Site icon TheCyberThrone

IceID Malware Shifting Focus to Ransomwares

Advertisements

Researchers have spotted three new variants of the IcedID malware are being used by multiple threat actors with their codes shifted away from launching banking trojans to more of a focus on ransomware.

A new version with potentially a separate panel for managing the malware. While much of the code base is the same, the threat actors have removed banking functionality, such as web injects and back connect.

The first new variant of IcedID dubbed “IcedID Lite” distributed as a follow-on payload in a TA542 Emotet campaign. This was dropped by the Emotet malware soon after the actor recently returned to the cybercrime landscape after a nearly four-month break.

Advertisements

During 2022 and 2023, researchers has seen hundreds of attack campaigns using the IcedID Trojan and managed to link them to five distinct threat actors.

With this, the researchers strongly believe the original operators behind Emotet have been using an IcedID variant with different functionality. IcedID comes from a family like Emotet, as it’s a two-stage malware, the behavior patterns are more accessible to identify than a single state, with the intent to load additional malicious code.

Advertisements

Emotet and IcedID are well-known trojans, more commonly known for stealing banking credentials, and now it’s transitioned into a C2 loader providing malicious actors with a much more fluid vehicle.

The high number of actors and campaigns involving IcedID’s suggests a potent and flexible strain of malware — the kind of tool that lends itself to other uses.

This research was documented by researchers from Proofpoint

Exit mobile version