Description
IcedID is a botnet that has been around since 2017 and grew from a banking trojan into one of the most popular loaders for serious intrusions. It steals personal data, credentials, and banking information through web injects and form grabbing, and it downloads and executes other payloads such as Cobalt Strike and ransomware. Cyberattackers deliver it through phishing, malvertising, and loader chains, and its modular design has kept it central to organized crime ecosystems for years.
Stats
- First seen
- January 2022
- Last seen
- October 2026
Also known as
IcedIdIcedid
MITRE ATT&CK techniques
31 techniques across 8 tactics.
TA0002 Execution
TA0005 Stealth
TA0007 Discovery
- T1016System Network Configuration Discovery
- T1069Permission Groups Discovery
- T1082System Information Discovery
- T1087Account Discovery
- T1087.002Domain Account
- T1135Network Share Discovery
- T1482Domain Trust Discovery
- T1518Software Discovery
- T1518.001Security Software Discovery
- T1614System Location Discovery
- T1614.001System Language Discovery
TA0009 Collection
- T1185Browser Session Hijacking
TA0011 Command and Control
Associated groups
Associated campaigns
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.IcedID |
| Document-Excel.Trojan.IcedID |
| Document-HTML.Dropper.IcedID |
| Document-HTML.Trojan.IcedID |
| Document-Office.Trojan.IcedID |
| Document-PDF.Trojan.IcedID |
| Document-Word.Trojan.IcedID |
| Gen:Variant.IcedID.11 |
| Gen:Variant.IcedId.112612 |
| Gen:Variant.IcedId.122234 |





