WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Threat Awareness – IcedID Banking Trojan Changes Strategy to Zoom Phishing Sites
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – IcedID Banking Trojan Changes Strategy to Zoom Phishing Sites

Author: April Zupan

Created: Tuesday, January 10, 2023 - 18:21

Categories: Cybersecurity

Cyble has posted a blog discussing its analysis of a recently discovered phishing campaign targeting Zoom in order to deliver IcedID malware, also known as BokBot. This malware is a banking trojan whose purpose is to steal banking credentials from victims. IcedID also functions as a loader capable of downloading further malware (including ransomware) and is commonly associated with the Emotet botnet. IcedID has been observed traditionally targeting businesses to steal payment information using compromised Office attachments. However, this latest campaign is instead composed of a phishing webpage designed to look like the Zoom website, more specifically the software download page. The blog provides further technical analysis and indicators of compromise (IoCs) to detect relevant activity. Read more at Cyble here.

Additional Resources on IcedID

  • FBI FLASH: Indicators of Compromise Associated with IcedID (WaterISAC)
  • Security Primer – IcedID (Center for Internet Security)
  • IcedID Botnet Distributors Abuse Google PPC to Distribute Malware (TrendMicro)
  • More Than Meets the Eye: Exposing a Polyglot File That Delivers IcedID (Unit 42)
  • Spoofed Invoice Used to Drop IcedID (Fortinet)

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar