logo

Analysis of a Dridex Banking Trojan Phish

ID: d3ce3cc6-7aff-5931-af33-a5dfe92518ae

STIX ID: report--d3ce3cc6-7aff-5931-af33-a5dfe92518ae

Feed Name: WatchGuard Secplicity Blog

Threat Score
70/100

Date Published: 2021-03-31

Date Updated: 2026-05-01

Author: The Editor

...
...

This report details phishing campaigns exploiting COVID‑19 relief themes to deliver the Dridex banking trojan via macro-enabled documents and credential-harvesting sites that spoof Microsoft login pages; the author demonstrates an active compromise where entered credentials were stored on an exposed attacker server and provides detection and prevention advice (email red flags, WMI/PowerShell monitoring, and WatchGuard products).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.