ATT&CKReferencesIBM IcedID November 2017

IBM IcedID November 2017

Kessem, L., et al. (2017, November 13). New Banking Trojan IcedID Discovered by IBM X-Force Research. Retrieved July 14, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1055.004
Asynchronous Procedure Call
MalwareIcedID

IcedID has used ZwQueueApcThread to inject itself into remote processes.

T1069
Permission Groups Discovery
MalwareIcedID

IcedID has the ability to identify Workgroup membership.

T1082
System Information Discovery
MalwareIcedID

IcedID has the ability to identify the computer name and OS version on a compromised host.

T1087.002
Domain Account
MalwareIcedID

IcedID can query LDAP and can use built-in `net` commands to identify additional users on the network to infect.

T1087.003
Email Account
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

T1105
Ingress Tool Transfer
MalwareIcedID

IcedID has the ability to download additional modules and a configuration file from C2.

T1114
Email Collection
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

T1185
Browser Session Hijacking
MalwareIcedID

IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser.

T1204.002
Malicious File
MalwareEmotet

Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1547.001
Registry Run Keys / Startup Folder
MalwareIcedID

IcedID has established persistence by creating a Registry run key.

T1555.003
Credentials from Web Browsers
MalwareEmotet

Emotet has been observed dropping browser password grabber modules.

T1566.001
Spearphishing Attachment
MalwareEmotet

Emotet has been delivered by phishing emails containing attachments.

T1573.002
Asymmetric Cryptography
MalwareIcedID

IcedID has used SSL and TLS in communications with C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.