You are here

Threat Awareness – IcedID Banking Trojan Changes Strategy to Zoom Phishing Sites

Threat Awareness – IcedID Banking Trojan Changes Strategy to Zoom Phishing Sites

Created: Tuesday, January 10, 2023 - 13:21

Cyble has posted a blog discussing its analysis of a recently discovered phishing campaign targeting Zoom in order to deliver IcedID malware, also known as BokBot. This malware is a banking trojan whose purpose is to steal banking credentials from victims. IcedID also functions as a loader capable of downloading further malware (including ransomware) and is commonly associated with the Emotet botnet. IcedID has been observed traditionally targeting businesses to steal payment information using compromised Office attachments. However, this latest campaign is instead composed of a phishing webpage designed to look like the Zoom website, more specifically the software download page. The blog provides further technical analysis and indicators of compromise (IoCs) to detect relevant activity. Read more at Cyble here.

Additional Resources on IcedID