LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0384: Dridex

MITRE ATT&CK S0384: Dridex Malware details for Windows, with detection guidance, relationships and mapped CVEs.

EnterpriseS0384MalwareObject v2.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Dridex matters because it represents mature Windows banking Trojan tradecraft with documented large-scale financial harm. For leaders, the key lesson is not only “malware on endpoints,” but whether the organization can detect and respond to credential/session theft, suspicious browser activity, encrypted web-based command-and-control, persistence through scheduled tasks, and abuse of legitimate Windows components before fraud or follow-on intrusion decisions escalate.

Executive priority

Prioritize Dridex-informed readiness where financial transactions, privileged browser sessions, and Windows endpoint integrity are business-critical. The ATT&CK record ties Dridex to banking theft at global scale and relationships with cybercriminal groups including TA505 and Indrik Spider; this supports using it as a control-validation scenario for SOC visibility, incident response playbooks, fraud response coordination, and audit evidence around endpoint monitoring, web traffic inspection, and identity/session protection.

Technical view

ATT&CK does not provide a dedicated detection section for Dridex, so defenders should validate coverage through the techniques linked to this malware. On Windows, focus on user-executed malicious files, scheduled task creation or modification, Regsvr32 proxy execution, DLL abuse, native API-driven execution patterns, browser session hijacking indicators, system and software discovery, and command-and-control over web protocols, proxies, multi-hop proxy behavior, and encrypted C2 using symmetric or asymmetric cryptography. Relationship context also supports monitoring for legitimate remote access tools used as command-and-control channels, while avoiding assumptions that any single RAT or web session is malicious without surrounding endpoint and network evidence.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • Scheduled Task creation, modification, and execution records
  • Regsvr32 execution and module/DLL load telemetry
  • File creation, script/document execution, and malware quarantine events related to user-opened files
  • Browser process behavior, injected modules, unusual session or web request activity

Detection direction

  • Build detections around behavior chains rather than a Dridex name match: malicious file execution followed by discovery, persistence, browser interaction, and outbound web/proxy C2 is more decision-useful than any single event.
  • Tune scheduled task and Regsvr32 detections for administrative noise; prioritize unusual parent processes, user context, unsigned or unexpected DLL paths, and newly created tasks on workstations.
  • Validate that encrypted web traffic and proxy logs are retained with enough metadata to support triage, since ATT&CK links Dridex to web protocols, proxies, and cryptographic C2 techniques.
  • Review browser-session and financial-application monitoring assumptions; browser session hijacking can reduce the value of password-only controls and may require endpoint context to investigate.
  • Use the TA505 and Indrik Spider relationships as threat-intelligence context for campaign triage, but do not treat group association alone as attribution without incident-specific evidence.

Mitigation priorities

  • Reduce successful initial execution by hardening handling of user-opened files and enforcing email/web controls appropriate to malicious file risk.
  • Strengthen Windows endpoint controls around scheduled tasks, Regsvr32 abuse, DLL loading paths, and unauthorized remote access tools.
  • Improve identity and session protection for high-risk financial and administrative workflows, including rapid response procedures for suspected browser/session compromise.
  • Ensure SOC and IR teams can correlate endpoint, browser, proxy, DNS, and HTTP/S telemetry for a single Windows host and user.
  • Maintain tested playbooks for suspected banking Trojan activity that include containment, credential/session review, fraud-response escalation, and evidence preservation.
Additional notes and limits

The supplied ATT&CK object identifies Dridex as a prolific banking Trojan first appearing in 2014, derived from Bugat/Cridex source code, with U.S. Treasury reporting more than $100 million in theft and infections across banks and financial institutions in more than 40 countries by December 2019. ATT&CK relationships provide the most useful defensive detail: Dridex is linked to multiple execution, persistence, discovery, stealth, collection, and command-and-control techniques, and is used by TA505 and Indrik Spider according to the supplied relationship context.

ATT&CK provides no official detection text for this object, and the object-level tactics are not specified. The platform field supports Windows for Dridex, while some related techniques list broader platforms that should not be assumed applicable to this malware without local evidence. Defensive priorities should be validated against the organization’s actual Windows estate, logging coverage, financial workflows, and incident history.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Dridex

