IcedID, also known as BokBot, is a financially motivated cybercrime operation centered on a banking trojan and post-compromise access malware that has also been used to enable follow-on ransomware activity. The malware has been used to steal sensitive information, including banking credentials, and to provide other criminal actors with access to compromised systems for deployment of additional payloads. U.S. authorities have linked leadership of the operation to Ukrainian national Vyacheslav Penchukov, who pleaded guilty to charges tied to his role in the IcedID group. Reporting has also described commercial relationships between the IcedID operation and other criminal services and access brokers. IcedID functions as both an information stealer and an access platform. Its operators have maintained a BackConnect command-and-control ecosystem used after initial compromise on systems assessed as valuable. Observed infrastructure and protocol behavior indicate support for SOCKS proxying and remote interactive access, including functionality associated with screen sharing or VNC-style control. Researchers have assessed that compromised hosts can be rotated across multiple BackConnect servers over time while remaining infected, and that the malware’s SOCKS capability has likely been used to proxy victim outbound connections to mail infrastructure in support of spam operations. The operation has shown sustained infrastructure management and adaptation. In 2023, researchers observed protocol changes, increased numbers of concurrently active BackConnect servers, and shorter server lifetimes, consistent with active operational maintenance and response to defender disruption. Management and jump-box activity associated with the ecosystem has been observed across multiple countries, and some infrastructure patterns suggest use by both core operators and affiliates. IcedID has been closely associated with the broader e-crime malware ecosystem. It has been linked in reporting and infrastructure analysis with other major crimeware operations including QakBot, TrickBot, Emotet, Bazar, and SystemBC. The malware has also appeared in code-signing certificate collision analysis alongside other malware families, indicating overlap in criminal signing services rather than exclusive infrastructure. Separate reporting has tied IcedID campaigns to malicious LNK-based delivery activity and identified metadata relationships between IcedID-related LNK campaigns and Bumblebee, suggesting operational overlap or shared tooling. The group’s activity is strongly associated with credential theft, post-compromise access monetization, and enabling ransomware deployment by downstream actors. Authorities have stated that the operation infected large numbers of computers and that access obtained through IcedID was used in cyberattacks including ransomware. The actor is best characterized as a mature cybercrime operation focused on financial gain through theft, resale of access, and support for broader criminal intrusion chains.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
56 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cybercrime gang that purchased access to bots from Mario Kart/TA551 for follow-on criminal activity.
Financially motivated cybercrime group associated with the IcedID malware ecosystem; compromises large numbers of systems and monetizes access including via ransomware activity.
Malware operation used to steal sensitive information, including banking credentials, and to provide access to compromised systems for follow-on payloads such as ransomware.
Operating and evolving BackConnect command-and-control infrastructure post-compromise, with likely operator and affiliate access to victim hosts and suspected use of infected victims as SOCKS proxies for spamming operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.