Following the takedown of Emotet, a hole was left in the malspam-as-a-service cybercrime ecosystem. IcedID, a well-known banking trojan used by multiple distinct threat groups, now seems primed to fill that hole after stepping up the volume of distribution using its variety of affiliates, as originally reported by TheRecord. Using a variety of lures/distribution tactics including:
- Excel 4.0 XLM sheets
- Password-protected zip files to bypass email filters
- Public contact forms to send email and trick corporate employees into installing malware
- Unauthorized modifications of the Zoom video-conferencing app that include malware