Researchers and incident responders detailed how IcedID (also known as BokBot) evolved from a banking trojan into a broader access malware platform that supports BackConnect command-and-control, SOCKS proxying, VNC/DarkVNC, reverse shell access, file management, and follow-on payload delivery including Cobalt Strike. Protocol analysis showed a compact BackConnect packet format with changing authentication values and commands that can spawn secondary sessions for remote control and proxy activity, while malware reverse engineering documented persistence through scheduled tasks, injected svchost.exe processes, encrypted configuration retrieval over HTTPS, browser traffic interception, and credential theft through local proxy and web-injection components.
Network telemetry and case studies showed operators using this capability for post-compromise reconnaissance, Active Directory enumeration, disk listing, internal scanning, proxied outbound TLS traffic, and likely spam operations over TCP/465 and TCP/587. Team Cymru reported that IcedID’s BackConnect ecosystem grew from 11 observed C2 servers in mid-2022 to 34 medium- and high-confidence servers in the first half of 2023, with server lifetimes shrinking from about four weeks to roughly eight days and management infrastructure spanning multiple countries. Separate infection chains tied IcedID delivery to TA551/Shathak malspam and other loaders, with victims receiving password-protected ZIP, ISO, JavaScript, or macro-laden documents that ultimately installed IcedID before attackers deployed remote access tooling and, in some cases, Cobalt Strike as a precursor to broader intrusion activity and possible ransomware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
26 events from the most recent confirmed update back to the earliest known activity.
Team Cymru's Part 2 report documented shorter C2 lifetimes, up to four concurrent active servers, additional management nodes, and suspected use of BackConnect SOCKS for spam-related mail traffic.
The same April 2023 infection progressed to BackConnect traffic over 193.149.176.100:443, where the attacker enumerated hosts in the boogienights.live Active Directory environment and listed disk contents.
During the 19 April 2023 infection, the IcedID installer fetched a gzip-compressed binary from skigimeetroc.com and then began HTTPS command-and-control communications with askamoshopsi.com and skansnekssky.com.
Unit 42 analyzed an IcedID infection whose malicious traffic began on 19 April 2023 at 15:31 UTC on host DESKTOP-SFF9LJF in the boogienights.live Active Directory environment.
Team Cymru identified 20 high-confidence IcedID BackConnect C2 servers since 11 April 2023 by pivoting from management infrastructure.
Team Cymru reported that IcedID actors updated the BackConnect protocol in mid-April 2023, including a notable shift from victim connections over TCP/8080 to TCP/443.
Elastic Security Labs published research on a recent ICEDID GZip variant, describing its multi-stage execution chain, persistence, anti-analysis features, and support for VNC, reverse shell, and browser proxying.
Team Cymru identified 34 medium- and high-confidence IcedID BackConnect C2 servers since 23 January 2023, showing a substantial expansion of the ecosystem in 2023.
Team Cymru published research tying 11 BackConnect C2 servers to two long-lived management nodes and describing operator tradecraft, weekday management patterns, and likely OpenVPN and WireGuard usage.
Team Cymru observed a spike in Tor-related activity around 3 November 2022 on a VNC management node, coinciding with renewed Emotet activity that dropped a new version of IcedID.
A full packet capture from 2022-10-31 showed GzipLoader delivering IcedID, which then established BackConnect communications and gave the attacker reverse VNC access to the victim desktop. The attacker attempted to buy an iPhone 14 with stolen payment details, then conducted reconnaissance, used the file manager function, uploaded P2.dll, and launched Cobalt Strike beaconing to clouditsoft[.]com:8008.
Erik Hjelmvik published an analysis of the BackConnect protocol, documenting packet structure, command semantics, alternate auth bytes, and attacker use of SOCKS, VNC, reverse shell, and file manager functions.
A separate IcedID infection capture from 2022-10-04 showed BackConnect traffic to 51.89.201.236:8080 using the new auth value and a command that initiated apparent reverse shell activity.
Researchers assessed that the IcedID BackConnect authentication value changed from 0x974f014a to 0x08088b1f between 30 August 2022 and 22 September 2022, indicating protocol evolution.
A TA551 campaign observed on 2022-07-26 targeted Italy with a ZIP-to-ISO infection chain that installed IcedID, followed by DarkVNC activity and retrieval of a Cobalt Strike DLL.
Team Cymru identified 11 distinct IcedID BackConnect C2 servers active since 1 July 2022, establishing the observed start of the 2022 BackConnect infrastructure set.
In Brad Duncan's 2022-06-28 TA578 IcedID pcap, the BackConnect server sent SOCKS and VNC start commands, and the attacker used the infected host to scan internal network ranges and proxy outbound connections.
SANS ISC reported a TA551/Shathak malspam campaign delivering IcedID through a password-protected ZIP containing a macro-enabled Word document that dropped an HTA and installer DLL.
Fortinet published Part III of its IcedID series, detailing child processes used for browser injection, local proxying, WebSocket C2 communications, and registry operations.
Fortinet published Part II of its IcedID analysis, describing the core payload's HTTPS C2 communications, .DAT downloads, scheduled-task persistence, and injected svchost.exe architecture.
Fortinet released Part I of a three-part IcedID analysis covering unpacking, API hooking, and process injection, including how the malware relaunches itself and injects into svchost.exe.
Fox-IT published research assessing that Bokbot was connected to the operators behind the 76service and Neverquest/Vawtrak crimeware ecosystem, citing operational and configuration similarities.
Fox-IT identified early Bokbot samples in its lab in May 2017, marking one of the earliest documented observations of the malware family later known as IcedID.
Elastic Security Labs states that ICEDID was first described in 2017 by IBM X-Force researchers, establishing the malware family's initial public documentation.
A later pcap released on 2022-11-02 contained BackConnect command 0x12, which Netresec determined launches a file manager.
A malware infection analyzed by Netresec began with execution of the malicious JavaScript file StolenImages_Evidence.js, which downloaded an IcedID DLL and later a Cobalt Strike beacon.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
learn.microsoft.com
Open sourcemalware-traffic-analysis.net
Open sourcemalware-traffic-analysis.net
Open sourcenetresec.com
Open sourcefortinet.com
Open sourcefortinet.com
Open sourcefortinet.com
Open sourceblog.fox-it.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.