LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0483: IcedID

IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017. IcedID has been downloaded by Emotet in multiple campaigns.CitationIBM IcedID November 2017CitationJuniper IcedID June 2020

EnterpriseS0483MalwareObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

IcedID matters because ATT&CK describes it as modular Windows banking malware built to steal financial information and associated with follow-on malware distribution relationships. For leaders, the practical issue is not just “banking malware”; it is whether the organization can detect a Windows endpoint compromise that blends web traffic, discovery, persistence, obfuscation, browser session abuse, and data exfiltration behaviors before it becomes a broader incident.

Executive priority

Prioritize IcedID-relevant readiness where Windows endpoints handle financial workflows, privileged access, or sensitive browser-based sessions. Ask whether SOC, IR, and audit teams can prove visibility into endpoint execution, scheduled tasks, WMI activity, process injection indicators, account and network discovery, web-based command-and-control, and encrypted exfiltration patterns. Because ATT&CK provides no official detection text for this malware, coverage should be validated through the related techniques rather than assumed from malware naming alone.

Technical view

ATT&CK lists IcedID on Windows and relates it to techniques spanning initial access, execution, persistence, privilege escalation, defense evasion, discovery, collection, command-and-control, ingress tool transfer, and exfiltration. Detection engineering should map coverage to the specific relationships: drive-by compromise, Visual Basic execution, WMI, Native API use, scheduled tasks, process hollowing/APC injection, packed or encoded payloads, legitimate-looking resource names or locations, domain/account/share/system/network discovery, browser session hijacking, web protocols, tool transfer, and asymmetric encrypted non-C2 exfiltration. Treat IcedID as a behavior cluster: endpoint, identity, browser, and network telemetry must be correlated rather than relying on static signatures alone.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • Scheduled task creation, modification, and execution logs
  • WMI activity and remote/local management events
  • Endpoint detection telemetry for process injection, process hollowing, APC-style injection, and unusual Native API behavior
  • File creation and execution telemetry for packed, encoded, embedded, or misleadingly named payloads

Detection direction

  • Validate ATT&CK technique coverage rather than depending on an IcedID signature, since official detection guidance is not provided.
  • Tune detections for suspicious chains: script or Visual Basic execution leading to WMI, scheduled task creation, discovery commands, browser interaction, network callbacks, or tool transfer.
  • Correlate endpoint and network signals; web protocols can blend with normal traffic, and encrypted exfiltration may not expose content inspection opportunities.
  • Review false positives around legitimate administration: WMI, scheduled tasks, Native API-heavy software, and domain/share discovery can be normal in managed Windows environments.
  • Look for defense-evasion context such as software packing, encoded files, embedded payloads, process injection, and legitimate-looking names or locations.

Mitigation priorities

  • Ensure Windows endpoint protection and logging are configured to retain process, file, scheduled task, WMI, and injection-relevant telemetry.
  • Harden browser and endpoint controls around financial and privileged workflows, including restrictions on unauthorized script execution and suspicious downloaded content.
  • Limit unnecessary local administrative capability and monitor identity discovery against domain accounts and permission groups.
  • Control and monitor outbound web traffic and encrypted egress, with attention to unusual destinations, tool downloads, and data movement patterns.
  • Prepare IR playbooks for modular malware incidents: isolate affected Windows hosts, preserve volatile and endpoint evidence, review account/session exposure, and inspect for follow-on tools or persistence.
Additional notes and limits

The supplied ATT&CK object identifies IcedID as modular banking malware observed since at least 2017 and notes that Emotet downloaded it in multiple campaigns. Relationships also connect it to TA551, TA578, Water Curupira Pikabot Distribution, and multiple ATT&CK techniques. The most defensible operational use is to validate coverage against those related behaviors on Windows rather than infer a single detection strategy.

Official ATT&CK detection text is not provided, tactics are not specified directly on the malware object, aliases are not supplied, and relationship descriptions are partly sparse or truncated. This take does not assert current activity, attribution beyond supplied relationships, guaranteed detection, or exposure in any specific environment. Local telemetry, asset criticality, and incident evidence are required to determine risk and response priority.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

IcedID

IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017. IcedID has been downloaded by Emotet in multiple campaigns.CitationIBM IcedID November 2017CitationJuniper IcedID June 2020

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
362532594b1e1809...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.