logo

Bokbot: The (re)birth of a banker

ID: 3d4a71b4-a186-539a-8ee0-b684b39a7377

STIX ID: report--3d4a71b4-a186-539a-8ee0-b684b39a7377

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2018-08-09

Date Updated: 2026-04-27

...
...

This Fox-IT technical analysis describes Bokbot (aka IcedID), a banking trojan observed from mid-2017 that appears linked to the Neverquest/Vawtrak actors; it covers Bokbot’s HTTPS/RC4/LZMAT communication, signed binary configs (bot/inject/reporting), bot/project ID formats, web-inject and dynamic redirect capabilities, geographic targeting (primarily North America), distribution via partners such as Geodo/Emotet and Chanitor, and its role in downloading additional malware (TheTrick, TinyLoader), concluding that Bokbot is an active, evolving criminal operation with strong underground affiliations and growing impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.