Threat Intelligence Tarot
pentacles · 12
Criminal (Eastern European)
G0099★★★★★
risk 4/5
✦ The Frozen Account ✦
IcedID / Bokbot
Bokbot · Gold Swathmore
BanksUS financial sectorHealthcareGlobal enterprise
Active since ~2017 · Banking credential theft, Loader-as-a-service for ransomware, Financial fraud
IcedID began as a banking trojan and became something more valuable: a loader. It gets in, establishes persistence, and rents the access to ransomware operators. The Frozen Account does not care what gets delivered - it cares about the delivery. Access-as-a-service at enterprise scale.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆Banking trojan affecting 100+ financial institutions globally
- ◆Loader for Quantum, BlackCat, and Conti ransomware
- ◆US DoJ charges against IcedID operators (2023)
- ◆Evolved from banking trojan to ransomware delivery platform
Defenses
- ▸Email sandboxing and macro execution controlsCIS Control 9 ↗
- ▸Banking credential monitoring and anomalous transaction detectionNIST CSF: DE.AE ↗
- ▸Network monitoring for IcedID C2 traffic patternsNIST CSF: DE.CM ↗
- ▸Endpoint detection for IcedID loader behaviorCIS Control 10 ↗
Reversed: Their Weakness
IcedID's evolution from banking trojan to ransomware loader reflects the maturing criminal ecosystem - operators who built a reliable infection mechanism found more value in the delivery business than the theft business, allowing law enforcement to target them through their ransomware affiliates.
Share this adversary profile
swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.