IcedID

Last reviewed:

IcedID is a type of malware primarily used for financial theft and data exfiltration. Initially identified in 2017, IcedID has evolved to include additional functionalities, making it a versatile threat. It is often distributed through phishing campaigns and has been linked to various cybercriminal activities. As of October 2023, IcedID remains a significant concern for cybersecurity professionals due to its adaptability and the persistent threat it poses to organizations across different sectors.

Overview

IcedID, also known as BokBot, is a banking trojan designed to steal financial information and facilitate other malicious activities. It was first discovered in 2017 and has since been used in numerous cybercriminal campaigns. IcedID is known for its modular architecture, allowing it to incorporate new functionalities as needed. This adaptability has made it a persistent threat in the cybersecurity landscape.

History

IcedID was first identified by security researchers in 2017. Initially, it targeted financial institutions in the United States, using web injection techniques to steal banking credentials. Over time, its capabilities expanded to include data exfiltration, network reconnaissance, and the ability to serve as a dropper for other malware. This evolution has made IcedID a versatile tool for cybercriminals.

Technical characteristics

IcedID is a modular malware, meaning it can load additional components to enhance its capabilities. It primarily operates as a banking trojan, using web injection techniques to intercept and modify web traffic. This allows it to steal sensitive information such as login credentials and financial data. IcedID can also perform network reconnaissance, enabling attackers to gather information about the infected system and its network environment. Additionally, it can serve as a dropper, facilitating the delivery of other malware onto compromised systems.

Infection vector

IcedID is typically distributed through phishing emails that contain malicious attachments or links. These emails often appear to be legitimate communications from trusted sources, tricking recipients into opening them. Once the attachment is opened or the link is clicked, the malware is downloaded and executed on the victim's system. IcedID can also spread through exploit kits, which take advantage of vulnerabilities in software to deliver the malware without user interaction.

Notable campaigns

IcedID has been involved in several high-profile cybercriminal campaigns. One notable campaign occurred in 2018, when IcedID was used in conjunction with the Emotet malware to deliver ransomware to targeted organizations. This campaign highlighted IcedID's ability to act as a dropper for other malware, increasing its threat potential. Another significant campaign took place in 2020, when IcedID was used to target healthcare organizations during the COVID-19 pandemic, exploiting the increased reliance on digital communication and remote work.

Detection and mitigation

Detecting IcedID can be challenging due to its modular nature and ability to evade traditional security measures. However, organizations can implement several strategies to mitigate the risk of infection. These include using advanced threat detection solutions that leverage machine learning and behavioral analysis to identify suspicious activity. Additionally, organizations should educate employees about the risks of phishing and encourage them to verify the legitimacy of emails before opening attachments or clicking links. Regular software updates and patch management can also help protect against vulnerabilities that IcedID may exploit.

IcedID Malware Evolution

IcedID Infection Process

See also

  • lateral movement

Sources

Categories: Malware
Last updated: September 1, 2026