IcedID: new malware version
ID: 0626442e-ae98-5709-b560-af767fc746fa
STIX ID: report--0626442e-ae98-5709-b560-af767fc746fa
Feed Name: Group-IB Blog
Threat Score
This report analyzes a new IcedID (BokBot) banking Trojan variant that uses steganography to hide its second-stage downloader, main module, and configuration in PNG images; it details the multi-stage infection flow, persistence, MiTM proxy/hooker for HTTPS interception, VNC and SOCKS backconnect capabilities, UAC bypass methods, SSL pinning, VM checks, and provides indicators of compromise and C2 URLs to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
