IcedID

MITRE ATT&CK: S0483 View on attack.mitre.org

Aliases: BokBot, IceID, IcedID

First seen
2017-01-01 00:00:00
Malware type
trojan, credential-stealer, botnet
Family
Malware family
Operating systems
windows
Related IoCs
3198 (2079 malicious)
Last IoC activity
2026-09-02 00:39:41
Profile updated
2026-07-07 12:41:29

Targeted industries: financial-services healthcare-and-pharmaceutical energy-and-utilities retail-and-hospitality

Context

IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017. IcedID has been downloaded by Emotet in multiple campaigns.

Recent IoC activity

2,079 malicious indicators in Maltiverse are attributed to IcedID (S0483). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname www.petiakremen.com 2026-09-03 1
hostname www.hy-link.com 2026-09-03 1
hostname texascathlab.com 2026-09-03 1
hostname petiakremen.com 2026-09-03 1
hostname www.ganjitsu.com 2026-09-03 1
hostname cannabisjoblistings.com 2026-09-03 1
hostname www.dakotapartyride.com 2026-09-03 1
hostname filomeranta.com 2026-09-03 1
hostname nataniela.com 2026-09-03 1
hostname partygirlptsd.com 2026-09-03 1
hostname mail.uriramenperu.com 2026-09-03 1
hostname nettextz.com 2026-09-03 1
hostname www.creditsail.com 2026-09-03 1
hostname clever-cohen.206-166-251-52.plesk.page 2026-09-03 1
hostname 5starfreelancer.com 2026-09-03 1
hostname bgesmart.com 2026-09-03 1
hostname yaqity.com 2026-09-03 1
hostname cannabistalks.com 2026-09-03 1
hostname yaqqity.com 2026-09-03 1
hostname mckeebler.com 2026-09-03 1

Detection coverage

  • 16 YARA rules
  • 449 Sigma rules

Malware & tools used

  • Virtualization/Sandbox Evasion (attack-pattern)
  • Process Hollowing (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Domain Trust Discovery (attack-pattern)
  • Msiexec (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (attack-pattern)
  • Permission Groups Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Rundll32 (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Malicious File (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Native API (attack-pattern)
  • Steganography (attack-pattern)
  • Domain Account (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Visual Basic (attack-pattern)
  • Asynchronous Procedure Call (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Web Protocols (attack-pattern)

Used by threat actors

  • TA577 (threat-actor)
  • TA551 (threat-actor)
  • TA578 (threat-actor)
  • Pikabot Distribution Campaigns 2023 (campaign)
  • Quantum Ransomware Compromise (campaign)
  • Water Curupira Pikabot Distribution (campaign)

Detection rules

  • TELEKOM_SECURITY_Fake_Gzip_Bokbot_202104 (yara-rule)
  • TELEKOM_SECURITY_Win_Iceid_Core_Ldr_202104 (yara-rule)
  • TELEKOM_SECURITY_Win_Iceid_Core_202104 (yara-rule)
  • EMBEERESEARCH_Win_Icedid_Snowloader_Bytecodes_Oct_2023 (yara-rule)
  • EMBEERESEARCH_Win_Icedid_Encryption_Oct_2022 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Iceid (yara-rule)
  • SIGNATURE_BASE_MAL_Icedid_GZIP_LDR_202104 (yara-rule)
  • CAPE_Icedidsyscallwritemem (yara-rule)
  • CAPE_Icedidhook (yara-rule)
  • CAPE_Icedidpackera (yara-rule)
  • CAPE_Icedidpackerb (yara-rule)
  • CAPE_Icedidpackerc (yara-rule)
  • CAPE_Icedidpackerd (yara-rule)
  • CAPE_Icedsleep (yara-rule)
  • MALPEDIA_Win_Icedid_Downloader_Auto (yara-rule)
  • MALPEDIA_Win_Icedid_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • CrowdStrike — Sin Ful Spiders Wizard Spider And Lunar Spider Sharing The Same Web (report)
  • strapi.eurepoc.eu — Eu Repo C Apt Profile Conti Wizard Spider Dc2A733E18 (report)
  • securityintelligence.com — Itg23 Crypters Cooperation Between Cybercriminal Groups (report)
  • secureworks.com — Gold Swathmore (report)
  • slideshare.net — Cb19 Cyber Threat Landscape In Japan Revealing Threat In The Shadow By Chi En Shen Ashley Oleg Bondarenko (report)
  • cloud.google.com — Melting Unc2198 Icedid To Ransomware Operations (report)
  • CrowdStrike — Report2021Gtr (report)
  • Palo Alto Unit 42 — Monsterlibra (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • proofpoint.com — First Step Initial Access Leads Ransomware (report)
  • Palo Alto Unit 42 — Ta551 Shathak Icedid (report)
  • proofpoint.com — Latrodectus Spider Bytes Ice (report)
  • Trend Micro — Rpt Navigating New Frontiers Trend Micro 2021 Annual Cybersecurity Report (report)
  • cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • Microsoft — Microsoft Digital Defense Report 2020 September (report)
  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • thedfirreport.com — Sodinokibi Aka Revil Ransomware (report)
  • web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • CrowdStrike — Carbon Spider Sprite Spider Target Esxi Servers With Ransomware (report)
  • ironnet.com — Ransomware Graphic Blog (report)
  • Cisco Talos — Quarterly Ir Report Fall 2020 Q4 (report)
  • Mandiant — Melting Unc2198 Icedid To Ransomware Operations (report)
  • trellix.com — Conti Leaks Examining The Panama Papers Of Ransomware (report)

External references