logo

The malware Dridex: origins and uses

ID: c944f6ca-b8df-4ba4-9ce7-96db6e83b28f

STIX ID: report--c944f6ca-b8df-4ba4-9ce7-96db6e83b28f

Threat Score

80/100

Uploaded: 2026-07-30

Published Date: 2026-07-30

Last Modified Date: 2026-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:A1
...
...
**Executive summary:** This ANSSI report provides a comprehensive analysis of the Dridex banking trojan—its evolution, modular capabilities (loader, core, VNC, SOCKS, Pony, Kill OS, etc.), P2P botnet architecture, and the criminal group Evil Corp and affiliates that operate and distribute it—while detailing distribution methods (phishing, Emotet, exploit kits, FakeUpdates), associated ransomware (BitPaymer/DoppelPaymer), and a large set of IOCs and detection recommendations.