Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware IcedID

IcedID

TLP:CLEAR
Family

AI Analysis

· 23 hours ago

Executive Summary

IcedID is a modular Windows banking trojan that steals online banking credentials by injecting code into browsers and logging keystrokes. The trojan is frequently dropped by Emotet campaigns, enabling attackers to acquire valuable financial data while maintaining persistence through scheduled tasks and encrypted C2 channels. Its flexible module system allows operators to adapt attacks to new banking targets and evade detection.

Enhanced Description

IcedID is a modular banking trojan first observed in 2017 that focuses on harvesting financial credentials from compromised Windows systems. The codebase is designed as a dropper, capable of loading additional modules over the network; its most common delivery vector is through Emotet campaigns, which download and install IcedID variants onto infected machines. Once installed, the malware injects malicious DLL components into popular web browsers (e.g., Internet Explorer, Edge, Chrome) to intercept HTTPS traffic, capture form submissions, and log keystrokes. It also collects local data such as saved passwords in browsers, cached credentials from Windows Credential Manager, and can exfiltrate this information over encrypted channels. Beyond credential theft, IcedID implements persistence via scheduled tasks, system registry modifications, and Windows service recreation. The trojan communicates with command‑and‑control servers using HTTP/HTTPS through dynamic DNS, enabling the operator to upload new modules or alter configuration at runtime. In some cases it also performs basic reconnaissance on the host network, collecting IP ranges and identifying other vulnerable services for lateral movement. The modular architecture allows IcedID operators to tailor infects for specific banking targets, adding specialized payload modules that can launch phishing windows or harvest credentials from niche web portals. While the malware’s footprint is relatively lightweight—often under 2 MB—it remains a high‑impact threat due to the financial gain derived from stolen account data and the ability to co‑operate with other sophisticated campaigns such as Emotet. Overall, IcedID represents an evolving, low‑visibility component of the broader cybercrime ecosystem that continuously adapts its delivery and exfiltration mechanisms to remain effective in banking fraud and credential theft.

Key Capabilities

  • Credential harvesting via browser DLL injection
  • Keylogging and form grabbing
  • Network traffic sniffing for HTTPS credentials
  • Dynamic module download from C2 using HTTP/HTTPS
  • Persistence through scheduled tasks, registry entries, and services
  • Encrypted command‑and‑control communication
  • Lateral reconnaissance of internal networks
  • Integration with Emotet dropper campaigns

ATT&CK Techniques

T1056
T1071.001
T1041
T1105

Recommended Actions

  • Block known IcedID domains and IP addresses at the perimeter and with DNS filtering
  • Implement strict web filtering to prevent access to compromised banking portals
  • Enable endpoint detection to flag suspicious DLL injections into browsers
  • Enforce least privilege and remove unnecessary local admin accounts
  • Apply timely software patches to reduce vulnerability exploitation chances
  • Use multi‑factor authentication on all financial accounts to mitigate credential misuse
  • Deploy a robust backup strategy for critical data and account credentials
  • Configure network monitoring to detect anomalous outbound HTTPS connections

Suggested Tags

Banking trojan
Credential theft
DLL injection
Modular malware
Emotet dropper
Financial phishing
Windows endpoint threat

Confidence Assessment

The available information is largely derived from public security reports and threat intelligence alerts, providing a solid foundation for understanding IcedID’s observable behavior. However, gaps remain in the detailed technical breakdown of specific variants, internal code structure, and full range of command‑and‑control techniques employed. Continuous monitoring of new sightings and deeper malware analyses would strengthen confidence further.

Description

IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017. IcedID has been downloaded by Emotet in multiple campaigns.(Citation: IBM IcedID November 2017)(Citation: Juniper IcedID June 2020)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.