IcedID, also known as BokBot, is a modular Windows banking trojan first identified in 2017 by IBM X-Force. Originally associated with theft of login credentials, banking information, and other personal information, it evolved into a loader and initial-access platform supporting financially motivated intrusions and ransomware operations. Its modules support browser-traffic interception, credential capture, browser-cookie theft, command execution, shellcode injection, backconnect functionality, and system and network discovery. Analyzed variants also provide reverse-shell and VNC capabilities.
IcedID is commonly distributed through phishing and malicious email attachments, including Microsoft Office documents and nested archives containing disk images and malicious Windows shortcuts. Campaigns have also used compiled HTML/HTA polyglot files to execute scripts and retrieve the payload. Other malware families, including Emotet, Bazar, Raspberry Robin, and Latrodectus, have delivered IcedID to already compromised systems.
Its multistage architecture separates loaders from an encrypted core payload and can retrieve additional components from command-and-control infrastructure. IcedID uses custom executable formats, packing, encrypted configurations, and memory-resident loading to hinder analysis and detection. Documented behaviors include process hollowing, virtualization and anti-analysis checks, and persistence through scheduled tasks or Windows Registry autorun mechanisms. It collects host identifiers and enumerates accounts, processes, security software, domain relationships, network configuration, and shared resources. Analyzed variants use TLS certificate pinning to validate command-and-control servers and support encrypted data exfiltration.
IcedID has deployed secondary tools including Cobalt Strike and DarkVNC, enabling further post-compromise activity. It has supplied access used in Conti ransomware attacks and has been used as a loader by Black Basta. Distributors include TA578 and Storm-0324, while Wizard Spider has used phishing chains that deliver it. IcedID infrastructure was among the targets of Operation Endgame in May 2024.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Kevin Beaumont reported on this conversation hijacking technique back in November 2021 being used to distribute Qakbot. Through the investigation, he confirmed that the Microsoft Exchange servers where the emails originated from had evidence of being exploited by ProxyShell... The majority of the originating Exchange servers we have observed appear to also be unpatched and publicly exposed, making the ProxyShell vector a good theory.
In November 2021, a Trend Micro report described a wave of attacks using ProxyShell and ProxyLogon vulnerabilities in exposed Microsoft Exchange servers to hijack internal email reply-chains and spread malware-laced documents. | The distribution of the IcedID malware has seen a spike recently due to a new campaign that hijacks existing email conversation threads and injects malicious payloads that are hard to spot. IcedID is a modular banking trojan first spotted back in 2017, used mainly to deploy second-stage malware such as other loaders or ransomware.
the seller offered two types of weaponized Microsoft Office documents (maldocs) to users: one that exploits a known vulnerability in Microsoft Office (CVE-2017-8570) and another that uses a malicious macro.
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
31 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
IcedID, also known as BokBot, is a malware family that first appeared in 2017 as a banking trojan and later became a tool for selling initial access to ransomware affiliates.
IcedID has been delivered via phishing e-mails with malicious attachments.
“Prior to this threat, Storm-0324 had the following range of payload distribution: ... IcedID.”
“IcedID:” Loader malware used for command-and-control (C2) and delivering advanced malware like ransomware to compromised systems.
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.
"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"
32 distinct techniques documented for this family, organized by ATT&CK tactic.
1,271 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Originally stole financial information and subsequently became an initial-access tool for ransomware operations, including Conti. Targeted by Operation Endgame in May 2024.
Infostealer distributed through a nested attachment chain designed to evade detection: ZIP archive, ISO disk image, and CHM file that is handled by mshta to download the primary payload.
Infostealer distributed through a nested polyglot attachment chain: ZIP archive to ISO image to a CHM file that is also processed as an mshta application, which downloads the primary payload.
Listed as a payload historically distributed by Storm-0324. The article provides no further description of its functionality or role.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.