Threat Intelligence Tarot
pentacles · 12
Criminal (Eastern European)
G0099★★★★★
risk 4/5
✦ The Frozen Account ✦
IcedID / Bokbot
Bokbot · Gold Swathmore
BanksUS financial sectorHealthcareGlobal enterprise
Active since ~2017 · Banking credential theft, Loader-as-a-service for ransomware, Financial fraud
IcedID began as a banking trojan and became something more valuable: a loader. It gets in, establishes persistence, and rents the access to ransomware operators. The Frozen Account does not care what gets delivered - it cares about the delivery. Access-as-a-service at enterprise scale.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆Banking trojan affecting 100+ financial institutions globally
- ◆Loader for Quantum, BlackCat, and Conti ransomware
- ◆US DoJ charges against IcedID operators (2023)
- ◆Evolved from banking trojan to ransomware delivery platform
Defenses
- ▸Email sandboxing and macro execution controlsCIS Control 9 ↗
- ▸Banking credential monitoring and anomalous transaction detectionNIST CSF: DE.AE ↗
- ▸Network monitoring for IcedID C2 traffic patternsNIST CSF: DE.CM ↗
- ▸Endpoint detection for IcedID loader behaviorCIS Control 10 ↗
Reversed: Their Weakness
IcedID's evolution from banking trojan to ransomware loader reflects the maturing criminal ecosystem - operators who built a reliable infection mechanism found more value in the delivery business than the theft business, allowing law enforcement to target them through their ransomware affiliates.
Share this adversary profile
Compare →swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.