Simda
Aliases: iBank
- First seen
- 2009-09-01 00:00:00
- Malware type
- botnet, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:21:50
- Profile updated
- 2026-07-07 14:55:57
Targeted industries: financial-services
Targeted regions: country_code:us country_code:ru
Context
Simda is a botnet and credential-stealing malware that primarily targets financial institutions. It is known for distributing fake software updates to users, subsequently infecting systems and stealing sensitive information.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Simda_Auto (yara-rule)
Related threat objects
- Simda (infrastructure)
Reports & references
- McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
- McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
- estr3llas.github.io — Unveiling Custom Packers A Comprehensive Guide (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Simda (report)
- Trend Micro — Simda A Botnet Takedown (report)
- secrary.com — Ibank (report)
- bin.re — The Dga Of Simda Shiz (report)
- youtube.com — Watch (report)
- web.archive.org — Simda A Botnet Takedown (report)
- sonicwall.com — Simda Process Injection Into Winlogon Dga Found (report)