IcedID is a banking Trojan family known for its modular loader and web-inject capabilities, used to steal financial credentials and deploy additional payloads.
Overview
IcedID is a banking Trojan family known for its modular loader and web-inject capabilities, used to steal financial credentials and deploy additional payloads. It has evolved into a versatile platform that can drop and monetize other malware, making it a persistent threat in financial-targeted operations. Its significance lies in combining credential theft, browser web-injects, and loader functionality to enable broader cybercrime campaigns.
Related Threat Clusters
-
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
7 articles · Updated July 1, 2026 -
VoidStealer and Infostealers Bypass Chrome's App-Bound Encryption
Malware developers have successfully bypassed Google's App-Bound Encryption (ABE) in Chrome, allowing infostealers like VoidStealer to access sensitive data such as session cookies and credentials. This new method…
11 articles · Updated May 7, 2026 -
Akira Ransomware Uses Safe Mode to Evade EDR Detection
In early August 2026, an Akira ransomware affiliate executed an attack leveraging Safe Mode to evade endpoint detection and response (EDR) tools. The attack began with credential spraying against an exposed SonicWall…
11 articles · Updated August 12, 2026 -
Russian Access Broker Sentenced for $9M Ransomware Facilitation
Aleksei Volkov, a 26-year-old Russian citizen, was sentenced to 81 months in prison for his role as an initial access broker (IAB) facilitating ransomware attacks against U.S. companies, including the Yanluowang group.…
21 articles · Updated March 24, 2026 -
Russia's Cybercrime Landscape Shifts Amid Law Enforcement Actions
Recent arrests of cybercriminals in Russia indicate a changing landscape for cybercrime, traditionally tolerated by the state as long as domestic interests were not targeted. The ongoing Operation Endgame, initiated in…
2 articles · Updated January 9, 2026 -
Operation Endgame Disrupts Major Malware Networks Rhadamanthys, VenomRAT, and Elysium
Law enforcement from nine countries has dismantled over 1,000 servers associated with the Rhadamanthys infostealer, VenomRAT remote access Trojan, and Elysium botnet during Operation Endgame. This operation, coordinated…
8 articles · Updated November 13, 2025 -
Over 10,000 Linux Servers Infected by SystemBC Botnet Variant
A new Linux variant of the SystemBC remote access trojan has infected over 10,000 IP addresses worldwide, primarily targeting web servers. Discovered by Silent Push, the compromised servers include those hosting…
6 articles · Updated February 4, 2026 -
Operation Endgame 3.0 Disrupts Major Malware Networks
Europol and law enforcement agencies from 11 countries executed Operation Endgame 3.0 from November 10 to 13, 2025, dismantling the infrastructure of three major malware operations: Rhadamanthys, VenomRAT, and Elysium.…
20 articles · Updated November 24, 2025
Recent Intelligence Reports
- AvosLocker — www.sophos.com · August 12, 2026
- 002 — attack.mitre.org · July 23, 2026
- 001 — attack.mitre.org · July 23, 2026
- 012 — attack.mitre.org · July 1, 2026
- Police cleans nearly 15,000 SocGholish — Bleepingcomputer · June 18, 2026
- Infostealing Malware Remains Top Threat To Healthcare — www.techtarget.com · May 7, 2026
- Manager of botnet used in ransomware attacks gets 2 years in prison — Bleepingcomputer · March 25, 2026
- Over 10,000 SystemBC Botnet Infections Identified Globally — Technadu · February 4, 2026