logo

Dridex Activity Continues

ID: 0003aa96-c64b-57f6-8956-596341bcb66a

STIX ID: report--0003aa96-c64b-57f6-8956-596341bcb66a

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Dridex banking malware has shown renewed activity after a takedown, with attackers distributing malicious Office/MHTML attachments that use obfuscated macros to download a packed Dridex executable; campaigns include both unsigned and digitally signed binaries (multiple forged/legitimate-seeming certificates). The report documents recent hosting IPs/URLs, MD5 hashes of samples, observed TTPs (macro-based delivery, custom packer, certificate abuse) and geographic hosting distribution, and warns of a steady increase in infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.