Researchers and security organizations reported that IcedID campaigns used phishing emails with invoice-themed lures, compromised business email accounts, and malicious Microsoft Office attachments to infect victims. One campaign sent password-protected ZIP files containing Word documents with heavily obfuscated macros, while another relied on Excel xls and xlsm files using Excel 4.0 macros. In both cases, victims were prompted to enable macros, allowing the documents to retrieve second-stage malware from compromised or attacker-controlled infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Between January 1 and March 31, 2021, Uptycs observed more than 15,000 HTTP requests tied to over 4,000 similar malicious documents in an IcedID-focused campaign. It reported that 93% of the malicious Office files in the cluster were Excel .xls or .xlsm spreadsheets delivered via email.
In July 2020, researchers observed an IcedID phishing campaign in which attackers used compromised business email accounts to send invoice-themed lures to existing customers. The campaign used password-protected ZIP files and malicious Word documents with macros to improve delivery and evade detection.
The Center for Internet Security published a security primer on IcedID, providing background on the malware family.
Uptycs reported that second-stage payloads in the broader campaign were disguised with fake extensions such as .dat, .jpg, and .gif, and included both IcedID and Qakbot. The report also assessed that IcedID was filling the gap left by Emotet's disruption and moving toward a malware-as-a-service model.
Uptycs analyzed malicious Excel documents, including a sample named "Claim_331903057_03292021.xlsm," that used Excel 4.0 macros and anti-analysis tricks to download DLL payloads disguised as .dat files. The payloads were executed with rundll32, after which the IcedID loader collected victim system information and sent it to command-and-control servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.