IcedID
MITRE ATT&CK: S0483 View on attack.mitre.org
Aliases: BokBot, IceID, IcedID
- First seen
- 2017-01-01 00:00:00
- Malware type
- trojan, credential-stealer, botnet
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 3198 (2079 malicious)
- Last IoC activity
- 2026-09-02 00:39:41
- Profile updated
- 2026-07-07 12:41:29
Targeted industries: financial-services healthcare-and-pharmaceutical energy-and-utilities retail-and-hospitality
Context
IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017. IcedID has been downloaded by Emotet in multiple campaigns.
Recent IoC activity
2,079 malicious indicators in Maltiverse are attributed to IcedID (S0483). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | www.petiakremen.com | 2026-09-03 | 1 |
| hostname | www.hy-link.com | 2026-09-03 | 1 |
| hostname | texascathlab.com | 2026-09-03 | 1 |
| hostname | petiakremen.com | 2026-09-03 | 1 |
| hostname | www.ganjitsu.com | 2026-09-03 | 1 |
| hostname | cannabisjoblistings.com | 2026-09-03 | 1 |
| hostname | www.dakotapartyride.com | 2026-09-03 | 1 |
| hostname | filomeranta.com | 2026-09-03 | 1 |
| hostname | nataniela.com | 2026-09-03 | 1 |
| hostname | partygirlptsd.com | 2026-09-03 | 1 |
| hostname | mail.uriramenperu.com | 2026-09-03 | 1 |
| hostname | nettextz.com | 2026-09-03 | 1 |
| hostname | www.creditsail.com | 2026-09-03 | 1 |
| hostname | clever-cohen.206-166-251-52.plesk.page | 2026-09-03 | 1 |
| hostname | 5starfreelancer.com | 2026-09-03 | 1 |
| hostname | bgesmart.com | 2026-09-03 | 1 |
| hostname | yaqity.com | 2026-09-03 | 1 |
| hostname | cannabistalks.com | 2026-09-03 | 1 |
| hostname | yaqqity.com | 2026-09-03 | 1 |
| hostname | mckeebler.com | 2026-09-03 | 1 |
Detection coverage
- 16 YARA rules
- 449 Sigma rules
Malware & tools used
- Virtualization/Sandbox Evasion (attack-pattern)
- Process Hollowing (attack-pattern)
- System Language Discovery (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- Msiexec (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (attack-pattern)
- Permission Groups Discovery (attack-pattern)
- Scheduled Task (attack-pattern)
- Rundll32 (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Malicious File (attack-pattern)
- Security Software Discovery (attack-pattern)
- Embedded Payloads (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Native API (attack-pattern)
- Steganography (attack-pattern)
- Domain Account (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Visual Basic (attack-pattern)
- Asynchronous Procedure Call (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Web Protocols (attack-pattern)
Used by threat actors
Detection rules
- TELEKOM_SECURITY_Fake_Gzip_Bokbot_202104 (yara-rule)
- TELEKOM_SECURITY_Win_Iceid_Core_Ldr_202104 (yara-rule)
- TELEKOM_SECURITY_Win_Iceid_Core_202104 (yara-rule)
- EMBEERESEARCH_Win_Icedid_Snowloader_Bytecodes_Oct_2023 (yara-rule)
- EMBEERESEARCH_Win_Icedid_Encryption_Oct_2022 (yara-rule)
- DITEKSHEN_MALWARE_Win_Iceid (yara-rule)
- SIGNATURE_BASE_MAL_Icedid_GZIP_LDR_202104 (yara-rule)
- CAPE_Icedidsyscallwritemem (yara-rule)
- CAPE_Icedidhook (yara-rule)
- CAPE_Icedidpackera (yara-rule)
- CAPE_Icedidpackerb (yara-rule)
- CAPE_Icedidpackerc (yara-rule)
- CAPE_Icedidpackerd (yara-rule)
- CAPE_Icedsleep (yara-rule)
- MALPEDIA_Win_Icedid_Downloader_Auto (yara-rule)
- MALPEDIA_Win_Icedid_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- CrowdStrike — Sin Ful Spiders Wizard Spider And Lunar Spider Sharing The Same Web (report)
- strapi.eurepoc.eu — Eu Repo C Apt Profile Conti Wizard Spider Dc2A733E18 (report)
- securityintelligence.com — Itg23 Crypters Cooperation Between Cybercriminal Groups (report)
- secureworks.com — Gold Swathmore (report)
- slideshare.net — Cb19 Cyber Threat Landscape In Japan Revealing Threat In The Shadow By Chi En Shen Ashley Oleg Bondarenko (report)
- cloud.google.com — Melting Unc2198 Icedid To Ransomware Operations (report)
- CrowdStrike — Report2021Gtr (report)
- Palo Alto Unit 42 — Monsterlibra (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- proofpoint.com — First Step Initial Access Leads Ransomware (report)
- Palo Alto Unit 42 — Ta551 Shathak Icedid (report)
- proofpoint.com — Latrodectus Spider Bytes Ice (report)
- Trend Micro — Rpt Navigating New Frontiers Trend Micro 2021 Annual Cybersecurity Report (report)
- cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- Microsoft — Microsoft Digital Defense Report 2020 September (report)
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- thedfirreport.com — Sodinokibi Aka Revil Ransomware (report)
- web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- CrowdStrike — Carbon Spider Sprite Spider Target Esxi Servers With Ransomware (report)
- ironnet.com — Ransomware Graphic Blog (report)
- Cisco Talos — Quarterly Ir Report Fall 2020 Q4 (report)
- Mandiant — Melting Unc2198 Icedid To Ransomware Operations (report)
- trellix.com — Conti Leaks Examining The Panama Papers Of Ransomware (report)