Executive Summary
IcedID is a modular Windows banking trojan that steals online banking credentials by injecting code into browsers and logging keystrokes. The trojan is frequently dropped by Emotet campaigns, enabling attackers to acquire valuable financial data while maintaining persistence through scheduled tasks and encrypted C2 channels. Its flexible module system allows operators to adapt attacks to new banking targets and evade detection.
Enhanced Description
IcedID is a modular banking trojan first observed in 2017 that focuses on harvesting financial credentials from compromised Windows systems. The codebase is designed as a dropper, capable of loading additional modules over the network; its most common delivery vector is through Emotet campaigns, which download and install IcedID variants onto infected machines. Once installed, the malware injects malicious DLL components into popular web browsers (e.g., Internet Explorer, Edge, Chrome) to intercept HTTPS traffic, capture form submissions, and log keystrokes. It also collects local data such as saved passwords in browsers, cached credentials from Windows Credential Manager, and can exfiltrate this information over encrypted channels. Beyond credential theft, IcedID implements persistence via scheduled tasks, system registry modifications, and Windows service recreation. The trojan communicates with command‑and‑control servers using HTTP/HTTPS through dynamic DNS, enabling the operator to upload new modules or alter configuration at runtime. In some cases it also performs basic reconnaissance on the host network, collecting IP ranges and identifying other vulnerable services for lateral movement. The modular architecture allows IcedID operators to tailor infects for specific banking targets, adding specialized payload modules that can launch phishing windows or harvest credentials from niche web portals. While the malware’s footprint is relatively lightweight—often under 2 MB—it remains a high‑impact threat due to the financial gain derived from stolen account data and the ability to co‑operate with other sophisticated campaigns such as Emotet. Overall, IcedID represents an evolving, low‑visibility component of the broader cybercrime ecosystem that continuously adapts its delivery and exfiltration mechanisms to remain effective in banking fraud and credential theft.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available information is largely derived from public security reports and threat intelligence alerts, providing a solid foundation for understanding IcedID’s observable behavior. However, gaps remain in the detailed technical breakdown of specific variants, internal code structure, and full range of command‑and‑control techniques employed. Continuous monitoring of new sightings and deeper malware analyses would strengthen confidence further.
IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017. IcedID has been downloaded by Emotet in multiple campaigns.(Citation: IBM IcedID November 2017)(Citation: Juniper IcedID June 2020)