IcedID Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
October 23, 2025
Last Seen
July 1, 2026

IcedID is a malware family tracked across 8 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed October 23, 2025; most recent activity July 1, 2026.

Overview

IcedID is a banking Trojan family known for its modular loader and web-inject capabilities, used to steal financial credentials and deploy additional payloads. It has evolved into a versatile platform that can drop and monetize other malware, making it a persistent threat in financial-targeted operations. Its significance lies in combining credential theft, browser web-injects, and loader functionality to enable broader cybercrime campaigns.

Related Threat Clusters

Recent Intelligence Reports

  • 012 — attack.mitre.org · July 1, 2026
  • Police cleans nearly 15,000 SocGholish — Bleepingcomputer · June 18, 2026
  • Infostealing Malware Remains Top Threat To Healthcare — www.techtarget.com · May 7, 2026
  • Manager of botnet used in ransomware attacks gets 2 years in prison — Bleepingcomputer · March 25, 2026
  • Over 10,000 SystemBC Botnet Infections Identified Globally — Technadu · February 4, 2026
  • Police disrupts Rhadamanthys, VenomRAT, and Elysium malware operations — Bleepingcomputer · November 13, 2025
  • Dark Covenant 3.0: Controlled Impunity and Russia’s Cybercriminals — Recordedfuture · October 23, 2025

CVSS v3.1 Breakdown