WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Threat Awareness – IcedID Banking Trojan Changes Strategy to Zoom Phishing Sites
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – IcedID Banking Trojan Changes Strategy to Zoom Phishing Sites

Author: April Zupan

Created: Tuesday, January 10, 2023 - 18:21

Categories: Cybersecurity

Cyble has posted a blog discussing its analysis of a recently discovered phishing campaign targeting Zoom in order to deliver IcedID malware, also known as BokBot. This malware is a banking trojan whose purpose is to steal banking credentials from victims. IcedID also functions as a loader capable of downloading further malware (including ransomware) and is commonly associated with the Emotet botnet. IcedID has been observed traditionally targeting businesses to steal payment information using compromised Office attachments. However, this latest campaign is instead composed of a phishing webpage designed to look like the Zoom website, more specifically the software download page. The blog provides further technical analysis and indicators of compromise (IoCs) to detect relevant activity. Read more at Cyble here.

Additional Resources on IcedID

  • FBI FLASH: Indicators of Compromise Associated with IcedID (WaterISAC)
  • Security Primer – IcedID (Center for Internet Security)
  • IcedID Botnet Distributors Abuse Google PPC to Distribute Malware (TrendMicro)
  • More Than Meets the Eye: Exposing a Polyglot File That Delivers IcedID (Unit 42)
  • Spoofed Invoice Used to Drop IcedID (Fortinet)

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar