Dridex emerged from the earlier Cridex banking malware lineage and developed into a long-running, modular botnet used to steal online banking credentials through web injection, redirection, and interception. Reporting ties the malware’s evolution to techniques associated with GameOverZeuS, with major changes over time in configuration formats, command-and-control communications, encryption, and botnet architecture, including peer-to-peer proxying and stronger loader authorization. The malware primarily targeted European victims, especially in the UK, Germany, and France, while using IP-based geo-filtering to avoid Russia.
Open-source reporting and CERT-FR attribute Dridex’s development and operation to Evil Corp, describing an affiliate model in which separate operators managed botnet IDs, infection vectors, and regional targeting. Dridex was distributed through spam and phishing campaigns, ZIP-attached executables, exploit kits such as Blackhole, Spelevo, and Fallout, and secondary payload chains involving Emotet, Gozi ISFB, and FakeUpdates. Beyond banking theft, Dridex supported modules for VNC access, SOCKS proxying, credential theft, spam delivery, and email theft, and was later used for reconnaissance and follow-on ransomware deployment including BitPaymer, while related operators used DoppelDridex and DoppelPaymer; CERT-FR also published associated indicators of compromise for hunting and detection, while cautioning that infrastructure contact alone does not confirm compromise.

Pull IOCs and campaign context straight into your stack.
20 events from the most recent confirmed update back to the earliest known activity.
Treasury, FinCEN, and CISA issued an alert to the financial services sector on Dridex malware, describing its tactics, links to fraud and ransomware activity, and sharing newly reported indicators of compromise derived from private-sector reporting to FinCEN. The alert also noted industry attribution of related campaigns to Evil Corp or TA505.
CERT-FR reports that on December 5, 2019, a joint U.S. and U.K. action identified nine members of Evil Corp and imposed sanctions related to Dridex activity.
CERT-FR states that Dridex was the first known malware to implement the AtomBombing code injection technique in February 2017.
CERT-FR says Dridex campaigns adopted the Microsoft Word zero-day CVE-2017-0199 during the transition from version 3 to version 4 in early 2017.
Securelist reports that the fourth version of Dridex was detected in early 2017, abandoning XML in configuration files and packets and returning to binary formats with stricter loader authorization.
In 2016, the Dridex loader became more complex, its encryption methods changed, and operators introduced a binary loader protocol.
Securelist states that in October 2015, Dridex networks 120, 200, and 220 returned online and new networks 121, 122, 123, 301, 302, and 303 were added.
Securelist reports that in early September 2015, Dridex networks 120, 200, and 220 went offline following the 2015 disruption.
CERT-FR identifies Aleksandr Ghinkul, also known as Smilex, as arrested in Cyprus in August 2015 and extradited to the United States for his role in Dridex operations; Securelist also notes that a Dridex network administrator was arrested on August 28, 2015.
After the 2015 disruption, Dridex operators introduced geo-filtering by adding an IP field to command requests so infrastructure could identify a peer's country and reject non-target regions.
CERT-FR says Dridex's peak infection period occurred in 2015 and 2016, with the United Kingdom, Italy, and France among the principal victim countries in 2015.
By early 2015, Dridex had implemented a peer-to-peer network in which supernodes relayed requests to command servers, and its communications with command infrastructure were encrypted.
CERT-FR reports that Dridex adopted digital signature spoofing and a peer-to-peer protocol in November 2014.
Securelist says that soon after the Gameover Zeus takedown, the zero version of Cridex stopped working and Dridex version 1.100 appeared on June 22, 2014, with configuration files that included JavaScript redirect behavior characteristic of Dridex.
CERT-FR states that Dridex first appeared in June 2014 as the fifth variant of the Bugat malware family and incorporated characteristics associated with GameOverZeuS.
Securelist notes that Operation Tovar took down Gameover Zeus in June 2014, a disruption that preceded a major shift in Dridex development.
A Contagio post documented Cridex as a financial trojan distributed through spam emails with ZIP-attached executables and through the Blackhole exploit kit, using lures themed around shipping notices, Groupon, and HP scans.
In 2012, a significantly modified Cridex variant was released that dropped USB infection functionality and replaced binary configuration and packet formats with XML.
Securelist states that Dridex first appeared as an independent malware program under the name Cridex around September 2011, with early samples supporting dynamic configuration, web injections, and USB infection.
CERT-FR published a set of open-source technical indicators associated with Dridex for compromise hunting and detection, while warning that contact with listed infrastructure alone does not prove compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 85 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourceus-cert.cisa.gov
Open sourcecert.ssi.gouv.fr
Open sourcecontagiodump.blogspot.com
Open sourcecert.ssi.gouv.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.