Dridex

Category: banking_trojan · Aliases: bugat, cridex, feodo · Sample count (EMBER 2018): 59 · Enrichment: hand-curated · Updated: 2026-05-27

Overview

Dridex is a major banking trojan that emerged in 2014 as a successor to Cridex and Bugat, primarily targeting banking credentials and corporate email. It is operated by the Evil Corp threat actor group, which has been under US Treasury sanctions since 2019. Dridex spreads through phishing campaigns with malicious Office documents and has been used as a precursor for BitPaymer and DoppelPaymer ransomware deployment in big-game-hunting operations.

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1566.001 T1185 T1071.001

Authoritative Advisory

CISA has published an advisory on this family: https://www.cisa.gov/news-events/alerts/2019/12/13/dridex-malware

Frequently Asked Questions

What is Dridex?

Dridex is a major banking trojan that emerged in 2014 as a successor to Cridex and Bugat, primarily targeting banking credentials and corporate email. It is operated by the Evil Corp threat actor group, which has been under US Treasury sanctions since 2019. Dridex spreads through phishing campaigns with malicious Office documents and has been used as a precursor for BitPaymer and DoppelPaymer ransomware deployment in big-game-hunting operations.

How does Dridex spread?

Dridex spreads through phishing emails with malicious Office macro documents, with later variants using Excel 4.0 macros and DLL sideloading techniques.

What are the signs of a Dridex infection?

Browser injection prompts on banking sites, scheduled tasks with random names, outbound connections to compromised WordPress sites used as C2, and AV alerts for Dridex, Bugat, or Cridex are signature indicators.

What should I do if I think I have Dridex on my system?

If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/dridex.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.