Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
ipconfig for system network configuration discovery (T1016).
arp -a for both remote system discovery (T1018)... nltest /dclist for the remote discovery of the domain controllers (T1018). ping for network connectivity tests to remote systems (T1018).
Another quite common technique was the inspection of Outlook... On one singular instance, we observed the actor expressing interests in Outlook’s rules.
IcedID itself is composed of multiple modules, one of which is a poorly documented VNC backdoor... acting as a cross-platform remote desktop solution... These backdoors are typically activated during the final initial-access stages to initiate hands-on-keyboard activity.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in an external resource title about VNC backdoors.
Keyhole is an HDESK VNC backdoor variant associated with IcedID. It adds interface changes such as grayscale mode, refreshed hidden desktop menus, and additional options including PowerShell and Desktop for interactive operator activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.