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

15 rows
DomainIDNameRelationship / procedure
EnterpriseT1573.001Symmetric CryptographySub-techniqueThis object uses Symmetric Cryptography.
EnterpriseT1574.001DLLSub-techniqueThis object uses DLL.
EnterpriseT1219Remote Access ToolsThis object uses Remote Access Tools.
EnterpriseT1106Native APIThis object uses Native API.
EnterpriseT1053.005Scheduled TaskSub-techniqueThis object uses Scheduled Task.
EnterpriseT1185Browser Session HijackingThis object uses Browser Session Hijacking.
EnterpriseT1518Software DiscoveryThis object uses Software Discovery.
EnterpriseT1071.001Web ProtocolsSub-techniqueThis object uses Web Protocols.
EnterpriseT1218.010Regsvr32Sub-techniqueThis object uses Regsvr32.
EnterpriseT1573.002Asymmetric CryptographySub-techniqueThis object uses Asymmetric Cryptography.
EnterpriseT1027Obfuscated Files or InformationThis object uses Obfuscated Files or Information.
EnterpriseT1090ProxyThis object uses Proxy.
EnterpriseT1082System Information DiscoveryThis object uses System Information Discovery.
EnterpriseT1090.003Multi-hop ProxySub-techniqueThis object uses Multi-hop Proxy.
EnterpriseT1204.002Malicious FileSub-techniqueThis object uses Malicious File.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0092: TA505

TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.[1][2][3][4][5]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.1
Created
Modified
Raw hash
0eceead1d6aaf0fe...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.1Current bundle0eceead1d6aa…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Dell Dridex Oct 2015

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, October 13). Dridex (Bugat v5) Botnet Takeover Operation. Retrieved May 31, 2019.

    Open source URL
  2. [2]
    Kaspersky Dridex May 2017

    Slepogin, N. (2017, May 25). Dridex: A History of Evolution. Retrieved May 31, 2019.

    Open source URL
  3. [3]
    Treasury EvilCorp Dec 2019

    U.S. Department of Treasury. (2019, December 5). Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware. Retrieved September 15, 2021.

    Open source URL
  4. [4]
    Red Canary Dridex Threat Report 2021

    Red Canary. (2021, February 9). Dridex - Red Canary Threat Detection Report. Retrieved August 3, 2023.

    Open source URL
  5. [5]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  6. [6]
    Proofpoint TA505 Sep 2017

    Proofpoint Staff. (2017, September 27). Threat Actor Profile: TA505, From Dridex to GlobeImposter. Retrieved May 28, 2019.

    Open source URL
  7. [7]
    Proofpoint TA505 June 2018

    Proofpoint Staff. (2018, June 8). TA505 shifts with the times. Retrieved May 28, 2019.

    Open source URL
  8. [8]
    IBM TA505 April 2020

    Frydrych, M. (2020, April 14). TA505 Continues to Infect Networks With SDBbot RAT. Retrieved May 29, 2020.

    Open source URL
  9. [9]
    Crowdstrike Indrik November 2018

    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

    Open source URL
  10. [10]
    Crowdstrike EvilCorp March 2021

    Podlosky, A., Feeley, B. (2021, March 17). INDRIK SPIDER Supersedes WastedLocker with Hades Ransomware to Circumvent OFAC Sanctions. Retrieved September 15, 2021.

    Open source URL
  11. [11]
    Bugat v5

    (Citation: Dell Dridex Oct 2015)

  12. [12]
    Bugat v5

    (Citation: Dell Dridex Oct 2015)

  13. [13]
    Bugat v5

    (Citation: Dell Dridex Oct 2015)

  14. [14]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  15. [15]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  16. [16]
    Dell Dridex Oct 2015

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, October 13). Dridex (Bugat v5) Botnet Takeover Operation. Retrieved May 31, 2019.

    Open source URL
  17. [17]
    Dell Dridex Oct 2015

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, October 13). Dridex (Bugat v5) Botnet Takeover Operation. Retrieved May 31, 2019.

    Open source URL
  18. [18]
    Dridex

    (Citation: Dell Dridex Oct 2015)(Citation: Kaspersky Dridex May 2017)(Citation: Checkpoint Dridex Jan 2021)

  19. [19]
    Dridex

    (Citation: Dell Dridex Oct 2015)(Citation: Kaspersky Dridex May 2017)(Citation: Checkpoint Dridex Jan 2021)

  20. [20]
    Dridex

    (Citation: Dell Dridex Oct 2015)(Citation: Kaspersky Dridex May 2017)(Citation: Checkpoint Dridex Jan 2021)

  21. [21]
    Kaspersky Dridex May 2017

    Slepogin, N. (2017, May 25). Dridex: A History of Evolution. Retrieved May 31, 2019.

    Open source URL
  22. [22]
    Kaspersky Dridex May 2017

    Slepogin, N. (2017, May 25). Dridex: A History of Evolution. Retrieved May 31, 2019.

    Open source URL
  23. [23]
    Treasury EvilCorp Dec 2019

    U.S. Department of Treasury. (2019, December 5). Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware. Retrieved September 15, 2021.

    Open source URL
  24. [24]
    Treasury EvilCorp Dec 2019

    U.S. Department of Treasury. (2019, December 5). Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware. Retrieved September 15, 2021.

    Open source URL
  25. [25]
    mitre-attackS0384
    Open source URL
  26. [26]
    mitre-attackS0384
    Open source URL
  27. [27]
    mitre-attackS0384
    Open source URL
  28. [28]
    Kaspersky Dridex May 2017

    Slepogin, N. (2017, May 25). Dridex: A History of Evolution. Retrieved May 31, 2019.

