Simda, also known as Shiz and sometimes associated with iBank naming in detections, is a Windows malware family and botnet used by cybercriminal operators since at least 2009. It is best known as an information-stealing threat that also provides remote backdoor access to compromised systems, enabling operators to reroute web traffic, inject or modify website content, harvest credentials and banking-related information, and deploy additional malware. Simda infections were historically widespread, with global botnet activity affecting large numbers of Windows hosts.
Simda has been associated with infections on systems running unpatched software and with a criminal pay-per-install ecosystem. Once established, it can support follow-on payload delivery and broader post-compromise activity through remote control of infected machines. Reporting also describes the malware as stealthy, with backdoor components changing their presence periodically to reduce antivirus detection.
Technically, Simda is notable for use of a domain generation algorithm for command-and-control resilience. Analyses describe generation of large sets of candidate domains based on sample-specific parameters such as key-derived values, domain length, and top-level domain. Simda samples have also used process injection, including DLL injection into the Windows Winlogon process via remote memory writing and remote thread creation, to execute malicious code within legitimate processes and evade defenses.
Simda has been described both as a malware family and as the botnet built from infected hosts under criminal control. Its operators used the resulting access for credential theft, traffic manipulation, malware installation, and resale or leasing of compromised-machine access to other criminals.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
This particular sample uses Dynamic-Link Library (DLL) injection. This involves writing multiple components of the injection process into the remote process with an API named "WriteProcessMemory" and "CreateRemoteThread". The remote process that will be supplying the code cave is called "Winlogon".
The backdoors also morph their presence every few hours, allowing low anti-virus detection rates and the means for stealthy operation.
This particular sample uses Dynamic-Link Library (DLL) injection. This involves writing multiple components of the injection process into the remote process with an API named "WriteProcessMemory" and "CreateRemoteThread". The remote process that will be supplying the code cave is called "Winlogon".
Adversaries may make use of Domain Generation Alogirthms (DGAs) to dynamically identify a destination for command and control traffic rather than relying on a list of static IP addresses or domains.
This malware may re-route a user’s Internet traffic to websites under criminal control...
The malicious actors control the network of compromised systems (botnet) through backdoors, giving them remote access to carry out additional attacks...
93 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing malware that can modify websites through injection, uses DLL injection into Winlogon, and employs a domain generation algorithm (DGA) to produce command-and-control domains active far into the future.
Self-propagating malware associated with the Simda botnet that compromises Windows systems, reroutes internet traffic to attacker-controlled websites, installs additional malware, and provides remote backdoor access to compromised hosts.
Simda is malware whose domain generation algorithm (DGA) is analyzed in detail. The post describes how different samples use varying seeds, domain lengths, TLDs, and keys to generate command-and-control domains.
Mentioned only in a sidebar link title.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.