word attachments with German lures impersonating the Bundeszentralamt fur Steuern... The lure states that a 2019 tax refund is due... and that the recipient should submit a refund request using an attached Microsoft Word document form.
The document has a macro in it that executes the base64 encoded PowerShell command and drops the next payload.
The Microsoft Word attachment, when opened, executes a Microsoft Office macro that, in turn, executes a PowerShell script...
When a user searches for a related term and clicks through to the malicious site, the attackers check the Referer header to confirm the user has come from a search engine, and then entice them into downloading malware disguised as a legitimate software application.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
Since encoded commands are often long, set a threshold (e.g., 1000 characters) to flag suspiciously long commands.
In malware, we often see threat actors that tend to obfuscate or encrypt their code in order to slow down the analysis of security researchers... many authors tend to use open-source packers but also craft their own custom packers.
Other campaigns have impersonated brands like Adobe, Gimp, Slack, Tor, and Thunderbird, in order to infect users with AuroraStealer, RedLine, Vidar, FormBook, and more.
Of particular note is the use of stolen branding as well as the use of lookalike .icu domains used for the sender email address in order to craft effective lures.
By inspecting the “ lpAddress ” argument in VirtualProtect we’ll notice that it appears to deal with shellcode execution.
At first glance, it seems this loop has characteristics we expect from traditional decryption\encryption routines, such as shr (shift right), xor , and rol (rotate left) opcodes... The loop changes the first bytes of the obfuscated content to “M8Z”, which starts to resemble the classic “MZ” string.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users. IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server. Sandworm Team has used a tool to query Active Directory using LDAP.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
109 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as part of an Atomic Red Team test example for ATT&CK technique T1020 Automated Exfiltration.
IcedID1
A malware family in the dropper/loader ecosystem referenced as a prior law-enforcement target.
Malware family whose infrastructure was targeted in prior Operation Endgame actions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.