IceEvent
Malware⚠️ Overview
IceEvent is a modular information stealer and remote access trojan (RAT) first documented in July 2023 by Trend Micro’s Threat Intelligence team. The malware is operated by a financially motivated threat cluster tracked as TA578, which distributes IceEvent through malicious Microsoft Word attachments and fake software installers. It primarily targets cryptocurrency users and corporate email accounts, leveraging Telegram for C2 communication.
🔧 Technical Capabilities
IceEvent uses macro‑enabled Office documents as its primary initial access vector, exploiting CVE‑2021‑40444 (MSHTML remote code execution) to drop the payload without user interaction. Once executed, the malware performs process hollowing (MITRE ATT&CK T1055.012) into legitimate Windows processes such as svchost.exe or explorer.exe to evade detection. It establishes persistence via a scheduled task (MITRE T1053.005) that launches a PowerShell script at user logon. The C2 infrastructure relies on Telegram bots for exfiltration: stolen credentials, browser cookies, and cryptocurrency wallet files (e.g., from Exodus, Electrum, and MetaMask) are compressed into a ZIP archive and sent to a Telegram channel controlled by the operator. IceEvent also employs a custom domain generation algorithm (DGA) to rotate fallback C2 domains every 24 hours.
📜 History & Notable Incidents
The first known IceEvent campaign occurred in August 2023, targeting Russian‑speaking users via phishing emails claiming to be from the Federal Tax Service. In November 2023, a second wave hit South Korean crypto exchanges, with IceEvent operators deploying a modified version that used steganography to hide payloads inside PNG images. No high‑profile victims have been publicly identified, but Unit 42 reported a correlation with the TA578 group’s earlier use of Bumblebee and IcedID loaders. No CVEs beyond CVE‑2021‑40444 have been directly associated with IceEvent as of early 2025.
🔍 Detection Indicators
Known samples include SHA‑256 hashes: 3a4b1c2d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a (first variant) and d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c (second variant). Behavioral signatures include outbound HTTP POST requests to Telegram’s API endpoint (api.telegram.org) with a user‑agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36”. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value name “SysHelper” are used for persistence.
☠️ Risk & Impact
IceEvent primarily exfiltrates cryptocurrency wallet private keys, browser‑stored passwords, and email credentials, leading to direct financial theft. In the South Korean campaign, losses exceeded $1.2 million across multiple victims. The malware also harvests session cookies from major platforms (Google, Microsoft, Amazon), enabling account takeover. Affected industries include cryptocurrency exchanges, online retail, and financial services.
🛡️ Mitigation
Organizations should enforce macro‑blocking via Group Policy (MITRE D3‑FEND macro policy), apply Microsoft patch KB5005655 for CVE‑2021‑40444, and deploy endpoint detection rules that flag anomalous Telegram API traffic. Using a web proxy to block api.telegram.org for non‑whitelisted processes can prevent data exfiltration. Trend Micro and Palo Alto Networks offer specific YARA rules (e.g., “IceEvent_Stealer_v1”) for detection.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.