Simda

Aliases: iBank

First seen
2009-09-01 00:00:00
Malware type
botnet, credential-stealer
Family
Malware family
Last IoC activity
2026-07-22 01:21:50
Profile updated
2026-07-07 14:55:57

Targeted industries: financial-services

Targeted regions: country_code:us country_code:ru

Context

Simda is a botnet and credential-stealing malware that primarily targets financial institutions. It is known for distributing fake software updates to users, subsequently infecting systems and stealing sensitive information.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Simda_Auto (yara-rule)

Related threat objects

  • Simda (infrastructure)

Reports & references

  • McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
  • McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
  • estr3llas.github.io — Unveiling Custom Packers A Comprehensive Guide (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Simda (report)
  • Trend Micro — Simda A Botnet Takedown (report)
  • secrary.com — Ibank (report)
  • bin.re — The Dga Of Simda Shiz (report)
  • youtube.com — Watch (report)
  • web.archive.org — Simda A Botnet Takedown (report)
  • sonicwall.com — Simda Process Injection Into Winlogon Dga Found (report)

External references