Researchers documented continued Simda malware activity using a domain generation algorithm (DGA) to maintain command-and-control resilience and evade takedowns. Reverse-engineering of Simda, also tracked as Shiz and sometimes linked to iBank, showed the malware can generate 1,000 domains per run using sample-specific seeds, keys, domain lengths, and top-level domains. Historical analysis tied multiple malware samples observed between 2013 and 2015 to several distinct seed sets, expanding prior public tracking of the family’s DGA behavior.
A later Simda sample analyzed by SonicWall used DLL injection into the Windows winlogon process, calling WriteProcessMemory and CreateRemoteThread to load WinSCard.dll. SonicWall said the sample retained the family’s DGA-based infrastructure, generating up to 1,000 active C2 domains, with observed use of .com domains and prior Simda-related activity also tied to .eu, .info, .su, and .net. The malware was described as an information stealer that can also alter websites through injection, underscoring Simda’s combination of stealthy process compromise and durable C2 generation.

Get the actors, campaigns, and ATT&CK mapping behind it.
10 events from the most recent confirmed update back to the earliest known activity.
A sample with MD5 ad71cd5a05db9473c5580eb070963bf9 was analyzed on Malwr.com and mapped to seed set 1, showing the DGA configuration still in use in 2015.
A sample with MD5 809652095b88a2fa0ea4dd89760599c1 was analyzed on Malwr.com and mapped to seed set 2, adding another observed Simda/Shiz DGA variant.
A sample with MD5 11b54c5d8531c0705d30a87f2b42a20f was analyzed on Malwr.com and mapped to seed set 4, for which the key sum was later brute-forced by the researcher.
The reverse-engineering note states that multiple Malwr.com samples analyzed between February and July 2014 mapped to seed set 5, indicating recurring use of that Simda/Shiz DGA configuration.
A sample with MD5 d0acd37e9075990d0f1289db350c258d was analyzed on Malwr.com and mapped to seed set 1, indicating continued reuse of that Simda/Shiz DGA seed set.
A sample with MD5 ecbdcf103052f1537798e5b27e1f2538 was analyzed on Malwr.com and mapped to seed set 3, showing another Simda/Shiz DGA configuration in use.
A Simda/Shiz malware sample with MD5 9c5e9e1a049ec198abf461f92758d8b5 was analyzed on Malwr.com and mapped to seed set 1 of the malware's DGA configuration.
SonicWall said Microsoft had previously documented the Simda malware family and first identified its use of a domain generation algorithm in 2012.
SonicWall Capture Labs reported a new Simda sample and related activity observed in August, describing DLL injection into the Winlogon process and loading of a DLL named WinSCard.dll.
A reverse-engineering analysis of the Simda/Shiz DGA documented how the malware generates 1,000 domains per run and identified six seed sets in total, including two additional seeds beyond prior DGArchive and abuse.ch work.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 93 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.