Researchers reported that IcedID (also known as BokBot) continued to evolve from a banking trojan into a multi-stage malware platform widely used to establish initial access for ransomware intrusions. Across observed campaigns, phishing emails delivered password-protected ZIP archives, malicious Word or Excel documents, or zipped JavaScript files that launched HTA scripts and DLL loaders through tools such as rundll32, regsvr32, and mshta.exe. Analysts documented several loader techniques, including disguised DLLs saved with .jpg extensions, registry-stored configuration data derived from victim-specific bot IDs, and even PNG steganography used to hide encrypted shellcode. Later reporting also described PhotoLoader and GzipLoader variants, including a newer GzipLoader build that added dynamic API resolution and XOR-based stacked-string encryption while dropping earlier SSL-pinning behavior, changes that risked breaking older pattern-based detections.
Incident responders and threat researchers linked IcedID infections to financially motivated intrusion clusters that rapidly escalated to MAZE and later EGREGOR ransomware. Mandiant said UNC2198 repeatedly leveraged access originating from the MOUSEISLAND → PHOTOLOADER → ICEDID chain, then deployed tooling including SYSTEMBC, WINDARC, Cobalt Strike BEACON, METERPRETER, KOADIC, and PowerShell EMPIRE for discovery, lateral movement, and privilege escalation, including observed abuse of CVE-2020-0787. In multiple cases, attackers used BloodHound, moved laterally over WinRM and RDP, exfiltrated data with RCLONE, and encrypted victim environments within days. Defenders published YARA rules, unpacking workflows using Qiling, registry- and network-based hunting methods, and configuration extractors to recover domains, campaign IDs, and other indicators from packed IcedID samples.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
OpenAnalysis reported that Proofpoint researchers observed a forked ICEDID variant in February 2023. The fork lacked webinject capability and was used by a small number of threat actors.
Threatray said the earliest sample of the new IcedID GZipLoader variant in its telemetry was dated February 9, 2022, providing the first explicit sample anchor for the updated loader.
Threatray reported that a new IcedID GZipLoader variant began appearing in malware feeds at the beginning of February 2022. The updated loader kept prior functionality while adding anti-analysis changes and removing SSL pinning.
VMware based a hunting and unpacking workflow on IcedID samples seen during April and May 2021, reporting that a YARA rule built around opaque predicate patterns returned many packed IcedID samples with limited false positives.
Deutsche Telekom reported that by 2021 it had observed ransomware deployment following IcedID infections and assessed that more ransomware operators were using IcedID operators' service.
A January 2021 reverse-engineering write-up described ICEID variants that hid encrypted shellcode in PNG files and noted a newer loader variant had changed from RSRC-stored RC4-encrypted code to aplib-compressed modules.
OpenAnalysis, citing Proofpoint, reported that a lite ICEDID variant was observed as a follow-on payload in November Emotet infections. This variant delivered a bot with minimal functionality and did not exfiltrate host data during loader check-in.
Mandiant observed UNC2198 move from deploying MAZE to deploying EGREGOR in engagements during October and November 2020. The shift aligned with broader late-2020 changes in ransomware affiliate activity.
Mandiant created the UNC2414 cluster in October 2020 and attributed three intrusions to it before later merging it into UNC2198.
Mandiant created the UNC2374 cluster in October 2020 after observing BEACON, WINDARC, and SYSTEMBC in an incident at a Managed Defense customer.
Between July and December 2020, Mandiant observed an ICEDID phishing infection chain using MOUSEISLAND and PHOTOLOADER stages. The activity was attributed to UNC2420, which overlaps with TA551/Shathak.
Mandiant observed UNC2198 using access derived from ICEDID infections to deploy MAZE ransomware during July 2020, tying ICEDID initial access directly to ransomware monetization.
Mandiant created the UNC2198 cluster based on a June 2020 intrusion involving ICEDID, BEACON, SYSTEMBC, and WINDARC. In that incident, the actor compromised 32 systems in 26 hours without deploying ransomware.
By late 2020, Mandiant observed a subset of groups that had deployed MAZE ransomware shifting to EGREGOR. The company linked this transition to access obtained through ICEDID infections.
VMware noted that IcedID regained attention in 2019 for using steganography to hide payloads, reflecting an evolution in its delivery and concealment techniques.
Multiple references state that IcedID, also known as BokBot, was first discovered or documented in 2017 as a banking trojan targeting financial information.
VMware published analysis of a common IcedID delivery sequence in which phishing emails with password-protected ZIP archives led to malicious Office documents, a first-stage DLL, and a second-stage DLL plus encrypted payload.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
research.openanalysis.net
Open sourcethreatray.com
Open sourceforensicitguy.github.io
Open sourceblogs.vmware.com
Open sourceblogs.vmware.com
Open sourcetelekom.com
Open sourcefireeye.com
Open sourcetccontre.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.