IcedID operators continued to adapt email-borne delivery chains by abusing hijacked conversation threads, compromised Microsoft Exchange accounts, and password-protected archives to make phishing messages appear legitimate. Across multiple campaigns, victims received PDFs, Word documents, or links to cloud-hosted payloads on Google Firebase or Google Cloud Storage, which led to ZIP archives containing ISO images, malicious LNK files, DLL loaders, or signed executables. Researchers tied parts of this activity to TA551/Shathak and reported targeting of organizations in the energy, healthcare, legal, and pharmaceutical sectors, with unpatched public Exchange servers and ProxyShell cited as a likely initial access path in some cases.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
21 events from the most recent confirmed update back to the earliest known activity.
The April 11, 2023 IcedID installer downloaded a gzip payload, created persistence via a scheduled task, and stored a DLL plus license.dat under AppData. The infected host then communicated with IcedID command-and-control domains villageskaier[.]com and deadwinston[.]com over HTTPS.
On April 11, 2023, researchers observed an IcedID infection chain delivered through thread-hijacked emails with a PDF attachment. The PDF linked to a redirector that led to a Firebase-hosted password-protected ZIP containing a digitally signed EXE installer.
The August 11, 2022 TA551 IcedID infection was followed by DarkVNC and Cobalt Strike activity. The report identified related network communications for both post-compromise tools, though no binaries were saved to disk on the analyzed host.
On August 11, 2022, Monster Libra/TA551/Shathak distributed IcedID through malicious Word documents requiring macros. The infection chain downloaded an installer DLL and a gzip payload that created persistent IcedID components.
In 2022-03, Fortinet reported a spearphishing campaign targeting a fuel company in Kyiv, Ukraine, with a spoofed invoice email carrying a ZIP archive that unpacked an ISO containing an LNK and malicious DLL. The LNK launched regsvr32 to execute main.dll, which installed IcedID, performed host and domain reconnaissance, contacted multiple C2 servers, and established persistence as Arur.exe in the temp directory.
During analysis of the March 2022 campaign, researchers found many originating Exchange servers appeared unpatched and publicly exposed. They assessed ProxyShell as a plausible vector used to compromise those servers and send the phishing emails.
In mid-March 2022, Intezer observed a phishing campaign delivering IcedID through hijacked email conversations sent from compromised Microsoft Exchange accounts. The campaign used password-protected ZIP archives containing ISO files with an LNK and DLL, and beaconed to yourgroceries[.]top.
In January 2022, attackers sent a stolen email conversation using a different FROM address pattern as part of an IcedID phishing operation. Intezer later linked this to the same broader conversation-hijacking activity.
Beginning around October 20, 2020, TA551 changed the URL structures generated by its malicious macros. The report notes this as part of the campaign's evolving delivery tradecraft.
Starting July 14, 2020, observed TA551 waves delivered only IcedID as the primary payload. Unit 42 also characterized the broader shift as occurring after mid-July 2020.
A GitHub repository began tracking TA551 attack waves starting July 6, 2020. The repository recorded daily waves with hashes, filenames, and URLs.
On April 28, 2020, TA551 conducted an English-language campaign delivering Valak. This reflected the group's continued use of malspam to distribute different malware families before later shifting to IcedID.
On March 26, 2020, TA551 targeted a German-speaking recipient and delivered ZLoader instead of Ursnif. The macro retrieved a ZLoader DLL from a remote URL.
On December 19, 2019, a host infected with Ursnif through TA551 was also infected with IcedID and Valak as follow-on malware. This showed TA551-associated activity leading to multi-malware compromise.
On December 17, 2019, TA551 targeted a Japanese-speaking recipient with Ursnif malspam. The macro-based lure downloaded an EXE from attacker-controlled infrastructure.
On October 30, 2019, TA551 ran a German-language malspam wave delivering Ursnif. The infection chain again relied on a macro-enabled Word document that fetched an EXE installer.
On April 2, 2019, TA551 delivered Ursnif to an Italian-speaking target via a macro-enabled Word document. The document's macro retrieved an EXE payload from attacker infrastructure.
On February 4, 2019, TA551 sent an English-targeted malspam campaign delivering Ursnif using a macro-enabled Word document. The macro downloaded an EXE installer from a remote URL.
The references state that IBM X-Force originally reported or discovered IcedID as a banking trojan. It was initially described as targeting banks and other financial or commerce-related organizations.
Recent lab execution of IcedID samples showed BackConnect traffic to 45.61.137[.]159 and 193.149.176[.]100 over TCP port 443. The report states this was a new port for IcedID BackConnect traffic, which had previously used TCP port 8080.
Researchers observed a new IcedID phishing campaign that abused Google Cloud Storage and Google Firebase links to deliver a ZIP archive containing an ISO payload. The infection chain used cmd.exe, isoburn.exe, and regsvr32.exe, and the infected host contacted command-and-control domains including bredofenction[.]com.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
intezer.com
Open sourcedshield.org
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourcefortinet.com
Open sourcesplunk.com
Open sourceunit42.paloaltonetworks.com
Open sourcesecurityintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.