Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    IcedID Banking Trojan Redirects Users to Fake Sites, IBM Reports

    Written by

    Sean Michael Kerner
    Published November 13, 2017
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The IBM X-Force research team has discovered a new banking Trojan, dubbed “IcedID,” that is taking aim at global financial institutions.

      The IcedID Trojan relies on the Emotet malware dropper to exploit a victim’s system. IcedID then provides the Trojan payload, redirecting victims to an attacker site that is a replica of a real banking website. The IcedID Trojan attack has targeted banks, payment card providers and e-commerce sites in the United States, Canada and the UK.

      “IBM X-Force monitors close to 300 million protected endpoints across the globe, detecting and mapping threat evolution close to real time,” Limor Kessem, executive security adviser at IBM Security, told eWEEK. “X-Force research detected and analyzed IcedID as soon as it was identified in attempts to infect end users.”

      It’s not clear how many victims IcedID has claimed or how widespread the distribution of the Trojan is. Kessem said X-Force detected IcedID very early after its launch, and so far the campaigns are still small, with the number of infections being limited. 

      By using the Emotet dropper as a distribution mechanism, IcedID’s authors have attempted to keep the malware under the radar, Kessem noted, adding that Emotet itself is usually delivered via malware spam (malspam), often concealed in productivity file attachments.

      “After the user is first infected with Emotet, the latter is used as a covert tunnel through which other malware is delivered and executed on the endpoint,” she said. “Aside from newly dropping IcedID, Emotet is known for its connection with a variety of malicious codes, most recently the QakBot banking Trojan that targets business banking in North America.”

      Redirection

      Among IcedID’s core capabilities is it redirects victims to an attacker-controlled site. Instead of using web injections on a bank’s site, IcedID takes a victim to a page it serves from its own server and can communicate with the victim there, away from the bank’s control. Kessem said the redirection pages are often difficult for regular users to identify.

      “Redirection attacks are malware-facilitated operations in which the bank’s genuine site is an unwilling participant,” she said. “The malware keeps a live connection to the genuine site and manipulates the fake session in a way that has it present the bank’s true URL in the address bar.”

      IcedID does not directly exploit user systems; it is delivered into an already compromised endpoint that was first exploited by the Emotet dropper.

      “To gain the initial foothold, Emotet uses malicious JavaScript in file macros in order to invoke a PowerShell script to fetch the payload from a remote server,” Kessem said. “This process is initiated by unwitting users who are tricked into opening email attachments that carry concealed malcode.”

      Although IcedID uses tactics used in other banking Trojans, according to IBM X-Force’s analysis, IcedID is custom code. It’s not clear where IcedID came from or who wrote the code. Kessem warned that when it comes to cyber-crime activity, attribution is often a tricky concept as malware can be operated by different groups or subgroups, or be sold and shared. That said, IBM X-Force researchers do have some suspicions.

      “According to an analysis of IcedID’s infrastructure, the malware’s main servers are hosted in Russia,” Kessem said. “Judging by the company it keeps, IcedID is delivered by the same group that delivers QakBot and Dridex, both of which are also known to come from Russian-speaking regions.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.