IcedID

S0483

Malware.View on attack.mitre.org

About this malware

IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017. IcedID has been downloaded by Emotet in multiple campaigns.

Techniques used31

Procedure examples31

TechniqueProcedure example
T1016
System Network Configuration Discovery

IcedID used the `ipconfig /all` command and a batch script to gather network information.

T1027.002
Software Packing

IcedID has packed and encrypted its loader module.

T1027.003
Steganography

IcedID has embedded binaries within RC4 encrypted .png files.

T1027.009
Embedded Payloads

IcedID has embedded malicious functionality in a legitimate DLL file.

T1027.013
Encrypted/Encoded File

IcedID has utilzed encrypted binaries and base64 encoded strings.

T1036.005
Match Legitimate Resource Name or Location

IcedID has modified legitimate .dll files to include malicious code.

T1047
Windows Management Instrumentation

IcedID has used WMI to execute binaries.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol

IcedID has exfiltrated collected data via HTTPS.

T1053.005
Scheduled Task

IcedID has created a scheduled task to establish persistence.

T1055.004
Asynchronous Procedure Call

IcedID has used ZwQueueApcThread to inject itself into remote processes.

T1055.012
Process Hollowing

IcedID can inject a Cobalt Strike beacon into cmd.exe via process hallowing.

T1059.005
Visual Basic

IcedID has used obfuscated VBA string expressions.

T1069
Permission Groups Discovery

IcedID has the ability to identify Workgroup membership.

T1071.001
Web Protocols

IcedID has used HTTPS in communications with C2.

T1082
System Information Discovery

IcedID has the ability to identify the computer name and OS version on a compromised host.

View all 31 procedure examples

Groups that use it2

Campaigns1

References2

  1. IBM IcedID November 2017 Open source
    Kessem, L., et al. (2017, November 13). New Banking Trojan IcedID Discovered by IBM X-Force Research. Retrieved July 14, 2020.
  2. Juniper IcedID June 2020 Open source
    Kimayong, P. (2020, June 18). COVID-19 and FMLA Campaigns used to install new IcedID banking malware. Retrieved July 14, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.