Netskope Threat Labs

Cridex

ATP Sandbox Adv. HeuristicsAV

Cridex is a banking trojan and worm that steals financial credentials and self propagates through network shares, often serving as a loader for additional malware payloads. It emerged in 2011 and evolved into the Feodo and Dridex banking trojan lineages that remain active today. Its combination of worm like spreading and credential theft made it particularly effective inside corporate networks, where a single infected host could compromise many others.

First seen
January 2022
Last seen
September 2026
Alert Name
Dropped:Trojan.Cridex.Gen.1
Gen:Heur.Cridex.1
Gen:Heur.Cridex.2
GT:VB.Cridex.1.02AA86DC
GT:VB.Cridex.1.303FDC59
GT:VB.Cridex.1.4639B13D
GT:VB.Cridex.1.50F92B7B
GT:VB.Cridex.1.5E406B4B
GT:VB.Cridex.1.6E3EA801
GT:VB.Cridex.1.730851B0