New IcedID variants have been found without the usual banking fraud functionality. Instead, they appear to be aimed at installing additional malware on infected devices.

According to Proofpoint, these new variants have been used by three separate hackers in seven campaigns since last year, focusing on sending additional payloads, specifically ransomware.
Proofpoint has identified two new versions of the IcedID loader, named “Lite” and “Forked,” both of which ship the same IcedID bot with a more focused set of features.
By removing unnecessary functionality from IcedID, which has been used in numerous campaigns without its code having changed since 2017, it makes it quieter and leaner, thus allowing hackers to avoid detection.

See also: IcedID Banking Trojan: New variant distributed via spam emails
New IcedID campaign
Since November 2022, the “Lite” version of the IcedID loader has been sent as a second part of the payload to systems infected with the well-known Emote malware.
The “Forked” version of the loader first appeared in February 2023, infecting directly via invoice phishing emails.
These messages used the Microsoft OneNote (.one) extension to execute a malicious HTA file that ran PowerShell commands that remotely pulled IcedID. At the same time, the victim was viewing a PDF as a distraction.

In late February, Proofpoint researchers observed a low-volume campaign distributing IcedID “Forked” via fake alerts from the National Highway Traffic Safety Administration and the U.S. Food and Drug Administration (FDA).
It is important to note that while some hackers are using new variants of the IcedID malware, others still choose to use the “Standard” variant, with one of the most recent campaigns dating back to March 10, 2023.
The new variations
The “Forked” IcedID loader is quite similar to the “Standard” version in terms of its role, sending basic host information to the C2 and then retrieving the IcedID bot.
However, “Forked” uses a different file type (COM Server) and has additional domain and string decryption code, making the payload 12KB larger than the “Standard” version.

Suggestion:IcedID malware: Hackers are testing new distribution methods
On the other hand, the loader of the “Lite” variant is lighter, at 20KB, and does not pass host information to the C2. This change makes sense, given that it was developed alongside Emotet, which had already profiled the compromised system.
The “Forked” version of the IcedID bot is 64KB smaller than the “Standard” bot and is essentially the same malware minus the web injection system, AiTM features, and backconnect capabilities that give hackers remote access to infected devices.

IcedID is generally used for initial access by hackers, so the development of new variants is a worrying sign, signifying a shift towards the bot's specialization in cargo delivery.
Read also: Emotet malware: Distributed in Microsoft OneNote files
Proofpoint predicts that most hackers will continue to use the “Standard” variant, but the development of new IcedID versions will likely increase and more variants may appear later in 2023.
source of information:bleepingcomputer.com