    Open source URL
  29. [29]
    Kaspersky Dridex May 2017

    Slepogin, N. (2017, May 25). Dridex: A History of Evolution. Retrieved May 31, 2019.

    Open source URL
  30. [30]
    Red Canary Dridex Threat Report 2021

    Red Canary. (2021, February 9). Dridex - Red Canary Threat Detection Report. Retrieved August 3, 2023.

    Open source URL
  31. [31]
    Dell Dridex Oct 2015

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, October 13). Dridex (Bugat v5) Botnet Takeover Operation. Retrieved May 31, 2019.

    Open source URL
  32. [32]
    Dell Dridex Oct 2015

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, October 13). Dridex (Bugat v5) Botnet Takeover Operation. Retrieved May 31, 2019.

    Open source URL
  33. [33]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  34. [34]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  35. [35]
    IBM TA505 April 2020

    Frydrych, M. (2020, April 14). TA505 Continues to Infect Networks With SDBbot RAT. Retrieved May 29, 2020.

    Open source URL
  36. [36]
    Proofpoint TA505 June 2018

    Proofpoint Staff. (2018, June 8). TA505 shifts with the times. Retrieved May 28, 2019.

    Open source URL
  37. [37]
    Proofpoint TA505 Sep 2017

    Proofpoint Staff. (2017, September 27). Threat Actor Profile: TA505, From Dridex to GlobeImposter. Retrieved May 28, 2019.

    Open source URL
  38. [38]
    Red Canary Dridex Threat Report 2021

    Red Canary. (2021, February 9). Dridex - Red Canary Threat Detection Report. Retrieved August 3, 2023.

    Open source URL
  39. [39]
    Red Canary Dridex Threat Report 2021

    Red Canary. (2021, February 9). Dridex - Red Canary Threat Detection Report. Retrieved August 3, 2023.

    Open source URL
  40. [40]
    Dell Dridex Oct 2015

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, October 13). Dridex (Bugat v5) Botnet Takeover Operation. Retrieved May 31, 2019.

    Open source URL
  41. [41]
    Dell Dridex Oct 2015

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, October 13). Dridex (Bugat v5) Botnet Takeover Operation. Retrieved May 31, 2019.

    Open source URL
  42. [42]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  43. [43]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  44. [44]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  45. [45]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  46. [46]
    Kaspersky Dridex May 2017

    Slepogin, N. (2017, May 25). Dridex: A History of Evolution. Retrieved May 31, 2019.

    Open source URL
  47. [47]
    Kaspersky Dridex May 2017

    Slepogin, N. (2017, May 25). Dridex: A History of Evolution. Retrieved May 31, 2019.

    Open source URL
  48. [48]
    Red Canary Dridex Threat Report 2021

    Red Canary. (2021, February 9). Dridex - Red Canary Threat Detection Report. Retrieved August 3, 2023.

    Open source URL
  49. [49]
    Red Canary Dridex Threat Report 2021

    Red Canary. (2021, February 9). Dridex - Red Canary Threat Detection Report. Retrieved August 3, 2023.

    Open source URL
  50. [50]
    Kaspersky Dridex May 2017

    Slepogin, N. (2017, May 25). Dridex: A History of Evolution. Retrieved May 31, 2019.

    Open source URL
  51. [51]
    Kaspersky Dridex May 2017

    Slepogin, N. (2017, May 25). Dridex: A History of Evolution. Retrieved May 31, 2019.

    Open source URL
  52. [52]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  53. [53]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  54. [54]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  55. [55]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  56. [56]
    Dell Dridex Oct 2015

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, October 13). Dridex (Bugat v5) Botnet Takeover Operation. Retrieved May 31, 2019.

    Open source URL
  57. [57]
    Dell Dridex Oct 2015

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, October 13). Dridex (Bugat v5) Botnet Takeover Operation. Retrieved May 31, 2019.

    Open source URL
  58. [58]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  59. [59]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  60. [60]
    Crowdstrike EvilCorp March 2021

    Podlosky, A., Feeley, B. (2021, March 17). INDRIK SPIDER Supersedes WastedLocker with Hades Ransomware to Circumvent OFAC Sanctions. Retrieved September 15, 2021.

    Open source URL
  61. [61]
    Crowdstrike Indrik November 2018

    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

    Open source URL
  62. [62]
    Treasury EvilCorp Dec 2019

    U.S. Department of Treasury. (2019, December 5). Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware. Retrieved September 15, 2021.

    Open source URL
  63. [63]
    Treasury EvilCorp Dec 2019

    U.S. Department of Treasury. (2019, December 5). Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware. Retrieved September 15, 2021.

    Open source URL
  64. [64]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
  65. [65]
    Checkpoint Dridex Jan 2021

    Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.