Investigators tied IcedID (also known as Bokbot) command-and-control infrastructure to ransomware intrusions in which the malware served as an initial access foothold later used by Sodinokibi/REvil operators. In one documented compromise, a malspam-delivered XLSM macro launched IcedID through WMIC and regsvr32, after which attackers established persistence, deployed Cobalt Strike, moved laterally across the Windows domain, escalated to Domain Administrator, and dumped credentials from LSASS. The intrusion also involved Exchange server pivoting, SMB and PowerShell-based lateral movement, Active Directory discovery with techniques consistent with BloodHound, and additional enumeration using AdFind and ping.
Before encrypting systems, the attackers used Rclone disguised as svchost.exe to exfiltrate data for double extortion, then pushed REvil ransomware from a domain controller with BITSAdmin and executed it with the -smode option to reboot hosts into Safe Mode with Networking, helping disable security and management tools; all domain-joined systems were encrypted in about 4.5 hours. Building on indicators from that case, researchers used passive DNS and infrastructure-pattern analysis to identify a broader IcedID cluster characterized by recurring domain registration and hosting behavior, including Porkbun registrations, later migration to Cloudflare name servers, and shared hosting across IPs such as 206.189.10.247, 161.35.109.168, 143.198.25.214, and 83.97.20.176, ultimately mapping 58 IP addresses and 323 domains believed to support IcedID operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
After filtering for false positives, Silent Push compiled a dataset of 58 IP addresses, 323 domain names, and 402 domain-to-IP combinations assessed as very likely belonging to IcedID infrastructure. Some of these domains had not previously been publicly associated with IcedID.
Using passive DNS pivots from the DFIR Report indicators, Silent Push identified additional clusters of domains and IPs linked to IcedID, including infrastructure on 206.189.10.247, 161.35.109.168, 143.198.25.214, and 83.97.20.176. The analysis highlighted recurring registration, DNS, and hosting patterns across the clusters.
The DFIR Report published an analysis of the intrusion, documenting how IcedID enabled follow-on access that culminated in Sodinokibi/REvil ransomware deployment. The report included IcedID command-and-control indicators such as cikawemoret34[.]space and nomovee[.]website.
IBM X-Force discovered IcedID in 2017. The malware initially operated as a banking trojan before later being used as an initial access tool for ransomware intrusions.
The attackers created a Group Policy Object named "new" to disable Windows Defender, staged the ransomware on a domain controller, and distributed it with BITSAdmin. The Sodinokibi/REvil payload was executed with the "-smode" option to reboot systems into Safe Mode with Networking and encrypt domain-joined systems.
Before ransomware deployment, the attackers used Rclone disguised as svchost.exe to collect and exfiltrate data from network shares. This supported a double-extortion phase prior to encryption.
The operators pivoted first to an Exchange server and then to other systems using SMB, PowerShell beacons, remote services, and RDP. They dumped LSASS credentials and performed discovery with AdFind, ping, and LDAP/BloodHound-style techniques.
Within about 1.5 hours of initial access, the attackers downloaded Cobalt Strike beacons from cloudmetric.online (45.86.163.78) and smalleststores.com (195.189.99.74). These beacons were then used throughout the intrusion with process injection and follow-on operations.
After execution, IcedID beaconed to 161.35.109.168:443 throughout the intrusion and created a scheduled task for persistence. The DFIR Report also identified nomovee[.]website and cikawemoret34[.]space as IcedID command-and-control servers used in the case.
A March intrusion began with malicious spam carrying an XLSM document that required macros and ultimately executed IcedID disguised as a GIF payload. The infection chain used WMIC, regsvr32, and rundll32 to launch the malware.
Multiple suspected IcedID domains switched from registrar parking to Cloudflare name servers and then to shared hosting IPs, with staggered timing suggesting activation shortly before campaigns. Some domains also briefly pointed to 83.97.20.176 or used Russia's Server Space name servers before later migration.
Domains later associated with IcedID infrastructure were registered in February or March, mostly through Porkbun, with at least one through NameSilo. They were initially parked at Porkbun before later DNS and hosting changes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.