Dridex

MITRE ATT&CK: S0384 View on attack.mitre.org

Aliases: Bugat v5, Dridex

First seen
2014-01-01 00:00:00
Malware type
trojan, credential-stealer, botnet
Family
Malware family
Operating systems
windows
Related IoCs
1727 (1552 malicious)
Last IoC activity
2026-09-01 17:24:28
Profile updated
2026-07-07 12:41:31

Targeted industries: financial-services

Targeted regions: country_code:us country_code:gb country_code:de

Context

Dridex is a prolific banking Trojan that first appeared in 2014. By December 2019, the US Treasury estimated Dridex had infected computers in hundreds of banks and financial institutions in over 40 countries, leading to more than $100 million in theft. Dridex was created from the source code of the Bugat banking Trojan (also known as Cridex).

Recent IoC activity

1,552 malicious indicators in Maltiverse are attributed to Dridex (S0384). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname serverconnect.se 2026-09-02 1
IP address 46.101.142.214 2026-09-01 5
file sample subscription06679735.xlsb 2026-09-01 1
file sample e7455dd312ece91519ca3ad74ffac3e35872bacd181f6125c31cf940f2dee501 2026-08-30 1
file sample a21a285ce9482d0a0a45f4f33063c608.exe 2026-08-29 1
file sample 025dc58d72cfc2f41ffd21649ea2f374.dll 2026-08-29 1
file sample cdc6fdc6cfa18d26713eba66ebe9e3885bea2d8e48f049293706de870126743b 2026-08-29 1
file sample 496636ca904c6d802faa632d5857f3c330219d8d1f1edae703ca075bf35b3187 2026-08-28 1
file sample abadcd128b404c4966990d6664163526f2cb49d7ce235eca9f5c7f1fcb545b41 2026-08-28 1
file sample nsetldk.dll 2026-08-27 1
file sample 547e81ee477ae73f30b4435bfa093d48082a0edfa3186a0e4af2eeab60b8d8e0 2026-08-24 3
file sample 5d91f693ae62123730e9b2df722f0653 2026-08-24 2
file sample c8ee1f4c03948d9bfc7f15f2c3915b20 2026-08-24 2
file sample 0dfa8d935cf1a5c91b02ade726c48fd472da75c3ceb0ce61a5c14d953495195a 2026-08-24 1
file sample 48076ad58115ffcf2623aaa0338560ca1438b7b9f2d492ed574cacdefa2878d6 2026-08-24 1
file sample 17b12f609806dd89d497045704ff68259770bcf54bd208a992866f050516e9c4 2026-08-24 1
file sample 7a6bf9f70ee8fcab803f3f2c52ada9f4a0f3673d3ee0793b81cd83ede37e8243 2026-08-24 1
file sample 7b314e9074346686ed1ca3707bc454c8a688040c3f182e83e8e34252a79595c8 2026-08-24 1
file sample 403aae0f2e25fd1c521e02be13b08dd11297e652bb46c324bf0f74a307528859 2026-08-24 1
file sample 8b3a2594d8cd199c38be423a83293220454616ce0eca9acc404b86affce0b8db 2026-08-24 1

Detection coverage

  • 3 YARA rules
  • 351 Sigma rules

Malware & tools used

  • Symmetric Cryptography (attack-pattern)
  • DLL (attack-pattern)
  • Remote Access Tools (attack-pattern)
  • Native API (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Browser Session Hijacking (attack-pattern)
  • Software Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Proxy (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Malicious File (attack-pattern)

Used by threat actors

Detection rules

  • SIGNATURE_BASE_Crime_Win32_Dridex_Socks5_Mod (yara-rule)
  • CAPE_Dridexv4 (yara-rule)
  • CAPE_Dridexloader_1 (yara-rule)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • secureworks.com — Gold Heron (report)
  • proofpoint.com — Holiday Lull Not So Much (report)
  • CrowdStrike — Report2021Gtr (report)
  • krebsonsecurity.com — Inside Evil Corp A 100M Cybercrime Menace (report)
  • Wikipedia — Maksim Yakubets (report)
  • secureworks.com — Gold Drake (report)
  • secureworks.com — Dridex Bugat V5 Botnet Takeover Operation (report)
  • secureworks.com — Evolution Of The Gold Evergreen Threat Group (report)
  • Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
  • blogs.blackberry.com — Blackberry Prevents Threat Actor Group Ta575 And Dridex Malware (report)
  • home.treasury.gov — Sm845 (report)
  • cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • CISA — Aa20 345A (report)
  • web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • pwc.co.uk — What Is Behind Ransomware Attacks Increase (report)
  • ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
  • CrowdStrike — Doppelpaymer Ransomware And Dridex 2 (report)
  • killingthebear.jorgetesta.tech — Evil Corp (report)
  • medium.com — Operation Synctrek E5013Df8D167 (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
  • Mandiant — Unc2165 Shifts To Evade Sanctions (report)
  • secureworks.com — Gold Heron (report)

External references