Cridex is a Windows banking Trojan associated with online-banking credential theft and financial fraud. It has been distributed through malicious spam carrying executable payloads inside ZIP attachments and through the Blackhole exploit kit. Email campaigns have used parcel-delivery notifications, promotional offers, and printer or scanner notifications impersonating recognizable businesses to persuade recipients to open malicious attachments.
Cridex is a predecessor of Dridex, which retains portions of code from the earlier Cridex and Bugat Trojans. In 2014, the cybercrime actor Mealybug used Emotet as the loader component of a rewritten Cridex variant designated W32.Cridex.B. This relationship connects Cridex to the early development of Emotet but does not establish that Cridex possessed the broader capabilities subsequently introduced into Emotet or Dridex.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Andre' DiMino posted an excellent analysis of Cridex banking malware... Cridex is a complex financial trojan and is being distributed via spam messages (carrying exe files in zipped attachments) and Blackhole Exploit kit.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
At the time, Mealybug was using Trojan.Emotet as the loader portion of W32.Cridex.B, a rewritten version of the Cridex banking Trojan.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
was able to infect USB media. This ability influenced the name under which the “zero” version of Cridex was detected — Worm.Win32.Cridex.
Cridex is a complex financial trojan and is being distributed via spam messages (carrying exe files in zipped attachments) and Blackhole Exploit kit.
Bugat malware was allegedly designed to automate the theft of confidential personal and financial information, such as online banking credentials, and facilitated the theft of confidential personal and financial information by a number of methods.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Online banking trojan from which Emotet was developed; used for credential theft and man-in-the-browser attacks against online banking users.
Banking trojan for which Emotet acted as the loader portion in earlier Mealybug operations.
A banking trojan/financial malware family distributed via spam campaigns and the Blackhole exploit kit. The samples shown are associated with credential theft/banking fraud behavior and are variously detected as Cridex, Dapato, and related banker/worm classifications by AV vendors.
Mentioned in discussion of whether Dridex was related to Cridex; the report argues they were not created by the same developers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.