Ice IX is a Zeus-derived Windows banking malware family that emerged after the ZeuS 2.0.8.9 source code became public. It is widely characterized as a banking Trojan and bot built from leaked Zeus code, with only modest architectural changes from its predecessor but a strong focus on credential theft and online banking fraud. Ice IX manipulates banking sessions on infected hosts through Zeus-style web injects and browser hooking, enabling man-in-the-browser theft of credentials and other sensitive data from both HTTP and HTTPS sessions. It can alter web content presented to victims, inject fraudulent fields into banking pages, redirect users to attacker-controlled pages, and capture screenshots to support theft from sites that use virtual keyboards or other interactive defenses.
The malware communicates with command-and-control infrastructure over HTTP using a gate script intermediary rather than direct backend access. Traffic is obfuscated and encrypted with Zeus-style routines including RC4-based protection, and some variants generate benign-looking web requests to blend malicious traffic with normal browsing activity. Ice IX supports remote configuration and updating, allowing operators to change inject rules, redirect logic, collection filters, and other operational parameters after deployment.
Ice IX includes broad information-stealing functionality beyond banking credentials. Documented capabilities include form grabbing, theft of browser-stored data, cookies, Flash local storage, email client credentials, FTP client credentials, and certificates from the Windows certificate store. It can also delete certificates after export, likely to disrupt victim authentication material and facilitate fraud. Additional operator-controlled features include screenshot capture, URL blocking, homepage modification, host reboot or shutdown, and removal of stolen artifacts from the victim system.
On infected Windows systems, Ice IX establishes persistence through registry autorun mechanisms and may randomize names to hinder detection. It also exhibits self-deleting dropper behavior after installation. Some analyses describe support for backconnect access, SOCKS proxying, and VNC-based remote control, extending its utility beyond credential theft into broader post-compromise operations and fraud enablement.
Ice IX has been associated with criminal infrastructure used in Zeus-related financial malware operations and has appeared alongside other Zeus-lineage families in the broader banking malware ecosystem. It has been linked to infrastructure involved in online banking fraud campaigns and is best understood as a repackaged, operationally enhanced Zeus descendant rather than a fundamentally new malware architecture.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
This identifier is encrypted using the RC4 algorithm... The MD5 checksum is calculated for the encrypted data and sent as a hash variable. The configuration file is also encrypted using the same RC4 algorithm with the same S-box.
Web injection is a technique in which a bot injects malicious content into the incoming HTTP responses. The injected content tricks the user into entering sensitive information.
The ‘C’ flag instructs the bot to manage the cookie handling support for the masked URI so it can preserve and delete the cookies associated with the domain.
A modified function that is associated with reading data from the registry has been identified... In the ZeuS 2.0.8.9 code, the function that reads data from the registry includes all the API functions required for this task, i.e., RegOpenKeyEx, RegQueryValueEx and RegCloseKey.
Web injection is a technique in which a bot injects malicious content into the incoming HTTP responses. The injected content tricks the user into entering sensitive information.
It also implements a screen-capturing module, in which the botmaster defines the rules for capturing screenshots of target websites.
This technique is implemented using DLL injection and hooking to implement a man-in-the-middle-style attack within the browser. This attack, known as a man-in-the-browser attack, allows the bot to manipulate the data that is coming in and going out of the system.
The C&C server implements its visualEncrypt function to obfuscate the data, followed by an RC4 encryption routine that uses a predefined crypto key to encrypt the full stream and then sends it back to the bot.
The author charged $600 for a version of the bot with a hardwired URL that the bot must connect to after infection (i.e., the C&C address), and $1800 for a version without a hard-coded C&C address.
ICE IX communicates using the HTTP protocol... receiving_script_path: this parameter defines a path to the gateway that the ICE bot uses to connect back to its Command and Control (C&C) server. | The bot keeps sending HTTP POST requests back to the C&C server to notify it of any updates in the system and to send extracted information.
ICE bot implements SOCKS proxy with backconnect support. In addition, it also supports the VNC remote management module.
autoupdate_path: this parameter defines the path of the executable file (hosted in a remote location) that the ICE bot downloads to update itself when configuration parameters change.
Brainrace.ru pointed to the server as an alternative to the Albania and San Jose servers listed in the DNS history, most likely to dynamically rotate its control among the three locations.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ZeuS-derived bot/banking trojan marketed as an enhanced version of ZeuS. The analysis says its claimed improvements were largely overstated; observed changes included re-enabled email credential theft code, minor code changes, altered web filter symbols, and a modified POST-based method for downloading the encrypted configuration file.
Zeus-related banking malware mentioned only in historical background.
A Zeus-derived bot/banking trojan that communicates over HTTP, uses web injects and form grabbing to steal banking credentials, supports URL redirection, screenshot capture, certificate theft/deletion, cookie and Flash data theft, backconnect/SOCKS and VNC modules, self-update, and remote command execution.
Zeus-derived banking malware hosted on the Arizona server as a drop zone and control server, communicating with brainrace.ru and tied to the same infrastructure later used in Operation High Roller.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.