Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - IcedID,, The New Banking Trojan To Watch Out For
News & Analysis

IcedID,, The New Banking Trojan To Watch Out For

ISBuzz TeamBy ISBuzz TeamNovember 17, 2017Updated:December 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

News broke overnight of a new banking trojan, discovered by security experts and christened IcedID. The trojan appears to still be in its development stages, but has been reportedly targeting financial institutions in the United States and Canada, as well as two in the UK. IT security experts are commented below.

Andy Norton, Director of Threat Intelligence at Lastline: 

“IcedID is yet another raising of the bar by criminal groups to produce new and improved malware this time focused on stealing identity and financial data.

So far, the security industry has responded with a very generic classification of IceID often labelling it Emotet or simply “generic.torjan”. However, this won’t help in correct and appropriate incident response. Those organisations with a deployed Malware Analysis platform at the heart of their Cyber security infrastructure will see the common behaviours of Stealing Operating System and email passwords.

For those organisations without advanced protection, the samples we have studied connect it to:

medicalciferol(dot)com

Kapork(dot)net

Both domains were registered in Hong Kong by (first name)Capitalinitial(last name)@pokemail.net addresses, and have common DNS.”

Tertius Wessels, Product Manager at Entersekt:

“Although many of us know better than to open untrusted email attachments, the reality is that we’re often not careful all the time. This is one example of how the Trojan IcedID can find its way onto a customer’s computer and allow a fraudster to take control of, for example, an online banking session.

Malware such as IcedID exploit vulnerabilities in many authentication methods – including multi-factor authentication methods. When a customer has to enter sensitive information such as a PIN or one-time password into the same channel where they had logged in to their online banking platform or initiated a payment, for example, it enables a fraudster listening in on or tracking that channel to capture the sensitive information.

The importance of using an out-of-band channel for communications between banks and customers cannot be stressed enough. In an approach where a separate, secured and encrypted channel is established between the bank and the customer’s uniquely identified and verified mobile phone, for example, a fraudster will not receive authentication requests pushed to the customer’s mobile device. So even if the fraudster could gain access to a customer’s online or mobile banking platform, they would not be able to complete any sensitive transactions.”

Lee Munson, Security Researcher at Comparitech.com:

“As the new kid on the block, IcedID already exhibits signs that it may become one of the more potent banking Trojans around, potentially causing a massive headache for financial institutions, businesses and individuals alike.

Given its additional ability of being able to monitor a victim’s online activities, it represents a number of different threats beyond the obvious pure financial one, namely the theft of identities and the invasion of privacy.

Therefore, financial companies will need to ensure that their technical defences are sound, companies will need to consider perimeter security as well as segregation, given this Trojan’s ability to spread, and individuals will need to stay on top of multi-factor authentication when connecting to their online banking sessions, as well as remaining vigilant when checking bank and credit card statements.”

Craig Stewart, VP EMEA at Venafi:

“IcedID spreading throughout the networks of banks, payment providers and ecommerce sites across the US and is yet another way for hackers to get people running or connecting to malicious websites so they can commit fraud. Worse still, it’s already spreading, with researchers reporting that two UK banks have also been impacted so far.

Companies have a responsibility to protect customers against this sort of attack yet without visibility over the machine identities that control their websites, servers and other machines they have no way of knowing which machines have already been infected. It’s this uncertainty which allows malware like IcedID to continue its attack so easily. IcedID imitates previous Trojans like Dridex because this approach works. These attacks will continue to occur unless banks and other organisations put in place proper defences around their machine identities and the first step is to simply get a handle on what they’ve got. Until banks have full control of all the certificates on every devices, operating systems and applications in place, they won’t be secure. Having this oversight in place is a major step in ensuring malware like IcedID is unable to move between endpoints, as organisations will have the visibility and tools to protect keys and certificates from attackers.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}