logo

Signed Dridex Campaign

ID: f500eba5-919c-58b6-8ac4-1002e2b88d83

STIX ID: report--f500eba5-919c-58b6-8ac4-1002e2b88d83

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ analyzed a Dridex banking Trojan campaign in which malicious Office attachments download Dridex samples that are signed with COMODO-issued code-signing certificates (including a certificate issued to "Private Person Parobii Yuri Romanovich") and packed with a custom .NET packer. The report documents download URLs, numerous sample hashes, C2 IP addresses and embedded configuration details, describes the packer behavior and Delphi dropper, and notes that the malware collects system information (computer name, user name, Windows version, botnet ID) and attempts to connect to a list of command-and-control servers; Zscaler is monitoring the campaign and ensuring detection coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.