logo

IcedID GZIPLOADER Analysis

ID: 4af89350-dbe2-5153-8276-9d21ac64dd3c

STIX ID: report--4af89350-dbe2-5153-8276-9d21ac64dd3c

Feed Name: Binary Defense Blog

Threat Score
78/100

Date Published: 2025-08-12

Date Updated: 2026-05-12

...
...

Binary Defense analyzes a new IcedID variant delivered by Qakbot's TR malspam affiliate that replaces the photoloader with a novel 'gziploader' first stage and updated encryption to hide configuration and embedded strings. The report reverse-engineers the loader and main bot, documents payload layout and memory loading, describes post-infection behaviors (credential and cookie theft, browser hooking, DLL injection, Exec/ExecAdmin behavior, and Cobalt Strike staging), provides detection opportunities and IOCs (files, commands, domains, IPs), and releases a decryption tool to assist defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.