Dridex
MITRE ATT&CK: S0384 View on attack.mitre.org
Aliases: Bugat v5, Dridex
- First seen
- 2014-01-01 00:00:00
- Malware type
- trojan, credential-stealer, botnet
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1727 (1552 malicious)
- Last IoC activity
- 2026-09-01 17:24:28
- Profile updated
- 2026-07-07 12:41:31
Targeted industries: financial-services
Targeted regions: country_code:us country_code:gb country_code:de
Context
Dridex is a prolific banking Trojan that first appeared in 2014. By December 2019, the US Treasury estimated Dridex had infected computers in hundreds of banks and financial institutions in over 40 countries, leading to more than $100 million in theft. Dridex was created from the source code of the Bugat banking Trojan (also known as Cridex).
Recent IoC activity
1,552 malicious indicators in Maltiverse are attributed to Dridex (S0384). The 20 most recently updated:
Detection coverage
- 3 YARA rules
- 351 Sigma rules
Malware & tools used
- Symmetric Cryptography (attack-pattern)
- DLL (attack-pattern)
- Remote Access Tools (attack-pattern)
- Native API (attack-pattern)
- Scheduled Task (attack-pattern)
- Browser Session Hijacking (attack-pattern)
- Software Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Regsvr32 (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Proxy (attack-pattern)
- System Information Discovery (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Malicious File (attack-pattern)
Used by threat actors
- TA575 (threat-actor)
- Indrik Spider (threat-actor)
- TA505 (threat-actor)
Detection rules
- SIGNATURE_BASE_Crime_Win32_Dridex_Socks5_Mod (yara-rule)
- CAPE_Dridexv4 (yara-rule)
- CAPE_Dridexloader_1 (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- secureworks.com — Gold Heron (report)
- proofpoint.com — Holiday Lull Not So Much (report)
- CrowdStrike — Report2021Gtr (report)
- krebsonsecurity.com — Inside Evil Corp A 100M Cybercrime Menace (report)
- Wikipedia — Maksim Yakubets (report)
- secureworks.com — Gold Drake (report)
- secureworks.com — Dridex Bugat V5 Botnet Takeover Operation (report)
- secureworks.com — Evolution Of The Gold Evergreen Threat Group (report)
- Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
- blogs.blackberry.com — Blackberry Prevents Threat Actor Group Ta575 And Dridex Malware (report)
- home.treasury.gov — Sm845 (report)
- cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- CISA — Aa20 345A (report)
- web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- pwc.co.uk — What Is Behind Ransomware Attacks Increase (report)
- ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
- CrowdStrike — Doppelpaymer Ransomware And Dridex 2 (report)
- killingthebear.jorgetesta.tech — Evil Corp (report)
- medium.com — Operation Synctrek E5013Df8D167 (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
- Mandiant — Unc2165 Shifts To Evade Sanctions (report)
- secureworks.com — Gold Heron (report)