IcedID Malware Strikes Again: Active Directory Domain Compromised in Under 24 Hours
Jan 12, 2023
Active Directory / Malware
A recent IcedID malware attack enabled the threat actor to compromise the Active Directory domain of an unnamed target less than 24 hours after gaining initial access, while also borrowing techniques from other groups like Conti to meet its goals. "Throughout the attack, the attacker followed a routine of recon commands, credential theft, lateral movement by abusing Windows protocols, and executing Cobalt Strike on the newly compromised host," Cybereason researchers said in a report published this week. IcedID , also known by the name BokBot, started its life as a banking trojan in 2017 before evolving into a dropper for other malware , joining the likes of Emotet , TrickBot , Qakbot , Bumblebee , and Raspberry Robin . Attacks involving the delivery of IcedID have leveraged a variety of methods , especially in the wake of Microsoft's decision to block macros from Office files downloaded from the web. The intrusion d...