Dridex — Malware Profile
Dridex is a prolific banking Trojan that first appeared in 2014. By December 2019, the US Treasury estimated Dridex had infected computers in hundreds of banks and financial institutions in over 40 countries, leading to more than $100 million in theft. Dridex was created from the source code of the Bugat banking Trojan (also known as Cridex).
MITRE ATT&CK techniques (15)
- T1027 Obfuscated Files or Information
- T1053.005 Scheduled Task
- T1071.001 Web Protocols
- T1082 System Information Discovery
- T1090 Proxy
- T1090.003 Multi-hop Proxy
- T1106 Native API
- T1185 Browser Session Hijacking
- T1204.002 Malicious File
- T1218.010 Regsvr32
- T1219 Remote Access Tools
- T1518 Software Discovery
- T1573.001 Symmetric Cryptography
- T1573.002 Asymmetric Cryptography
- T1574.001 DLL
IntelFusions coverage
- Eduard Benderskiy Named: The Former KGB Officer Who Shielded Evil Corp from Russian Law Enforcement 2026-02-16
- Hades Ransomware: How INDRIK SPIDER Reinvented Its Toolchain to Evade OFAC Sanctions 2026-02-16
Attributed threat actors
- TA505
- FIN11 machine-inferred link
- TA544 machine-inferred link
- Evil Corp
- DoppelPaymer machine-inferred link