Elastic Security Labs documented how to unpack ICEDID’s fake-GZip variant, a credential- and banking-information-stealing malware family that uses custom file formats and encryption to impede analysis. The examined sample contained an encrypted configuration, core binary, and persistence loader; recovered configuration data identified alishaskainz[.]com and villageskaier[.]com as C2 domains and /news/ as the beacon URI. The workflow reconstructs ICEDID custom PE files, including x64 and x86 browser-hook payloads, for static analysis; execution should be limited to isolated environments.
Separately, Malpedia published an autogenerated YARA signature for Windows DarkVNC. The rule evaluates ten byte-pattern sequences and matches files below 606,208 bytes when at least seven patterns are present, providing a detection option for the remote-access malware family. The reference does not attribute DarkVNC to a specific incident, campaign, or threat actor.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
ICEDID became more prevalent following Emotet's temporary disruption in early 2021. ICEDID has also been linked to distribution of DarkVNC and Cobalt Strike.
IBM X-Force researchers discovered the ICEDID malware family, which is used to steal login credentials, banking information, and other personal data.
A YARA rule named win_darkvnc_auto was autogenerated by yara-signator v0.6.0 to detect the win.darkvnc malware family. The rule requires at least seven of ten byte-pattern sequences to match in files smaller than 606,208 bytes.
Elastic Security Labs released tooling using the nightMARE module to extract and decrypt ICEDID fake-GZip components and rebuild its custom PE payloads. Its analysis identified an examined sample's C2 domains as alishaskainz[.]com and villageskaier[.]com, with /news/ used for beaconing.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.