HomeSecurityIcedID: New variants spread malware

IcedID: New variants spread malware

New IcedID variants have been found without the usual banking fraud functionality. Instead, they appear to be aimed at installing additional malware on infected devices.

Malware

According to Proofpoint, these new variants have been used by three separate hackers in seven campaigns since last year, focusing on sending additional payloads, specifically ransomware.

Proofpoint has identified two new versions of the IcedID loader, named “Lite” and “Forked,” both of which ship the same IcedID bot with a more focused set of features.

By removing unnecessary functionality from IcedID, which has been used in numerous campaigns without its code having changed since 2017, it makes it quieter and leaner, thus allowing hackers to avoid detection.  

IcedID: New variants spread malware

See also: IcedID Banking Trojan: New variant distributed via spam emails

New IcedID campaign

Since November 2022, the “Lite” version of the IcedID loader has been sent as a second part of the payload to systems infected with the well-known Emote malware.

The “Forked” version of the loader first appeared in February 2023, infecting directly via invoice phishing emails.

These messages used the Microsoft OneNote (.one) extension to execute a malicious HTA file that ran PowerShell commands that remotely pulled IcedID. At the same time, the victim was viewing a PDF as a distraction.

IcedID: New variants spread malware

In late February, Proofpoint researchers observed a low-volume campaign distributing IcedID “Forked” via fake alerts from the National Highway Traffic Safety Administration and the U.S. Food and Drug Administration (FDA).

It is important to note that while some hackers are using new variants of the IcedID malware, others still choose to use the “Standard” variant, with one of the most recent campaigns dating back to March 10, 2023.

The new variations

The “Forked” IcedID loader is quite similar to the “Standard” version in terms of its role, sending basic host information to the C2 and then retrieving the IcedID bot.

However, “Forked” uses a different file type (COM Server) and has additional domain and string decryption code, making the payload 12KB larger than the “Standard” version.

IcedID: New variants spread malware

Suggestion:IcedID malware: Hackers are testing new distribution methods

On the other hand, the loader of the “Lite” variant is lighter, at 20KB, and does not pass host information to the C2. This change makes sense, given that it was developed alongside Emotet, which had already profiled the compromised system.

The “Forked” version of the IcedID bot is 64KB smaller than the “Standard” bot and is essentially the same malware minus the web injection system, AiTM features, and backconnect capabilities that give hackers remote access to infected devices.

IcedID: New variants spread malware

IcedID is generally used for initial access by hackers, so the development of new variants is a worrying sign, signifying a shift towards the bot's specialization in cargo delivery.

Read also: Emotet malware: Distributed in Microsoft OneNote files

Proofpoint predicts that most hackers will continue to use the “Standard” variant, but the development of new IcedID versions will likely increase and more variants may appear later in 2023.

source of information:bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS