IcedID malware distribution has increased! The reason? A new campaign is hacking existing email conversation threads and injecting malicious payloads that are difficult to detect.
IcedID is a banking trojan first detected in 2017, primarily used to deploy second-stage malware, such as other loaders or ransomware.

Its operators are believed to be initial access brokers who compromise networks and then sell the access to other cybercriminals.
The ongoing IcedID campaign was discovered this month by researchers at Intezer, who shared their findings with Bleeping Computer ahead of publication.
See also: CISA adds 66 vulnerabilities to the "Known Exploited Vulnerabilities" list
How the attack works
The main method of conversation hijacking is to take control of a primary email account that is participating in a conversation with the target and then send a phishing message designed to appear as a continuation of the thread.
Therefore, when the target receives a reply message with an attachment named and presented as something related to the previous conversation, the chances of suspecting fraud are reduced to a minimum.
Intezer explains that there are indications that threat actors are targeting vulnerable Microsoft Exchange servers to steal credentials, as many of the compromised endpoints they found are public and unpatched.
Additionally, in this campaign, analysts have seen malicious phishing messages sent from internal Exchange servers, using local IP addresses in a more trusted domain and, therefore, unlikely to be flagged as suspicious.

The email attachment sent to targets is a ZIP file containing an ISO file, which in turn encloses an LNK file and a DLL file. If the victim double-clicks on “document.lnk,” the DLL launches to set up the IcedID loader.
See also: Google fixes Chrome zero-day bug used in attacks
The IcedID GZiploader is stored in encrypted form in the resource section of the binary file and after decoding, it is placed in memory and executed.
The host is then fingerprinted and basic system information is sent to the C2 via an HTTP GET request.
Finally, the C2 responds by sending a payload to the infected machine, although this step was not performed during Intezer's analysis.

See also: FCC: Kaspersky poses a risk to US national security
Microsoft released fixes for the ProxyLogon and ProxyShell vulnerabilities a year ago, so if you haven't implemented the company's security solutions, you're really late and at risk.
Information source: bleepingcomputer.com
