Netskope Threat Labs

Dridex

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Dridex has been around since at least 2015 and has had its botnet infrastructure taken down multiple times, but it continues to re-emerge with new features and new infrastructure. The banking trojan steals credentials through web injects and form grabbing, and its operators rent out the botnet as a loader for ransomware and other payloads. Its resilience comes from a modular design and a criminal organization, Evil Corp, that repeatedly rebuilds its delivery chains after disruption.

First seen
January 2022
Last seen
October 2026

15 techniques across 5 tactics.

TA0002 Execution

TA0005 Stealth

TA0007 Discovery

  • T1082System Information Discovery
  • T1518Software Discovery

TA0009 Collection

  • T1185Browser Session Hijacking

TA0011 Command and Control

Alert Name
Binary.Infostealer.Dridex
Binary.Trojan.Dridex
DeepScan:Generic.Dridex.Y.D1888308
Document-Excel.Infostealer.Dridex
Document-Excel.Trojan.Dridex
Document-Office.Infostealer.Dridex
Document-Word.Infostealer.Dridex
Document-Word.Trojan.Dridex
Email-MIME.Infostealer.Dridex
Gen:Variant.Application.Jaik.Dridex.39019