Dridex is a modular banking Trojan and malware delivery platform that emerged from the Cridex/Bugat lineage and became one of the most prevalent financial malware families targeting online banking users and financial institutions. It is strongly associated with Evil Corp and has also been linked in industry reporting to TA505, while multiple threat actors have distributed it over time. Dridex has been used both for direct financial theft and as an access-enablement malware family in broader post-compromise operations, including ransomware deployment.
Dridex is primarily distributed through phishing and malspam campaigns that use business-themed lures and malicious attachments, often compressed archives containing macro-enabled Microsoft Office documents. Victims are commonly induced to enable macros or otherwise execute embedded content, after which Dridex retrieves and launches additional components. Recent activity has also included exploitation of Microsoft Office vulnerability CVE-2017-0199, and modified variants such as DoppelDridex have been delivered through payloads staged on trusted messaging-service CDNs using Excel 4.0 macro documents. Dridex has also been observed delivered by other malware distribution frameworks, including Emotet and SocGholish.
Functionally, Dridex is designed to steal banking credentials and facilitate fraud. It can inject into browser sessions, monitor access to online banking portals, use API hooking and keylogging to capture credentials, and collect screenshots and other victim data. Stolen information is packaged, encrypted, and transmitted over peer-to-peer communications. Dridex is modular and can download additional components after initial infection, enabling botnet participation and expanded functionality. Reported execution and persistence behaviors include use of regsvr32 to initiate malicious code, as well as techniques involving file modification, privilege escalation, and firewall-rule changes to support communications and continued access.
Beyond credential theft, Dridex has played a major role as an initial-access and follow-on malware enabler. It has been linked to delivery chains and operational overlap involving Locky and ransomware families such as BitPaymer and DoppelPaymer, and has been cited as a loader used to provide network access for later ransomware deployment. Victimology has historically been broad, with a notable concentration on English-speaking countries and the financial services sector, though Dridex-enabled operations have affected enterprises and government organizations across multiple industries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft has issued a critical patch for a vulnerability affecting Microsoft Office and WordPad. The vulnerability allows Rich Text Format (RTF) documents to run scripts when opened. Malicious email campaigns using this vulnerability to install the Dridex banking trojan and other malware have been reported. | Malicious email campaigns using this vulnerability to install the Dridex banking trojan and other malware have been reported.
Similar to techniques utilized by Dridex and Locky in mid-2017, the PDF contained an embedded RTF file which contains an embedded remote object that attacks CVE-2017-8579.
CVE-2012-0158 Vulnerable Products: Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Associated Malware: Dridex Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-0199 ... Associated Malware: FINSPY, LATENTBOT, Dridex; CVE-2012-0158 ... Associated Malware: Dridex
Threat actors now exploit the critical Apache Log4j vulnerability named Log4Shell to infect vulnerable devices with the notorious Dridex banking trojan or Meterpreter.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A modified version of the banking trojan Dridex – named DoppelDridex – is being delivered via payloads staged on Slack and Discord CDNs.
A modified version of the banking trojan Dridex – named DoppelDridex – is being delivered via payloads staged on Slack and Discord CDNs.
The Treasury Department has similarly said Maksim Yakubets, the alleged leader of the Evil Corp cybercrime organization, worked for the FSB and was tasked with projects on behalf of the Russian state while his organization carried out financially motivated attacks.
Typically, this group varies its payloads which appear to be targeted by region – for example, in 2021, all TA544 Ursnif campaigns have specifically targeted Italian organizations while Dridex payloads associated with this threat actor do not have specific geographic targeting.
The emails contained links to download Microsoft Excel documents containing macros that, when enabled, downloaded the Dridex malware designed to steal banking and other personal information.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
SocGholish is an advanced delivery framework used in drive-by-download and watering hole attacks.
the Bugat malware allowed computer intruders to hijack a computer session and present a fake online banking webpage to trick a user into entering personal and financial information.
In other cases, macros launch scripts that extract executables imbedded in the document as opposed to downloading the payload.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
leveraging attachments with the Excel 4.0 sheet-style macros to fetch the initial payload
The vulnerability allows Rich Text Format (RTF) documents to run scripts when opened.
Many of the files, rather than containing the actual malware, contain hidden or obfuscated macros.
In other cases, macros launch scripts that extract executables imbedded in the document as opposed to downloading the payload.
Bugat malware was allegedly designed to automate the theft of confidential personal and financial information, such as online banking credentials, and facilitated the theft of confidential personal and financial information by a number of methods.
inject malware or keylogging software, via API hooking, to steal customer login information
Bugat malware was allegedly designed to automate the theft of confidential personal and financial information, such as online banking credentials, and facilitated the theft of confidential personal and financial information by a number of methods.
inject malware or keylogging software, via API hooking, to steal customer login information
inject malware or keylogging software, via API hooking, to steal customer login information
1,002 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another notable banking Trojan used by attackers to steal credentials and financial information.
A banking trojan associated in the article with Evil Corp and financially motivated cyberattacks.
Banking trojan family whose C2 infrastructure is tracked by Abuse.ch Feodo Tracker.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.