Cridex is a Windows banking trojan associated with online banking fraud and credential theft. It is also referred to as Bugat or Feodo in some reporting and is part of the lineage that preceded and informed later malware such as Dridex and early Emotet variants. Cridex was distributed through spam campaigns using shipping, invoice, discount, and document-themed lures, commonly delivering executables inside compressed attachments, and it was also delivered through the Blackhole exploit kit. Early campaigns focused on financial theft by compromising browser sessions and stealing credentials used for online banking. Cridex is widely characterized as a complex financial trojan and an important predecessor in the evolution of later banking malware families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Andre' DiMino posted an excellent analysis of Cridex banking malware... Cridex is a complex financial trojan and is being distributed via spam messages (carrying exe files in zipped attachments) and Blackhole Exploit kit.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
At the time, Mealybug was using Trojan.Emotet as the loader portion of W32.Cridex.B, a rewritten version of the Cridex banking Trojan.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
was able to infect USB media. This ability influenced the name under which the “zero” version of Cridex was detected — Worm.Win32.Cridex.
Cridex is a complex financial trojan and is being distributed via spam messages (carrying exe files in zipped attachments) and Blackhole Exploit kit.
Bugat malware was allegedly designed to automate the theft of confidential personal and financial information, such as online banking credentials, and facilitated the theft of confidential personal and financial information by a number of methods.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Online banking trojan from which Emotet was developed; used for credential theft and man-in-the-browser attacks against online banking users.
Banking trojan for which Emotet acted as the loader portion in earlier Mealybug operations.
A banking trojan/financial malware family distributed via spam campaigns and the Blackhole exploit kit. The samples shown are associated with credential theft/banking fraud behavior and are variously detected as Cridex, Dapato, and related banker/worm classifications by AV vendors.
Mentioned in discussion of whether Dridex was related to Cridex; the report argues they were not created by the same developers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.