IcedID, also known as BokBot, is a sophisticated banking trojan and malware loader first identified in 2017. Initially designed to steal financial credentials, it has evolved into a multi-purpose threat capable of deploying ransomware and other malware.
Core Functionality
• Financial theft: Uses web injection attacks to hijack banking sessions, intercept credentials, and bypass multi-factor authentication (MFA) by redirecting traffic through malicious proxy servers.
• Malware delivery: Acts as a loader for payloads like ransomware (e.g., Conti, REvil).
• Network propagation: Spreads laterally across networks after initial infection.
Technical Characteristics
• Process hollowing: Injects malicious code into legitimate processes like svchost.exe
or msiexec.exe
.
• Obfuscation: Uses XOR cipher encryption, polymorphic code, and steganography to evade detection.
• Persistence: Creates scheduled tasks and modifies registry entries.