Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware IceCube

IceCube

TLP:CLEAR
Family

AI Analysis

No AI analysis yet.

Description

According to Proofpoint, IceCube is a JavaScript-based stealer likely developed with the assistance of a large language model, targeting Roundcube webmail instances. It escapes the webmail's iFrame context via DOM traversal to access the full document and the authentication session, then exfiltrates usernames, passwords, two-factor authentication material, cookies, and browser reconnaissance data (such as language, screen size, and form field values) via HTTP POST to its command-and-control server. The malware is heavily commented with well-marked execution phases, and incorporates self-cleanup routines, "fallbacks" for failed exploitation steps, and "deferred triggers" that hook browser events such as tab changes, mouse leaving the window, and the logout button to re-attempt exploitation. After successful server-side exploitation, it destroys both user and malware-initiated sessions to remove forensic evidence from the Roundcube server.

Details

Type
Unknown
Platforms
Windows
Linux
Macos
Confidence
80%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.