The malware Dridex: origins and uses
ID: c944f6ca-b8df-4ba4-9ce7-96db6e83b28f
STIX ID: report--c944f6ca-b8df-4ba4-9ce7-96db6e83b28f
Threat Score
80/100
Uploaded: 2026-07-30
Published Date: 2026-07-30
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:A1
...
...
**Executive summary:** This ANSSI report provides a comprehensive analysis of the Dridex banking trojan—its evolution, modular capabilities (loader, core, VNC, SOCKS, Pony, Kill OS, etc.), P2P botnet architecture, and the criminal group Evil Corp and affiliates that operate and distribute it—while detailing distribution methods (phishing, Emotet, exploit kits, FakeUpdates), associated ransomware (BitPaymer/DoppelPaymer), and a large set of IOCs and detection recommendations.
