Researchers and security organizations reported that IcedID campaigns used phishing emails with invoice-themed lures, compromised business email accounts, and malicious Microsoft Office attachments to infect victims. One campaign sent password-protected ZIP files containing Word documents with heavily obfuscated macros, while another relied on Excel xls and xlsm files using Excel 4.0 macros. In both cases, victims were prompted to enable macros, allowing the documents to retrieve second-stage malware from compromised or attacker-controlled infrastructure.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Between January 1 and March 31, 2021, Uptycs observed more than 15,000 HTTP requests tied to over 4,000 similar malicious documents in an IcedID-focused campaign. It reported that 93% of the malicious Office files in the cluster were Excel .xls or .xlsm spreadsheets delivered via email.
In July 2020, researchers observed an IcedID phishing campaign in which attackers used compromised business email accounts to send invoice-themed lures to existing customers. The campaign used password-protected ZIP files and malicious Word documents with macros to improve delivery and evade detection.
The Center for Internet Security published a security primer on IcedID, providing background on the malware family.
Uptycs reported that second-stage payloads in the broader campaign were disguised with fake extensions such as .dat, .jpg, and .gif, and included both IcedID and Qakbot. The report also assessed that IcedID was filling the gap left by Emotet's disruption and moving toward a malware-as-a-service model.
Uptycs analyzed malicious Excel documents, including a sample named "Claim_331903057_03292021.xlsm," that used Excel 4.0 macros and anti-analysis tricks to download DLL payloads disguised as .dat files. The payloads were executed with rundll32, after which the IcedID loader collected victim system information and sent it to command-and-control servers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.