Dridex is a modular Windows banking trojan and malware delivery platform that emerged in the early 2010s and became one of the most prevalent financial malware families. It is widely described as an evolution of earlier Bugat and Cridex codebases and has long been associated with large-scale financially motivated operations, particularly those linked in industry reporting to Evil Corp and, in some reporting, TA505. Although originally focused on theft of online banking credentials, Dridex evolved into a broader intrusion-enablement tool used to establish footholds, maintain access, and deliver additional malware, including ransomware such as BitPaymer and activity associated with DoppelPaymer intrusions.
Dridex has primarily targeted Microsoft Windows systems and has been especially active against financial institutions and their customers, with a concentration of attacks against English-speaking countries. Common delivery has relied on phishing and malspam campaigns using business-themed lures and malicious attachments, often compressed in archives and frequently requiring user interaction with macro-enabled documents. More recent activity has also included exploitation of Microsoft Office vulnerabilities such as CVE-2017-0199 and associations with older Office exploit chains including CVE-2012-0158. Dridex has additionally been observed delivered by other malware distribution ecosystems, including Emotet and SocGholish, reflecting its role within broader cybercriminal access and payload-sharing relationships.
Functionally, Dridex is modular and supports credential theft through browser injection and API-hooking techniques, keylogging, screenshot capture, and encrypted exfiltration of stolen data. It can detect visits to online banking portals and inject malicious content into browser sessions to harvest credentials and facilitate fraud. Reported downstream criminal uses of stolen data include fraudulent transfers, account abuse, business email compromise, and money mule operations. Dridex also supports peer-to-peer communications and botnet-style operation, and variants have included components for persistence and broader post-compromise activity.
Operationally, Dridex has used multiple Windows-native and evasive techniques. Reported behaviors include abuse of regsvr32 for code execution, DLL side-loading through legitimate executables, anti-debugging via OutputDebugStringW, and encrypted communications using RC4. Its role has expanded beyond banking fraud into initial access and malware staging for higher-impact intrusions, including ransomware deployment. This evolution made Dridex a significant bridge between classic banking trojan activity and modern enterprise-targeted cybercrime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Similar to techniques utilized by Dridex and Locky in mid-2017, the PDF contained an embedded RTF file which contains an embedded remote object that attacks CVE-2017-8579.
CVE-2017-0199 Vulnerable Products: Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016, Vista SP2, Server 2008 SP2, Windows 7 SP1, Windows 8.1 Associated Malware: FINSPY, LATENTBOT, Dridex Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-0199 ... Associated Malware: FINSPY, LATENTBOT, Dridex; CVE-2012-0158 ... Associated Malware: Dridex
CVE-2012-0158 Vulnerable Products: Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Associated Malware: Dridex Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-0199 ... Associated Malware: FINSPY, LATENTBOT, Dridex; CVE-2012-0158 ... Associated Malware: Dridex
Threat actors now exploit the critical Apache Log4j vulnerability named Log4Shell to infect vulnerable devices with the notorious Dridex banking trojan or Meterpreter.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
https://cyberintelmag.com/malware-viruses/dridex-malware-downloader-connected-to-entropy-ransomware/
Treasury and CISA are providing this report to inform the sector about the Dridex malware and variants.
Typically, this group varies its payloads which appear to be targeted by region – for example, in 2021, all TA544 Ursnif campaigns have specifically targeted Italian organizations while Dridex payloads associated with this threat actor do not have specific geographic targeting.
The emails contained links to download Microsoft Excel documents containing macros that, when enabled, downloaded the Dridex malware designed to steal banking and other personal information.
Dridex, apparu en juin 2014, est la cinquième variante du code malveillant Bugat actif de 2010 à 2013, agrémenté de particularités propres à GameOverZeuS. Sa fonctionnalité première est celle d’un stealer, c’est-à-dire le vol de codes d’accès de banque en ligne.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
SocGholish is an advanced delivery framework used in drive-by-download and watering hole attacks.
the Bugat malware allowed computer intruders to hijack a computer session and present a fake online banking webpage to trick a user into entering personal and financial information.
According to U.S. Government technical analysis, malicious cyber actors most often exploited vulnerabilities in Microsoft’s Object Linking and Embedding (OLE) technology. OLE allows documents to contain embedded content from other applications such as spreadsheets.
In other cases, macros launch scripts that extract executables imbedded in the document as opposed to downloading the payload.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
The compressed files can include extensible markup language (.xml), Microsoft Office (.doc, .xls), Visual Basic (.vbs), JavaScript (.jar), or portable document format (.pdf) files. | Many of the files, rather than containing the actual malware, contain hidden or obfuscated macros.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
U.S. Government reporting has identified the top 10 most exploited vulnerabilities by state, nonstate, and unattributed cyber actors from 2016 to 2019 as follows: CVE-2017-11882, CVE-2017-0199, CVE-2017-5638, CVE-2012-0158, CVE-2019-0604, CVE-2017-0143, CVE-2018-4878, CVE-2017-8759, CVE-2015-1641, and CVE-2018-7600.
Many of the files, rather than containing the actual malware, contain hidden or obfuscated macros.
In other cases, macros launch scripts that extract executables imbedded in the document as opposed to downloading the payload.
AppleSeed can call regsvr32.exe for execution. APT19 used Regsvr32 to bypass application control techniques. APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory.
Bugat malware was allegedly designed to automate the theft of confidential personal and financial information, such as online banking credentials, and facilitated the theft of confidential personal and financial information by a number of methods.
inject malware or keylogging software, via API hooking, to steal customer login information
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks...
Bugat malware was allegedly designed to automate the theft of confidential personal and financial information, such as online banking credentials, and facilitated the theft of confidential personal and financial information by a number of methods.
inject malware or keylogging software, via API hooking, to steal customer login information
inject malware or keylogging software, via API hooking, to steal customer login information
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
Dridex has had a longer evolutionary journey than most malwares and has survived through the years by obfuscating its main command-and-control (C&C) servers through proxies.
1,002 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking trojan family whose C2 infrastructure is tracked by Abuse.ch Feodo Tracker.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
The malware strain is linked to the Russian cyber criminal group Evil Corp, the group behind the Zeus and Dridex malware and associated with several large-scale ransomware and money laundering operations.
The malware is attributed to Evil Corp, the Russian cybercriminal group previously responsible for Zeus and Dridex, and associated with numerous ransomware and money-laundering operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.