Dridex, also known as Bugat v5, is a modular Windows banking trojan derived from the earlier Bugat and Cridex families. Associated with Evil Corp, also known as Indrik Spider, it has also been distributed through TA505 campaigns and the Necurs spam botnet. Its principal targets include financial institutions and online-banking customers, although its use as an initial-access and malware-delivery tool extends to enterprises and government organizations.
Dridex monitors browser activity for access to online-banking services and uses API hooking, browser manipulation, and keylogging to capture login credentials. It can capture screenshots, encrypt collected information, and transmit it through peer-to-peer infrastructure. Its modular architecture supports downloading additional malware, incorporating infected systems into a botnet, and deleting files. Peer-to-peer communications and multiple layers of proxy servers provide infrastructure redundancy and conceal backend nodes. Dridex campaigns have used executable packing and DLL search-order hijacking involving legitimate Windows applications to evade detection. Samples have also used application compatibility databases to bypass User Account Control.
Distribution commonly relies on high-volume phishing and spam emails with business-themed lures, including invoices, orders, and payment notices. Attachments or linked archives contain malicious Office documents, scripts, or downloaders; document macros retrieve or extract executable payloads after recipients enable content. Campaigns have also exploited CVE-2017-0199 in malicious Office documents. Beyond banking fraud, Dridex provides an entry point for subsequent compromise and ransomware deployment, notably in attack chains involving BitPaymer. Operators have used it to deliver additional tools that enable pivoting through victim networks. The modified variant DoppelDridex has been distributed through malicious Excel 4.0 macro attachments with payloads staged on Slack and Discord content-delivery infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recent versions of Dridex exploit vulnerability CVE-2017-0199, which allows remote execution of code. This vulnerability is specific to Microsoft Office and WordPad. Microsoft released a patch in 2017.
Similar to techniques utilized by Dridex and Locky in mid-2017, the PDF contained an embedded RTF file which contains an embedded remote object that attacks CVE-2017-8579.
CVE-2012-0158 Vulnerable Products: Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Associated Malware: Dridex Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-0199 ... Associated Malware: FINSPY, LATENTBOT, Dridex; CVE-2012-0158 ... Associated Malware: Dridex
Threat actors now exploit the critical Apache Log4j vulnerability named Log4Shell to infect vulnerable devices with the notorious Dridex banking trojan or Meterpreter.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dridex is known to be developed and distributed by EvilCorp (aka Ta505).
“Prior to this threat, Storm-0324 had the following range of payload distribution: ... Dridex.”
Dridex is known to be developed and distributed by EvilCorp (aka Ta505).
A modified version of the banking trojan Dridex – named DoppelDridex – is being delivered via payloads staged on Slack and Discord CDNs.
Typically, this group varies its payloads which appear to be targeted by region – for example, in 2021, all TA544 Ursnif campaigns have specifically targeted Italian organizations while Dridex payloads associated with this threat actor do not have specific geographic targeting.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
leveraging attachments with the Excel 4.0 sheet-style macros to fetch the initial payload
The vulnerability allows Rich Text Format (RTF) documents to run scripts when opened.
The vulnerability allows Rich Text Format (RTF) documents to run scripts when opened.
To disguise the source of malicious traffic, adversaries may chain together multiple proxies.
1,003 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking trojan identified as a payload distributed through Necurs.
Listed as a payload historically distributed by Storm-0324. Its capabilities are not discussed in this reference.
Mentioned as another notable banking Trojan used by attackers to steal credentials and financial information.
A banking trojan associated in the article with Evil Corp and financially motivated cyberattacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.