ICE IX emerged as an early banking Trojan built from the leaked ZeuS source code, giving cybercriminals a ready-made platform for credential theft and botnet operations. Sold on underground forums for about $1,800, the malware used HTTP-based command-and-control through a web panel and targeted online banking sessions with browser hooking, web injects, and form grabbing. Reporting tied the threat to theft involving Amazon EC2 data, while researchers warned that the ZeuS source leak would accelerate the creation of similar follow-on crimeware families.
Technical analysis showed ICE IX largely reused ZeuS tradecraft rather than introducing major new capabilities. The malware employed RC4-protected communications, fake Google traffic to blend in, Windows registry persistence, and a self-deleting dropper, while also stealing credentials from browsers, FTP and mail clients, cookies, Flash .sol files, and certificates. Researchers found support for backconnect access, SOCKS proxying, VNC, screenshot capture, and certificate deletion, but concluded that many of the product's advertised enhancements—such as tracker resistance and stronger evasion—were overstated, amounting mostly to minor code changes and repackaging of existing ZeuS functionality.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Virus Bulletin documented ICE IX as a Zeus-descended banking bot with HTTP-based C2, RC4-obfuscated communications, web injects, form grabbing, credential theft, and support for backconnect, SOCKS, VNC, and screenshots. The analysis covered versions up to 1.2.0 and detailed how the malware manipulated banking sessions and exfiltrated data.
Analysis of Ice IX samples concluded that the malware was largely a repackaged ZeuS 2.0.8.9 variant with only minor changes, such as re-enabled email credential theft and a modified configuration download method. The researcher found no substantial innovations matching the seller's advertised enhancements.
Jorge Mieres identified a command-and-control server tied to an Ice IX-based botnet, enabling analysis of the malware's implementation and claims.
Securelist said there was evidence associating Ice IX malware activity with theft of data from Amazon Elastic Compute Cloud environments.
Ice IX was advertised for sale as an improved ZeuS-derived banking Trojan, with sellers claiming features such as firewall bypass, proactive protection evasion, and tracker resistance. Pricing cited included $600 for a version with a hardcoded C2 URL and $1,800 for one without it.
Securelist reported that Ice IX had been seen in active use since the beginning of the year. The malware was described as browser-hooking crimeware built to steal banking information.
The ZeuS 2.0.8.9 source code was made public in May, creating the basis for later ZeuS-derived crimeware such as Ice IX.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourcesecurelist.com
Open sourcevirusbulletin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.