Netskope Threat Labs

IcedID

ATP Sandbox Adv. HeuristicsAVNetskope IPS

IcedID is a botnet that has been around since 2017 and grew from a banking trojan into one of the most popular loaders for serious intrusions. It steals personal data, credentials, and banking information through web injects and form grabbing, and it downloads and executes other payloads such as Cobalt Strike and ransomware. Cyberattackers deliver it through phishing, malvertising, and loader chains, and its modular design has kept it central to organized crime ecosystems for years.

First seen
January 2022
Last seen
October 2026
IcedIdIcedid

31 techniques across 8 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

TA0009 Collection

  • T1185Browser Session Hijacking

TA0011 Command and Control

TA0010 Exfiltration

  • T1048Exfiltration Over Alternative Protocol
    • T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Alert Name
ByteCode-MSIL.Trojan.IcedID
Document-Excel.Trojan.IcedID
Document-HTML.Dropper.IcedID
Document-HTML.Trojan.IcedID
Document-Office.Trojan.IcedID
Document-PDF.Trojan.IcedID
Document-Word.Trojan.IcedID
Gen:Variant.IcedID.11
Gen:Variant.IcedId.112612
Gen:Variant.IcedId.122234