Researchers and incident responders detailed multiple IcedID intrusion chains that used phishing, hijacked email threads, contact-form abuse, and compromised mail infrastructure to deliver the malware through deceptive attachments and loaders. Campaigns sent password-protected ZIPs, ISO and LNK chains, macro-enabled Office files, and JavaScript or HTA downloaders, while also abusing legitimate services such as Google Sites and trusted email conversations. Several delivery paths relied on masquerading techniques, including DLLs disguised as .jpg files, fake GZip wrappers, and steganographic payloads hidden in PNG images, with follow-on execution through tools and binaries such as mshta.exe, rundll32, regsvr32.exe, WScript, and PowerShell.
Once executed, IcedID unpacked encrypted configurations and payloads, injected into legitimate processes, established persistence with scheduled tasks, and contacted command-and-control infrastructure including URI paths such as /news/. Technical analyses showed the malware using custom encryption, custom PE formats, RC4-decrypted PNG loaders, anti-analysis checks, and browser-hook or secondary payload components, while incident reporting tied infections to rapid post-compromise activity including Cobalt Strike deployment, credential theft from LSASS, Active Directory reconnaissance, SMB and RDP lateral movement, and use as an access broker for ransomware or espionage operations, including attacks against Ukrainian government entities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs released tooling to automate unpacking and analysis of IcedID's fake GZip variant, including scripts for extracting payloads, decrypting files, rebuilding custom PE files, reading configuration, and loading the core binary. The work analyzed a sample whose decrypted configuration revealed botnet ID 0x3B7D6BA4, URI /news/, and C2 domains alishaskainz.com and villageskaier.com.
Unit 42 described an IcedID infection chain discovered in early November 2022 that delivered Bokbot and used packed stage one and stage two binaries. Researchers later recovered the malware's encrypted configurations from memory.
CERT-UA reported a campaign targeting Ukrainian government agencies with Excel files named "Mobilization Register.xls" that downloaded GzipLoader and then IcedID. CERT-UA attributed the activity with moderate confidence to the UAC-0041 cluster and assessed it was intended for cyber-espionage.
A Trend Micro report from November 2021 described attacks exploiting ProxyShell and ProxyLogon on exposed Microsoft Exchange servers to hijack internal email reply chains and spread malware-laced documents. The activity was believed to involve threat group TR.
Unit 42 cites IcedDecrypt, a public script by Jquinn147 and myrtus0x0 for decrypting IcedID configurations, as having been published in May 2021. The script became a referenced precursor for later configuration extraction work.
The DFIR Report documented a May 2021 intrusion where a malspam-delivered IcedID infection led to Cobalt Strike deployment within 35 minutes, credential theft from LSASS, and lateral movement via SMB and RDP. The actor reached at least one file server but no data exfiltration or ransomware deployment was observed.
SentinelLabs analyzed a May 2021 IcedID phishing campaign in which Word macros appeared benign while extracting reversed Base64-encoded JavaScript from document content. The chain wrote an HTA file, executed it with mshta.exe, downloaded a DLL disguised as a .jpg, and ran it with rundll32.
Microsoft described an IcedID campaign that abused legitimate website contact forms and Google-hosted pages to deliver a malicious ZIP archive containing an obfuscated JavaScript loader. The chain used WScript, PowerShell, rundll32, and also deployed Cobalt Strike for follow-on activity.
Trend Micro reported a spike in IcedID activity in March 2021, with campaigns using hijacked email threads and compressed XLSM attachments containing hidden formulas and macros. The activity continued into April, though detections decreased.
Elastic notes that IcedID grew further after the temporary disruption of Emotet in early 2021. This marks a broader shift in IcedID's prominence in the malware ecosystem.
A researcher published a manual unpacking analysis of an IcedID sample, documenting high-entropy packing, memory allocation behavior, and extraction of a compressed PE payload altered from MZ to M8Z. The process yielded an extracted file identified as dump0.bin.
A GitHub Gist published a Python 3 script to reconstruct an IcedID payload hidden in a PNG file using RC4 decryption and PE rebuilding with LIEF. The script credits @nazywam and @psrok1 and cites prior public IcedID parser research.
IBM X-Force researchers discovered the IcedID malware family in 2017. Multiple references describe it as a banking trojan later used for credential theft and as a loader for additional malware.
Unit 42 replicated the stage-two decryption routine in Python and recovered multiple C2 domains—newscommercde[.]com, spkdeutshnewsupp[.]com, germanysupportspk[.]com, and nrwmarkettoys[.]com—along with the URI path news and the same campaign ID 1139942657.
By tracing the unpacked binary to WinHttpConnect, Unit 42 decrypted the stage-one IcedID configuration and recovered the C2 domain bayernbadabum[.]com and campaign ID 1139942657. This showed how runtime memory analysis could reveal configuration data hidden from static inspection.
Intezer uncovered an ongoing IcedID campaign using hijacked email conversation threads and ZIP attachments containing an ISO with an LNK and DLL. Researchers also found clues suggesting attackers were compromising vulnerable public-facing Microsoft Exchange servers to steal credentials and send phishing emails from trusted infrastructure.
F5 reported recent TA551/Shathak phishing campaigns using COVID-19-themed Word documents with malicious macros to install IcedID. The infection chain downloaded an RC4-encrypted loader hidden inside a PNG file and established persistence with scheduled tasks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourceelastic.co
Open sourceunit42.paloaltonetworks.com
Open sourcebleepingcomputer.com
Open sourcef5.com
Open sourcekienmanowar.wordpress.com
Open sourceattack.mitre.org
Open sourcegist.github.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.