HomeSecurityIcedID Banking Trojan: New variant distributed via spam emails

IcedID Banking Trojan: New variant distributed via spam emails

A new variant of the IcedID Banking Trojan is being distributed via two new spam campaigns.

The spam messages are written in English and deliver .ZIP files with malware or links leading to such ZIP files.

See also: Bizarro banking trojan: Targets bank customers in Europe and America

IcedID Banking Trojan

Kaspersky researchers said they monitored the spam campaigns in mid-March. Most of the payloads the researchers collected were IcedID (Trojan-Banker.Win32.IcedID), but also some samples of the banking trojan Qbot (Backdoor.Win32.Qbot, also known as QakBot).

The same pattern (IcedID and Qbot) was also observed in another spam campaign in April. At the time, it seemed that IcedID was coming to fill the gap left by Emotet, which authorities had “destroyed” in January. IcedID not only functions as a banking trojan, but is also used as a dropper for other malware.

See also: QBot trojan replaces IcedID in malspam campaigns!

IcedID (also known as BokBot) is similar to Emotet in that both are modular malware, which started life as a banking trojan and were initially used to steal financial information. As Kaspersky researchers noted, IcedID can now also detect virtual machines (VMs), which is very useful for criminals.

IcedID Banking Trojan: New variant distributed via spam emails

The new variant of the IcedID banking trojan has also been equipped with a new downloader.

As the researchers say, IcedID has two parts: a downloader and a main body. The downloader sends user information (username, MAC address, and Windows version) to the C2 server , which in turn receives the main body of the malware.

See also: Janeleiro: The new banking trojan that targets organizations and governments

In previous versions of IcedID, the downloader was built as an x86 executable. In the new version, the criminals moved from x86 to an x86-64 version.

The creators of the latest IcedID variant also modified the main part of the malware. Previously, the main body was a shellcode hidden in a .PNG image. “The downloader takes the image, decrypts the main body in memory and executes it,” the researchers said. “The main body then begins to perform its malicious actions, such as web injects, extracting data to the C2, downloading and executing additional payloads, stealing system information, and more,” they said.

It is even distributed as a .PNG image. But this time, the creators decided not to use shellcode. Now the main body of IcedID is distributed as “a standard [PE or Portable Executable] file.”

On the other hand, Qbot does not have two parts. It is a single executable.

“To steal passwords, perform web injections, and take control of the infected system remotely, Qbot downloads additional modules: Web inject module, hVNC (remote control module), email and password harvesting tool, and more,” the researchers say.

IcedID Banking Trojan spam

The two spam campaigns distributing the IcedID Banking Trojan

Campaign 1: DotDat

Researchers have dubbed the first campaign “DotDat.” The spam emails contain .ZIP attachments, which in turn contain a malicious Excel file with the same name.

The Excel file downloads a malicious payload via a macro from a URL in the format [host]/[digits].[digits].dat and then executes the payload. The payload it delivers is either the IcedID downloader – Trojan.Win32.Ligooc – or Qbot.

The Excel file contains obfuscated Excel 4.0 macro formulas for downloading and executing the payload. The macro creates a payload URL and uses the WinAPI function “URLDownloadToFile” to download the malicious software.

Campaign 2: “summer.gif”“

In the second campaign, researchers found spam emails containing links to hacked websites with malicious files named “documents.zip”, “document-XX.zip” and “doc-XX.zip”, where XX represents two random digits. As in the DotDat campaign, the Zip files contained an Excel file with a macro that downloaded the IcedID downloader. This particular campaign peaked in mid-March and by April had all but disappeared.

IcedID banking trojan

IcedID and Qbot spam distribution campaigns have primarily targeted Chinese users (16%), followed by users in India (12%), Italy (11%), the US (11%), and Germany (9%).

Source: Threatpost

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS